PRAGMA foreign_keys=OFF; BEGIN TRANSACTION; CREATE TABLE alerts ( id INTEGER PRIMARY KEY, -- Store the timestamp timestamp INTEGER NOT NULL, -- Store the entire JSON object event JSONB NOT NULL ); INSERT INTO alerts VALUES(1,1772967419.289304019,'{"timestamp": "2026-03-08T11:56:59.289304+0100", "flow_id": 961079698010690, "event_type": "alert", "src_ip": "147.185.132.124", "src_port": 52155, "dest_ip": "185.254.126.122", "dest_port": 47687, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T11:56:59.289304+0100", "src_ip": "147.185.132.124", "dest_ip": "185.254.126.122", "src_port": 52155, "dest_port": 47687}}'); INSERT INTO alerts VALUES(2,1772967430.522192002,'{"timestamp": "2026-03-08T11:57:10.522192+0100", "flow_id": 1961325238545215, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 45714, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37714, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T11:57:10.522192+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 45714, "dest_port": 53}}'); INSERT INTO alerts VALUES(3,1772967434.425358058,'{"timestamp": "2026-03-08T11:57:14.425358+0100", "flow_id": 701000256440767, "event_type": "alert", "src_ip": "167.94.146.78", "src_port": 44851, "dest_ip": "185.254.126.122", "dest_port": 7327, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T11:57:14.425358+0100", "src_ip": "167.94.146.78", "dest_ip": "185.254.126.122", "src_port": 44851, "dest_port": 7327}}'); INSERT INTO alerts VALUES(4,1772967435.376257896,'{"timestamp": "2026-03-08T11:57:15.376258+0100", "flow_id": 1053068619941182, "event_type": "alert", "src_ip": "178.20.210.152", "src_port": 58665, "dest_ip": "185.254.126.122", "dest_port": 8022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T11:57:15.376258+0100", "src_ip": "178.20.210.152", "dest_ip": "185.254.126.122", "src_port": 58665, "dest_port": 8022}}'); INSERT INTO alerts VALUES(5,1772967445.550744057,'{"timestamp": "2026-03-08T11:57:25.550744+0100", "flow_id": 1449412654630148, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 52356, "dest_ip": "94.130.221.203", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053282, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "relays.syncthing.net", "version": "TLS 1.3", "ja3": {"hash": "473cd7cb9faa642487833865d516e578", "string": "771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-156-157-47-53-49170-10-4865-4866-4867,0-5-10-11-13-65281-18-43-51,29-23-24-25,0"}, "ja4": "t13d190900_9dc949149365_97f8aa674fd9"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 3, "pkts_toclient": 1, "bytes_toserver": 432, "bytes_toclient": 60, "start": "2026-03-08T11:57:25.534075+0100", "src_ip": "192.168.2.16", "dest_ip": "94.130.221.203", "src_port": 52356, "dest_port": 443}}'); INSERT INTO alerts VALUES(6,1772967462.691016913,'{"timestamp": "2026-03-08T11:57:42.691017+0100", "flow_id": 1841996644906554, "event_type": "alert", "src_ip": "88.210.63.190", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 9443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T11:57:42.691017+0100", "src_ip": "88.210.63.190", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 9443}}'); INSERT INTO alerts VALUES(7,1772967505.315068006,'{"timestamp": "2026-03-08T11:58:25.315068+0100", "flow_id": 508782971207888, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 9090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T11:58:25.315068+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 9090}}'); INSERT INTO alerts VALUES(8,1772967505.315068006,'{"timestamp": "2026-03-08T11:58:25.315068+0100", "flow_id": 508782971207888, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 9090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T11:58:25.315068+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 9090}}'); INSERT INTO alerts VALUES(9,1772967513.185911893,'{"timestamp": "2026-03-08T11:58:33.185912+0100", "flow_id": 517012712376562, "event_type": "alert", "src_ip": "45.153.34.226", "src_port": 34891, "dest_ip": "185.254.126.122", "dest_port": 20087, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T11:58:33.185912+0100", "src_ip": "45.153.34.226", "dest_ip": "185.254.126.122", "src_port": 34891, "dest_port": 20087}}'); INSERT INTO alerts VALUES(10,1772967513.185911893,'{"timestamp": "2026-03-08T11:58:33.185912+0100", "flow_id": 517012712376562, "event_type": "alert", "src_ip": "45.153.34.226", "src_port": 34891, "dest_ip": "185.254.126.122", "dest_port": 20087, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500030, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 16", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T11:58:33.185912+0100", "src_ip": "45.153.34.226", "dest_ip": "185.254.126.122", "src_port": 34891, "dest_port": 20087}}'); INSERT INTO alerts VALUES(11,1772967517.290266037,'{"timestamp": "2026-03-08T11:58:37.290266+0100", "flow_id": 1528159260649158, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "185.254.126.122", "dest_port": 11490, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T11:58:37.290266+0100", "src_ip": "79.124.40.110", "dest_ip": "185.254.126.122", "src_port": 52537, "dest_port": 11490}}'); INSERT INTO alerts VALUES(12,1772967628.863492013,'{"timestamp": "2026-03-08T12:00:28.863492+0100", "flow_id": 1175398258371088, "event_type": "alert", "src_ip": "45.153.34.226", "src_port": 40915, "dest_ip": "185.254.126.122", "dest_port": 40531, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500030, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 16", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T12:00:28.863492+0100", "src_ip": "45.153.34.226", "dest_ip": "185.254.126.122", "src_port": 40915, "dest_port": 40531}}'); INSERT INTO alerts VALUES(13,1772967716.599706888,'{"timestamp": "2026-03-08T12:01:56.599707+0100", "flow_id": 1168348496966980, "event_type": "alert", "src_ip": "64.89.163.131", "src_port": 47590, "dest_ip": "185.254.126.122", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:01:56.599707+0100", "src_ip": "64.89.163.131", "dest_ip": "185.254.126.122", "src_port": 47590, "dest_port": 27017}}'); INSERT INTO alerts VALUES(14,1772967719.755100011,'{"timestamp": "2026-03-08T12:01:59.755100+0100", "flow_id": 2117233669084283, "event_type": "alert", "src_ip": "204.76.203.30", "src_port": 56069, "dest_ip": "185.254.126.122", "dest_port": 3128, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:01:59.755100+0100", "src_ip": "204.76.203.30", "dest_ip": "185.254.126.122", "src_port": 56069, "dest_port": 3128}}'); INSERT INTO alerts VALUES(15,1772967719.755100011,'{"timestamp": "2026-03-08T12:01:59.755100+0100", "flow_id": 2117233669084283, "event_type": "alert", "src_ip": "204.76.203.30", "src_port": 56069, "dest_ip": "185.254.126.122", "dest_port": 3128, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:01:59.755100+0100", "src_ip": "204.76.203.30", "dest_ip": "185.254.126.122", "src_port": 56069, "dest_port": 3128}}'); INSERT INTO alerts VALUES(16,1772967724.022171021,'{"timestamp": "2026-03-08T12:02:04.022171+0100", "flow_id": 1221127573491045, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 43472, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:02:04.022171+0100", "src_ip": "79.124.62.134", "dest_ip": "185.254.126.122", "src_port": 43472, "dest_port": 3389}}'); INSERT INTO alerts VALUES(17,1772967727.100486993,'{"timestamp": "2026-03-08T12:02:07.100487+0100", "flow_id": 2120438464613340, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 40524, "dest_ip": "185.254.126.122", "dest_port": 2022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:02:07.100487+0100", "src_ip": "185.242.246.36", "dest_ip": "185.254.126.122", "src_port": 40524, "dest_port": 2022}}'); INSERT INTO alerts VALUES(18,1772967727.100486993,'{"timestamp": "2026-03-08T12:02:07.100487+0100", "flow_id": 2120438464613340, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 40524, "dest_ip": "185.254.126.122", "dest_port": 2022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:02:07.100487+0100", "src_ip": "185.242.246.36", "dest_ip": "185.254.126.122", "src_port": 40524, "dest_port": 2022}}'); INSERT INTO alerts VALUES(19,1772967761.398516894,'{"timestamp": "2026-03-08T12:02:41.398517+0100", "flow_id": 304243077302727, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 43068, "dest_ip": "185.254.126.122", "dest_port": 553, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:02:41.398517+0100", "src_ip": "79.124.62.126", "dest_ip": "185.254.126.122", "src_port": 43068, "dest_port": 553}}'); INSERT INTO alerts VALUES(20,1772967824.602550029,'{"timestamp": "2026-03-08T12:03:44.602550+0100", "flow_id": 54660028446774, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 51588, "dest_ip": "185.254.126.122", "dest_port": 4443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:03:44.602550+0100", "src_ip": "87.121.84.57", "dest_ip": "185.254.126.122", "src_port": 51588, "dest_port": 4443}}'); INSERT INTO alerts VALUES(21,1772967868.477924108,'{"timestamp": "2026-03-08T12:04:28.477924+0100", "flow_id": 1208244744334416, "event_type": "alert", "src_ip": "64.62.197.15", "src_port": 50066, "dest_ip": "185.254.126.122", "dest_port": 6081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:04:28.477924+0100", "src_ip": "64.62.197.15", "dest_ip": "185.254.126.122", "src_port": 50066, "dest_port": 6081}}'); INSERT INTO alerts VALUES(22,1772967888.195934057,'{"timestamp": "2026-03-08T12:04:48.195934+0100", "flow_id": 278581619090316, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 43615, "dest_ip": "185.254.126.122", "dest_port": 54373, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:04:48.195934+0100", "src_ip": "79.124.62.230", "dest_ip": "185.254.126.122", "src_port": 43615, "dest_port": 54373}}'); INSERT INTO alerts VALUES(23,1772967920.094182014,'{"timestamp": "2026-03-08T12:05:20.094182+0100", "flow_id": 123035360179307, "event_type": "alert", "src_ip": "176.65.134.20", "src_port": 35702, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:05:20.094182+0100", "src_ip": "176.65.134.20", "dest_ip": "185.254.126.122", "src_port": 35702, "dest_port": 443}}'); INSERT INTO alerts VALUES(24,1772967933.246010066,'{"timestamp": "2026-03-08T12:05:33.246010+0100", "flow_id": 1619556146710321, "event_type": "alert", "src_ip": "64.62.156.83", "src_port": 52572, "dest_ip": "185.254.126.122", "dest_port": 6081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:05:33.246010+0100", "src_ip": "64.62.156.83", "dest_ip": "185.254.126.122", "src_port": 52572, "dest_port": 6081}}'); INSERT INTO alerts VALUES(25,1772967936.600552083,'{"timestamp": "2026-03-08T12:05:36.600552+0100", "flow_id": 46076522523795, "event_type": "alert", "src_ip": "45.142.154.87", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 3110, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:05:36.600552+0100", "src_ip": "45.142.154.87", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 3110}}'); INSERT INTO alerts VALUES(26,1772968044.579890966,'{"timestamp": "2026-03-08T12:07:24.579891+0100", "flow_id": 1364715767711103, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 42263, "dest_ip": "185.254.126.122", "dest_port": 22022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:07:24.579891+0100", "src_ip": "185.242.246.37", "dest_ip": "185.254.126.122", "src_port": 42263, "dest_port": 22022}}'); INSERT INTO alerts VALUES(27,1772968044.579890966,'{"timestamp": "2026-03-08T12:07:24.579891+0100", "flow_id": 1364715767711103, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 42263, "dest_ip": "185.254.126.122", "dest_port": 22022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:07:24.579891+0100", "src_ip": "185.242.246.37", "dest_ip": "185.254.126.122", "src_port": 42263, "dest_port": 22022}}'); INSERT INTO alerts VALUES(28,1772968058.646970034,'{"timestamp": "2026-03-08T12:07:38.646970+0100", "flow_id": 808390271498471, "event_type": "alert", "src_ip": "167.94.138.128", "src_port": 50241, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:07:38.646970+0100", "src_ip": "167.94.138.128", "dest_ip": "185.254.126.122", "src_port": 50241, "dest_port": 80}}'); INSERT INTO alerts VALUES(29,1772968064.870910883,'{"timestamp": "2026-03-08T12:07:44.870911+0100", "flow_id": 81361713106344, "event_type": "alert", "src_ip": "64.62.156.126", "src_port": 43849, "dest_ip": "185.254.126.122", "dest_port": 9100, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:07:44.870911+0100", "src_ip": "64.62.156.126", "dest_ip": "185.254.126.122", "src_port": 43849, "dest_port": 9100}}'); INSERT INTO alerts VALUES(30,1772968071.505903006,'{"timestamp": "2026-03-08T12:07:51.505903+0100", "flow_id": 2172838372107286, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 4435, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:07:51.505903+0100", "src_ip": "88.210.63.69", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 4435}}'); INSERT INTO alerts VALUES(31,1772968086.532849074,'{"timestamp": "2026-03-08T12:08:06.532849+0100", "flow_id": 1725620693505979, "event_type": "alert", "src_ip": "87.121.84.93", "src_port": 48190, "dest_ip": "185.254.126.122", "dest_port": 8880, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:08:06.532849+0100", "src_ip": "87.121.84.93", "dest_ip": "185.254.126.122", "src_port": 48190, "dest_port": 8880}}'); INSERT INTO alerts VALUES(32,1772968121.220469952,'{"timestamp": "2026-03-08T12:08:41.220470+0100", "flow_id": 383964427788104, "event_type": "alert", "src_ip": "167.94.146.46", "src_port": 46392, "dest_ip": "185.254.126.122", "dest_port": 29037, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:08:41.220470+0100", "src_ip": "167.94.146.46", "dest_ip": "185.254.126.122", "src_port": 46392, "dest_port": 29037}}'); INSERT INTO alerts VALUES(33,1772968149.401411057,'{"timestamp": "2026-03-08T12:09:09.401411+0100", "flow_id": 1442573439966710, "event_type": "alert", "src_ip": "65.49.1.10", "src_port": 53486, "dest_ip": "185.254.126.122", "dest_port": 10161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 113, "bytes_toclient": 0, "start": "2026-03-08T12:09:09.401411+0100", "src_ip": "65.49.1.10", "dest_ip": "185.254.126.122", "src_port": 53486, "dest_port": 10161}}'); INSERT INTO alerts VALUES(34,1772968199.544286967,'{"timestamp": "2026-03-08T12:09:59.544287+0100", "flow_id": 2056224070135994, "event_type": "alert", "src_ip": "64.62.156.133", "src_port": 39958, "dest_ip": "185.254.126.122", "dest_port": 5002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:09:59.544287+0100", "src_ip": "64.62.156.133", "dest_ip": "185.254.126.122", "src_port": 39958, "dest_port": 5002}}'); INSERT INTO alerts VALUES(35,1772968201.585504055,'{"timestamp": "2026-03-08T12:10:01.585504+0100", "flow_id": 544398986985878, "event_type": "alert", "src_ip": "222.121.250.156", "src_port": 59589, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2500024, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 13", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:10:01.585504+0100", "src_ip": "222.121.250.156", "dest_ip": "185.254.126.122", "src_port": 59589, "dest_port": 22}}'); INSERT INTO alerts VALUES(36,1772968288.524804115,'{"timestamp": "2026-03-08T12:11:28.524804+0100", "flow_id": 2219680630656, "event_type": "alert", "src_ip": "162.217.98.180", "src_port": 44080, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 413, "bytes_toclient": 0, "start": "2026-03-08T12:11:28.524804+0100", "src_ip": "162.217.98.180", "dest_ip": "185.254.126.122", "src_port": 44080, "dest_port": 5060}}'); INSERT INTO alerts VALUES(37,1772968596.773941994,'{"timestamp": "2026-03-08T12:16:36.773942+0100", "flow_id": 1353731259262247, "event_type": "alert", "src_ip": "162.142.125.82", "src_port": 12566, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:16:36.773942+0100", "src_ip": "162.142.125.82", "dest_ip": "185.254.126.122", "src_port": 12566, "dest_port": 1433}}'); INSERT INTO alerts VALUES(38,1772968626.081825018,'{"timestamp": "2026-03-08T12:17:06.081825+0100", "flow_id": 632913899514048, "event_type": "alert", "src_ip": "167.94.146.41", "src_port": 33761, "dest_ip": "185.254.126.122", "dest_port": 52258, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:17:06.081825+0100", "src_ip": "167.94.146.41", "dest_ip": "185.254.126.122", "src_port": 33761, "dest_port": 52258}}'); INSERT INTO alerts VALUES(39,1772968633.133125067,'{"timestamp": "2026-03-08T12:17:13.133125+0100", "flow_id": 290293931178159, "event_type": "alert", "src_ip": "64.62.156.119", "src_port": 60596, "dest_ip": "185.254.126.122", "dest_port": 12654, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:17:13.133125+0100", "src_ip": "64.62.156.119", "dest_ip": "185.254.126.122", "src_port": 60596, "dest_port": 12654}}'); INSERT INTO alerts VALUES(40,1772968701.930237054,'{"timestamp": "2026-03-08T12:18:21.930237+0100", "flow_id": 1462065537787378, "event_type": "alert", "src_ip": "193.163.125.22", "src_port": 59470, "dest_ip": "185.254.126.122", "dest_port": 2107, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:18:21.930237+0100", "src_ip": "193.163.125.22", "dest_ip": "185.254.126.122", "src_port": 59470, "dest_port": 2107}}'); INSERT INTO alerts VALUES(41,1772968715.270917892,'{"timestamp": "2026-03-08T12:18:35.270918+0100", "flow_id": 882112871753615, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 57202, "dest_ip": "185.254.126.122", "dest_port": 3449, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:18:35.270918+0100", "src_ip": "45.142.193.7", "dest_ip": "185.254.126.122", "src_port": 57202, "dest_port": 3449}}'); INSERT INTO alerts VALUES(42,1772968762.92970109,'{"timestamp": "2026-03-08T12:19:22.929701+0100", "flow_id": 615335874839180, "event_type": "alert", "src_ip": "64.62.156.46", "src_port": 51289, "dest_ip": "185.254.126.122", "dest_port": 1434, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-08T12:19:22.929701+0100", "src_ip": "64.62.156.46", "dest_ip": "185.254.126.122", "src_port": 51289, "dest_port": 1434}}'); INSERT INTO alerts VALUES(43,1772968772.597405911,'{"timestamp": "2026-03-08T12:19:32.597406+0100", "flow_id": 1158467582124100, "event_type": "alert", "src_ip": "64.62.156.131", "src_port": 51301, "dest_ip": "185.254.126.122", "dest_port": 5804, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:19:32.597406+0100", "src_ip": "64.62.156.131", "dest_ip": "185.254.126.122", "src_port": 51301, "dest_port": 5804}}'); INSERT INTO alerts VALUES(44,1772968815.08911705,'{"timestamp": "2026-03-08T12:20:15.089117+0100", "flow_id": 2071606956141737, "event_type": "alert", "src_ip": "193.163.125.5", "src_port": 52109, "dest_ip": "185.254.126.122", "dest_port": 10109, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:20:15.089117+0100", "src_ip": "193.163.125.5", "dest_ip": "185.254.126.122", "src_port": 52109, "dest_port": 10109}}'); INSERT INTO alerts VALUES(45,1772968829.135941982,'{"timestamp": "2026-03-08T12:20:29.135942+0100", "flow_id": 1428294391629193, "event_type": "alert", "src_ip": "65.49.1.193", "src_port": 51795, "dest_ip": "185.254.126.122", "dest_port": 9060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:20:29.135942+0100", "src_ip": "65.49.1.193", "dest_ip": "185.254.126.122", "src_port": 51795, "dest_port": 9060}}'); INSERT INTO alerts VALUES(46,1772968987.806700945,'{"timestamp": "2026-03-08T12:23:07.806701+0100", "flow_id": 931483533319766, "event_type": "alert", "src_ip": "176.65.148.203", "src_port": 57395, "dest_ip": "185.254.126.122", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:23:07.806701+0100", "src_ip": "176.65.148.203", "dest_ip": "185.254.126.122", "src_port": 57395, "dest_port": 8088}}'); INSERT INTO alerts VALUES(47,1772968987.806700945,'{"timestamp": "2026-03-08T12:23:07.806701+0100", "flow_id": 931483533319766, "event_type": "alert", "src_ip": "176.65.148.203", "src_port": 57395, "dest_ip": "185.254.126.122", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:23:07.806701+0100", "src_ip": "176.65.148.203", "dest_ip": "185.254.126.122", "src_port": 57395, "dest_port": 8088}}'); INSERT INTO alerts VALUES(48,1772968987.806700945,'{"timestamp": "2026-03-08T12:23:07.806701+0100", "flow_id": 931483533319766, "event_type": "alert", "src_ip": "176.65.148.203", "src_port": 57395, "dest_ip": "185.254.126.122", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500018, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:23:07.806701+0100", "src_ip": "176.65.148.203", "dest_ip": "185.254.126.122", "src_port": 57395, "dest_port": 8088}}'); INSERT INTO alerts VALUES(49,1772968994.488075017,'{"timestamp": "2026-03-08T12:23:14.488075+0100", "flow_id": 688894393701528, "event_type": "alert", "src_ip": "176.65.148.2", "src_port": 57159, "dest_ip": "185.254.126.122", "dest_port": 8089, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:23:14.488075+0100", "src_ip": "176.65.148.2", "dest_ip": "185.254.126.122", "src_port": 57159, "dest_port": 8089}}'); INSERT INTO alerts VALUES(50,1772968994.488075017,'{"timestamp": "2026-03-08T12:23:14.488075+0100", "flow_id": 688894393701528, "event_type": "alert", "src_ip": "176.65.148.2", "src_port": 57159, "dest_ip": "185.254.126.122", "dest_port": 8089, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:23:14.488075+0100", "src_ip": "176.65.148.2", "dest_ip": "185.254.126.122", "src_port": 57159, "dest_port": 8089}}'); INSERT INTO alerts VALUES(51,1772969043.623117923,'{"timestamp": "2026-03-08T12:24:03.623118+0100", "flow_id": 987423258847880, "event_type": "alert", "src_ip": "45.156.87.91", "src_port": 52282, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:24:03.623118+0100", "src_ip": "45.156.87.91", "dest_ip": "185.254.126.122", "src_port": 52282, "dest_port": 8080}}'); INSERT INTO alerts VALUES(52,1772969136.564893007,'{"timestamp": "2026-03-08T12:25:36.564893+0100", "flow_id": 174398044913935, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 57816, "dest_ip": "185.254.126.122", "dest_port": 33333, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:25:36.564893+0100", "src_ip": "79.124.40.82", "dest_ip": "185.254.126.122", "src_port": 57816, "dest_port": 33333}}'); INSERT INTO alerts VALUES(53,1772969227.363162994,'{"timestamp": "2026-03-08T12:27:07.363163+0100", "flow_id": 996826649483882, "event_type": "alert", "src_ip": "167.94.146.42", "src_port": 32059, "dest_ip": "185.254.126.122", "dest_port": 3529, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:27:07.363163+0100", "src_ip": "167.94.146.42", "dest_ip": "185.254.126.122", "src_port": 32059, "dest_port": 3529}}'); INSERT INTO alerts VALUES(54,1772969230.134435892,'{"timestamp": "2026-03-08T12:27:10.134436+0100", "flow_id": 1703300492465607, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 46420, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:27:10.134436+0100", "src_ip": "45.153.34.32", "dest_ip": "185.254.126.122", "src_port": 46420, "dest_port": 3306}}'); INSERT INTO alerts VALUES(55,1772969230.134435892,'{"timestamp": "2026-03-08T12:27:10.134436+0100", "flow_id": 1703300492465607, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 46420, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:27:10.134436+0100", "src_ip": "45.153.34.32", "dest_ip": "185.254.126.122", "src_port": 46420, "dest_port": 3306}}'); INSERT INTO alerts VALUES(56,1772969231.584532022,'{"timestamp": "2026-03-08T12:27:11.584532+0100", "flow_id": 2229074908694708, "event_type": "alert", "src_ip": "64.62.197.104", "src_port": 47003, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:27:11.584532+0100", "src_ip": "64.62.197.104", "dest_ip": "185.254.126.122", "src_port": 47003, "dest_port": 3389}}'); INSERT INTO alerts VALUES(57,1772969244.378140927,'{"timestamp": "2026-03-08T12:27:24.378141+0100", "flow_id": 1342628541923666, "event_type": "alert", "src_ip": "87.121.84.72", "src_port": 44065, "dest_ip": "185.254.126.122", "dest_port": 1765, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:27:24.378141+0100", "src_ip": "87.121.84.72", "dest_ip": "185.254.126.122", "src_port": 44065, "dest_port": 1765}}'); INSERT INTO alerts VALUES(58,1772969244.857228995,'{"timestamp": "2026-03-08T12:27:24.857229+0100", "flow_id": 1148497289724770, "event_type": "alert", "src_ip": "64.62.156.196", "src_port": 44826, "dest_ip": "185.254.126.122", "dest_port": 20001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:27:24.857229+0100", "src_ip": "64.62.156.196", "dest_ip": "185.254.126.122", "src_port": 44826, "dest_port": 20001}}'); INSERT INTO alerts VALUES(59,1772969396.067214965,'{"timestamp": "2026-03-08T12:29:56.067215+0100", "flow_id": 1133111273325284, "event_type": "alert", "src_ip": "186.155.41.54", "src_port": 54451, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:29:56.067215+0100", "src_ip": "186.155.41.54", "dest_ip": "185.254.126.122", "src_port": 54451, "dest_port": 1433}}'); INSERT INTO alerts VALUES(60,1772969396.067708015,'{"timestamp": "2026-03-08T12:29:56.067708+0100", "flow_id": 1133111273325284, "event_type": "alert", "src_ip": "186.155.41.54", "src_port": 54451, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 80, "bytes_toclient": 0, "start": "2026-03-08T12:29:56.067215+0100", "src_ip": "186.155.41.54", "dest_ip": "185.254.126.122", "src_port": 54451, "dest_port": 1433}}'); INSERT INTO alerts VALUES(61,1772969454.749866008,'{"timestamp": "2026-03-08T12:30:54.749866+0100", "flow_id": 1813278450468078, "event_type": "alert", "src_ip": "167.94.146.44", "src_port": 20041, "dest_ip": "185.254.126.122", "dest_port": 28945, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:30:54.749866+0100", "src_ip": "167.94.146.44", "dest_ip": "185.254.126.122", "src_port": 20041, "dest_port": 28945}}'); INSERT INTO alerts VALUES(62,1772969455.414401054,'{"timestamp": "2026-03-08T12:30:55.414401+0100", "flow_id": 2061316693334352, "event_type": "alert", "src_ip": "124.128.247.169", "src_port": 49392, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:30:55.414401+0100", "src_ip": "124.128.247.169", "dest_ip": "185.254.126.122", "src_port": 49392, "dest_port": 1433}}'); INSERT INTO alerts VALUES(63,1772969485.985836983,'{"timestamp": "2026-03-08T12:31:25.985837+0100", "flow_id": 1419390800542631, "event_type": "alert", "src_ip": "185.242.226.17", "src_port": 35097, "dest_ip": "185.254.126.122", "dest_port": 5985, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:31:25.985837+0100", "src_ip": "185.242.226.17", "dest_ip": "185.254.126.122", "src_port": 35097, "dest_port": 5985}}'); INSERT INTO alerts VALUES(64,1772969503.767944098,'{"timestamp": "2026-03-08T12:31:43.767944+0100", "flow_id": 2172396000345852, "event_type": "alert", "src_ip": "147.185.132.176", "src_port": 50233, "dest_ip": "185.254.126.122", "dest_port": 2200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:31:43.767944+0100", "src_ip": "147.185.132.176", "dest_ip": "185.254.126.122", "src_port": 50233, "dest_port": 2200}}'); INSERT INTO alerts VALUES(65,1772969520.518975019,'{"timestamp": "2026-03-08T12:32:00.518975+0100", "flow_id": 258658261704279, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 34745, "dest_ip": "185.254.126.122", "dest_port": 1022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400037, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 38", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T12:32:00.518975+0100", "src_ip": "192.109.200.219", "dest_ip": "185.254.126.122", "src_port": 34745, "dest_port": 1022}}'); INSERT INTO alerts VALUES(66,1772969520.518975019,'{"timestamp": "2026-03-08T12:32:00.518975+0100", "flow_id": 258658261704279, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 34745, "dest_ip": "185.254.126.122", "dest_port": 1022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500020, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 11", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T12:32:00.518975+0100", "src_ip": "192.109.200.219", "dest_ip": "185.254.126.122", "src_port": 34745, "dest_port": 1022}}'); INSERT INTO alerts VALUES(67,1772969538.957374096,'{"timestamp": "2026-03-08T12:32:18.957374+0100", "flow_id": 734191275054246, "event_type": "alert", "src_ip": "167.94.146.35", "src_port": 14408, "dest_ip": "185.254.126.122", "dest_port": 41664, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:32:18.957374+0100", "src_ip": "167.94.146.35", "dest_ip": "185.254.126.122", "src_port": 14408, "dest_port": 41664}}'); INSERT INTO alerts VALUES(68,1772969540.911106109,'{"timestamp": "2026-03-08T12:32:20.911106+0100", "flow_id": 1379897170670676, "event_type": "alert", "src_ip": "64.62.197.40", "src_port": 46274, "dest_ip": "185.254.126.122", "dest_port": 1001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:32:20.911106+0100", "src_ip": "64.62.197.40", "dest_ip": "185.254.126.122", "src_port": 46274, "dest_port": 1001}}'); INSERT INTO alerts VALUES(69,1772969549.175812959,'{"timestamp": "2026-03-08T12:32:29.175813+0100", "flow_id": 1599539118572869, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 54839, "dest_ip": "185.254.126.122", "dest_port": 4207, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:32:29.175813+0100", "src_ip": "167.94.146.40", "dest_ip": "185.254.126.122", "src_port": 54839, "dest_port": 4207}}'); INSERT INTO alerts VALUES(70,1772969589.124248028,'{"timestamp": "2026-03-08T12:33:09.124248+0100", "flow_id": 1659545065564564, "event_type": "alert", "src_ip": "178.20.210.151", "src_port": 44371, "dest_ip": "185.254.126.122", "dest_port": 60022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:33:09.124248+0100", "src_ip": "178.20.210.151", "dest_ip": "185.254.126.122", "src_port": 44371, "dest_port": 60022}}'); INSERT INTO alerts VALUES(71,1772969675.490051032,'{"timestamp": "2026-03-08T12:34:35.490051+0100", "flow_id": 978855372649284, "event_type": "alert", "src_ip": "176.65.148.204", "src_port": 54265, "dest_ip": "185.254.126.122", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:34:35.490051+0100", "src_ip": "176.65.148.204", "dest_ip": "185.254.126.122", "src_port": 54265, "dest_port": 25565}}'); INSERT INTO alerts VALUES(72,1772969675.490051032,'{"timestamp": "2026-03-08T12:34:35.490051+0100", "flow_id": 978855372649284, "event_type": "alert", "src_ip": "176.65.148.204", "src_port": 54265, "dest_ip": "185.254.126.122", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:34:35.490051+0100", "src_ip": "176.65.148.204", "dest_ip": "185.254.126.122", "src_port": 54265, "dest_port": 25565}}'); INSERT INTO alerts VALUES(73,1772969676.924386025,'{"timestamp": "2026-03-08T12:34:36.924386+0100", "flow_id": 1155460185359247, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 40486, "dest_ip": "185.254.126.122", "dest_port": 1176, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500020, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 11", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T12:34:36.924386+0100", "src_ip": "192.109.200.219", "dest_ip": "185.254.126.122", "src_port": 40486, "dest_port": 1176}}'); INSERT INTO alerts VALUES(74,1772969706.614317893,'{"timestamp": "2026-03-08T12:35:06.614318+0100", "flow_id": 668151414313374, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 48403, "dest_ip": "185.254.126.122", "dest_port": 2001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:35:06.614318+0100", "src_ip": "185.242.246.38", "dest_ip": "185.254.126.122", "src_port": 48403, "dest_port": 2001}}'); INSERT INTO alerts VALUES(75,1772969706.614317893,'{"timestamp": "2026-03-08T12:35:06.614318+0100", "flow_id": 668151414313374, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 48403, "dest_ip": "185.254.126.122", "dest_port": 2001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:35:06.614318+0100", "src_ip": "185.242.246.38", "dest_ip": "185.254.126.122", "src_port": 48403, "dest_port": 2001}}'); INSERT INTO alerts VALUES(76,1772969708.039972067,'{"timestamp": "2026-03-08T12:35:08.039972+0100", "flow_id": 1297580871552892, "event_type": "alert", "src_ip": "101.0.104.38", "src_port": 5067, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 436, "bytes_toclient": 0, "start": "2026-03-08T12:35:08.039972+0100", "src_ip": "101.0.104.38", "dest_ip": "185.254.126.122", "src_port": 5067, "dest_port": 5060}}'); INSERT INTO alerts VALUES(77,1772969708.039972067,'{"timestamp": "2026-03-08T12:35:08.039972+0100", "flow_id": 1297580871552892, "event_type": "alert", "src_ip": "101.0.104.38", "src_port": 5067, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 436, "bytes_toclient": 0, "start": "2026-03-08T12:35:08.039972+0100", "src_ip": "101.0.104.38", "dest_ip": "185.254.126.122", "src_port": 5067, "dest_port": 5060}}'); INSERT INTO alerts VALUES(78,1772969738.882935047,'{"timestamp": "2026-03-08T12:35:38.882935+0100", "flow_id": 695952245243912, "event_type": "alert", "src_ip": "167.94.146.36", "src_port": 24606, "dest_ip": "185.254.126.122", "dest_port": 56924, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:35:38.882935+0100", "src_ip": "167.94.146.36", "dest_ip": "185.254.126.122", "src_port": 24606, "dest_port": 56924}}'); INSERT INTO alerts VALUES(79,1772969778.631633044,'{"timestamp": "2026-03-08T12:36:18.631633+0100", "flow_id": 742520687020377, "event_type": "alert", "src_ip": "167.94.138.153", "src_port": 17380, "dest_ip": "185.254.126.122", "dest_port": 2362, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 42, "bytes_toclient": 0, "start": "2026-03-08T12:36:18.631633+0100", "src_ip": "167.94.138.153", "dest_ip": "185.254.126.122", "src_port": 17380, "dest_port": 2362}}'); INSERT INTO alerts VALUES(80,1772969823.559125901,'{"timestamp": "2026-03-08T12:37:03.559126+0100", "flow_id": 2119954413435314, "event_type": "alert", "src_ip": "147.185.132.244", "src_port": 54469, "dest_ip": "185.254.126.122", "dest_port": 45101, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:37:03.559126+0100", "src_ip": "147.185.132.244", "dest_ip": "185.254.126.122", "src_port": 54469, "dest_port": 45101}}'); INSERT INTO alerts VALUES(81,1772969848.610964059,'{"timestamp": "2026-03-08T12:37:28.610964+0100", "flow_id": 90798536647977, "event_type": "alert", "src_ip": "147.185.132.14", "src_port": 50840, "dest_ip": "185.254.126.122", "dest_port": 9040, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:37:28.610964+0100", "src_ip": "147.185.132.14", "dest_ip": "185.254.126.122", "src_port": 50840, "dest_port": 9040}}'); INSERT INTO alerts VALUES(82,1772969872.024569035,'{"timestamp": "2026-03-08T12:37:52.024569+0100", "flow_id": 105526143122168, "event_type": "alert", "src_ip": "64.62.156.184", "src_port": 42784, "dest_ip": "185.254.126.122", "dest_port": 24156, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:37:52.024569+0100", "src_ip": "64.62.156.184", "dest_ip": "185.254.126.122", "src_port": 42784, "dest_port": 24156}}'); INSERT INTO alerts VALUES(83,1772969949.980952025,'{"timestamp": "2026-03-08T12:39:09.980952+0100", "flow_id": 1679883118561756, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 20906, "dest_ip": "185.254.126.122", "dest_port": 23868, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:39:09.980952+0100", "src_ip": "167.94.146.45", "dest_ip": "185.254.126.122", "src_port": 20906, "dest_port": 23868}}'); INSERT INTO alerts VALUES(84,1772969976.840507984,'{"timestamp": "2026-03-08T12:39:36.840508+0100", "flow_id": 232255189805329, "event_type": "alert", "src_ip": "192.109.200.157", "src_port": 34196, "dest_ip": "185.254.126.122", "dest_port": 34567, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400037, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 38", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:39:36.840508+0100", "src_ip": "192.109.200.157", "dest_ip": "185.254.126.122", "src_port": 34196, "dest_port": 34567}}'); INSERT INTO alerts VALUES(85,1772970061.731421948,'{"timestamp": "2026-03-08T12:41:01.731422+0100", "flow_id": 1452587357184737, "event_type": "alert", "src_ip": "64.62.156.94", "src_port": 51658, "dest_ip": "185.254.126.122", "dest_port": 5683, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 49, "bytes_toclient": 0, "start": "2026-03-08T12:41:01.731422+0100", "src_ip": "64.62.156.94", "dest_ip": "185.254.126.122", "src_port": 51658, "dest_port": 5683}}'); INSERT INTO alerts VALUES(86,1772970126.185158967,'{"timestamp": "2026-03-08T12:42:06.185159+0100", "flow_id": 1921153051424606, "event_type": "alert", "src_ip": "167.94.146.47", "src_port": 2199, "dest_ip": "185.254.126.122", "dest_port": 63391, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:42:06.185159+0100", "src_ip": "167.94.146.47", "dest_ip": "185.254.126.122", "src_port": 2199, "dest_port": 63391}}'); INSERT INTO alerts VALUES(87,1772970233.540241003,'{"timestamp": "2026-03-08T12:43:53.540241+0100", "flow_id": 349992661968521, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 48351, "dest_ip": "185.254.126.122", "dest_port": 18080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:43:53.540241+0100", "src_ip": "193.142.146.230", "dest_ip": "185.254.126.122", "src_port": 48351, "dest_port": 18080}}'); INSERT INTO alerts VALUES(88,1772970244.024663925,'{"timestamp": "2026-03-08T12:44:04.024664+0100", "flow_id": 1231833748404555, "event_type": "alert", "src_ip": "147.185.132.254", "src_port": 51595, "dest_ip": "185.254.126.122", "dest_port": 9588, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:44:04.024664+0100", "src_ip": "147.185.132.254", "dest_ip": "185.254.126.122", "src_port": 51595, "dest_port": 9588}}'); INSERT INTO alerts VALUES(89,1772970275.705806017,'{"timestamp": "2026-03-08T12:44:35.705806+0100", "flow_id": 1061093082999947, "event_type": "alert", "src_ip": "176.65.149.194", "src_port": 43039, "dest_ip": "185.254.126.122", "dest_port": 5005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:44:35.705806+0100", "src_ip": "176.65.149.194", "dest_ip": "185.254.126.122", "src_port": 43039, "dest_port": 5005}}'); INSERT INTO alerts VALUES(90,1772970318.780030012,'{"timestamp": "2026-03-08T12:45:18.780030+0100", "flow_id": 1942829923301587, "event_type": "alert", "src_ip": "147.185.132.130", "src_port": 49227, "dest_ip": "185.254.126.122", "dest_port": 13000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:45:18.780030+0100", "src_ip": "147.185.132.130", "dest_ip": "185.254.126.122", "src_port": 49227, "dest_port": 13000}}'); INSERT INTO alerts VALUES(91,1772970417.928836107,'{"timestamp": "2026-03-08T12:46:57.928836+0100", "flow_id": 330148858282879, "event_type": "alert", "src_ip": "167.94.138.155", "src_port": 7127, "dest_ip": "185.254.126.122", "dest_port": 52200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:46:57.928836+0100", "src_ip": "167.94.138.155", "dest_ip": "185.254.126.122", "src_port": 7127, "dest_port": 52200}}'); INSERT INTO alerts VALUES(92,1772970423.654944897,'{"timestamp": "2026-03-08T12:47:03.654945+0100", "flow_id": 2250019849755167, "event_type": "alert", "src_ip": "147.185.132.44", "src_port": 54016, "dest_ip": "185.254.126.122", "dest_port": 52110, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:47:03.654945+0100", "src_ip": "147.185.132.44", "dest_ip": "185.254.126.122", "src_port": 54016, "dest_port": 52110}}'); INSERT INTO alerts VALUES(93,1772970448.13249302,'{"timestamp": "2026-03-08T12:47:28.132493+0100", "flow_id": 6106737805137, "event_type": "alert", "src_ip": "88.210.63.193", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 1443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:47:28.132493+0100", "src_ip": "88.210.63.193", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 1443}}'); INSERT INTO alerts VALUES(94,1772970530.874842882,'{"timestamp": "2026-03-08T12:48:50.874843+0100", "flow_id": 661199746636833, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 5080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:48:50.874843+0100", "src_ip": "204.76.203.73", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 5080}}'); INSERT INTO alerts VALUES(95,1772970530.874842882,'{"timestamp": "2026-03-08T12:48:50.874843+0100", "flow_id": 661199746636833, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 5080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:48:50.874843+0100", "src_ip": "204.76.203.73", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 5080}}'); INSERT INTO alerts VALUES(96,1772970533.740964889,'{"timestamp": "2026-03-08T12:48:53.740965+0100", "flow_id": 1493574562761147, "event_type": "alert", "src_ip": "165.154.182.207", "src_port": 43439, "dest_ip": "185.254.126.122", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:48:53.740965+0100", "src_ip": "165.154.182.207", "dest_ip": "185.254.126.122", "src_port": 43439, "dest_port": 1521}}'); INSERT INTO alerts VALUES(97,1772970642.64416194,'{"timestamp": "2026-03-08T12:50:42.644162+0100", "flow_id": 796332903287087, "event_type": "alert", "src_ip": "64.62.197.36", "src_port": 36142, "dest_ip": "185.254.126.122", "dest_port": 143, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:50:42.644162+0100", "src_ip": "64.62.197.36", "dest_ip": "185.254.126.122", "src_port": 36142, "dest_port": 143}}'); INSERT INTO alerts VALUES(98,1772970686.149171114,'{"timestamp": "2026-03-08T12:51:26.149171+0100", "flow_id": 1766584935590848, "event_type": "alert", "src_ip": "190.26.208.130", "src_port": 17540, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:51:26.149171+0100", "src_ip": "190.26.208.130", "dest_ip": "185.254.126.122", "src_port": 17540, "dest_port": 1433}}'); INSERT INTO alerts VALUES(99,1772970705.723393917,'{"timestamp": "2026-03-08T12:51:45.723394+0100", "flow_id": 292206732422533, "event_type": "alert", "src_ip": "185.242.226.68", "src_port": 52208, "dest_ip": "185.254.126.122", "dest_port": 6999, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-08T12:51:45.723394+0100", "src_ip": "185.242.226.68", "dest_ip": "185.254.126.122", "src_port": 52208, "dest_port": 6999}}'); INSERT INTO alerts VALUES(100,1772970713.364567996,'{"timestamp": "2026-03-08T12:51:53.364568+0100", "flow_id": 439911588205995, "event_type": "alert", "src_ip": "64.62.197.171", "src_port": 58441, "dest_ip": "185.254.126.122", "dest_port": 49666, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:51:53.364568+0100", "src_ip": "64.62.197.171", "dest_ip": "185.254.126.122", "src_port": 58441, "dest_port": 49666}}'); INSERT INTO alerts VALUES(101,1772970726.134099006,'{"timestamp": "2026-03-08T12:52:06.134099+0100", "flow_id": 1701852578689491, "event_type": "alert", "src_ip": "64.89.163.23", "src_port": 49191, "dest_ip": "185.254.126.122", "dest_port": 587, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:52:06.134099+0100", "src_ip": "64.89.163.23", "dest_ip": "185.254.126.122", "src_port": 49191, "dest_port": 587}}'); INSERT INTO alerts VALUES(102,1772970833.377430916,'{"timestamp": "2026-03-08T12:53:53.377431+0100", "flow_id": 495155639860306, "event_type": "alert", "src_ip": "147.185.132.107", "src_port": 55072, "dest_ip": "185.254.126.122", "dest_port": 46895, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:53:53.377431+0100", "src_ip": "147.185.132.107", "dest_ip": "185.254.126.122", "src_port": 55072, "dest_port": 46895}}'); INSERT INTO alerts VALUES(103,1772970847.462182045,'{"timestamp": "2026-03-08T12:54:07.462182+0100", "flow_id": 1985058708004696, "event_type": "alert", "src_ip": "176.65.148.197", "src_port": 45968, "dest_ip": "185.254.126.122", "dest_port": 5006, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:54:07.462182+0100", "src_ip": "176.65.148.197", "dest_ip": "185.254.126.122", "src_port": 45968, "dest_port": 5006}}'); INSERT INTO alerts VALUES(104,1772970847.462182045,'{"timestamp": "2026-03-08T12:54:07.462182+0100", "flow_id": 1985058708004696, "event_type": "alert", "src_ip": "176.65.148.197", "src_port": 45968, "dest_ip": "185.254.126.122", "dest_port": 5006, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:54:07.462182+0100", "src_ip": "176.65.148.197", "dest_ip": "185.254.126.122", "src_port": 45968, "dest_port": 5006}}'); INSERT INTO alerts VALUES(105,1772970860.434972048,'{"timestamp": "2026-03-08T12:54:20.434972+0100", "flow_id": 1305242660097052, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 64436, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:54:20.434972+0100", "src_ip": "185.156.73.181", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 64436}}'); INSERT INTO alerts VALUES(106,1772970876.915090085,'{"timestamp": "2026-03-08T12:54:36.915090+0100", "flow_id": 1397008129464063, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 32985, "dest_ip": "185.254.126.122", "dest_port": 55595, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T12:54:36.915090+0100", "src_ip": "167.94.146.32", "dest_ip": "185.254.126.122", "src_port": 32985, "dest_port": 55595}}'); INSERT INTO alerts VALUES(107,1772970975.931539058,'{"timestamp": "2026-03-08T12:56:15.931539+0100", "flow_id": 2030607631199649, "event_type": "alert", "src_ip": "193.163.125.19", "src_port": 56298, "dest_ip": "185.254.126.122", "dest_port": 8083, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:56:15.931539+0100", "src_ip": "193.163.125.19", "dest_ip": "185.254.126.122", "src_port": 56298, "dest_port": 8083}}'); INSERT INTO alerts VALUES(108,1772970976.134443044,'{"timestamp": "2026-03-08T12:56:16.134443+0100", "flow_id": 14480115273459, "event_type": "alert", "src_ip": "46.151.182.45", "src_port": 46126, "dest_ip": "185.254.126.122", "dest_port": 2080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T12:56:16.134443+0100", "src_ip": "46.151.182.45", "dest_ip": "185.254.126.122", "src_port": 46126, "dest_port": 2080}}'); INSERT INTO alerts VALUES(109,1772971035.564723014,'{"timestamp": "2026-03-08T12:57:15.564723+0100", "flow_id": 1018093094413412, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 33997, "dest_ip": "185.254.126.122", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T12:57:15.564723+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 33997, "dest_port": 8332}}'); INSERT INTO alerts VALUES(110,1772971035.564723014,'{"timestamp": "2026-03-08T12:57:15.564723+0100", "flow_id": 1018093094413412, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 33997, "dest_ip": "185.254.126.122", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T12:57:15.564723+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 33997, "dest_port": 8332}}'); INSERT INTO alerts VALUES(111,1772971126.148916006,'{"timestamp": "2026-03-08T12:58:46.148916+0100", "flow_id": 1765493161747515, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "185.254.126.122", "dest_port": 12587, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:58:46.148916+0100", "src_ip": "79.124.40.110", "dest_ip": "185.254.126.122", "src_port": 52537, "dest_port": 12587}}'); INSERT INTO alerts VALUES(112,1772971136.582801104,'{"timestamp": "2026-03-08T12:58:56.582801+0100", "flow_id": 251314566996962, "event_type": "alert", "src_ip": "185.156.73.182", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 8085, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T12:58:56.582801+0100", "src_ip": "185.156.73.182", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 8085}}'); INSERT INTO alerts VALUES(113,1772971158.590765,'{"timestamp": "2026-03-08T12:59:18.590765+0100", "flow_id": 1692892284103529, "event_type": "alert", "src_ip": "147.185.132.124", "src_port": 56768, "dest_ip": "185.254.126.122", "dest_port": 7080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T12:59:18.590765+0100", "src_ip": "147.185.132.124", "dest_ip": "185.254.126.122", "src_port": 56768, "dest_port": 7080}}'); INSERT INTO alerts VALUES(114,1772971238.954747915,'{"timestamp": "2026-03-08T13:00:38.954748+0100", "flow_id": 1848811938633137, "event_type": "alert", "src_ip": "87.121.84.85", "src_port": 40128, "dest_ip": "185.254.126.122", "dest_port": 2011, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:00:38.954748+0100", "src_ip": "87.121.84.85", "dest_ip": "185.254.126.122", "src_port": 40128, "dest_port": 2011}}'); INSERT INTO alerts VALUES(115,1772971304.47939992,'{"timestamp": "2026-03-08T13:01:44.479400+0100", "flow_id": 88684102664093, "event_type": "alert", "src_ip": "193.163.125.6", "src_port": 56193, "dest_ip": "185.254.126.122", "dest_port": 9595, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:01:44.479400+0100", "src_ip": "193.163.125.6", "dest_ip": "185.254.126.122", "src_port": 56193, "dest_port": 9595}}'); INSERT INTO alerts VALUES(116,1772971307.622184991,'{"timestamp": "2026-03-08T13:01:47.622185+0100", "flow_id": 983416158379710, "event_type": "alert", "src_ip": "147.185.132.142", "src_port": 56685, "dest_ip": "185.254.126.122", "dest_port": 34465, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:01:47.622185+0100", "src_ip": "147.185.132.142", "dest_ip": "185.254.126.122", "src_port": 56685, "dest_port": 34465}}'); INSERT INTO alerts VALUES(117,1772971351.772161961,'{"timestamp": "2026-03-08T13:02:31.772162+0100", "flow_id": 2190513127722926, "event_type": "alert", "src_ip": "65.49.1.230", "src_port": 59832, "dest_ip": "185.254.126.122", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:02:31.772162+0100", "src_ip": "65.49.1.230", "dest_ip": "185.254.126.122", "src_port": 59832, "dest_port": 23}}'); INSERT INTO alerts VALUES(118,1772971358.014561891,'{"timestamp": "2026-03-08T13:02:38.014562+0100", "flow_id": 1751394306380374, "event_type": "alert", "src_ip": "176.65.149.182", "src_port": 42870, "dest_ip": "185.254.126.122", "dest_port": 8118, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T13:02:38.014562+0100", "src_ip": "176.65.149.182", "dest_ip": "185.254.126.122", "src_port": 42870, "dest_port": 8118}}'); INSERT INTO alerts VALUES(119,1772971424.335268021,'{"timestamp": "2026-03-08T13:03:44.335268+0100", "flow_id": 32593150578692, "event_type": "alert", "src_ip": "91.196.152.148", "src_port": 56888, "dest_ip": "185.254.126.122", "dest_port": 50075, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T13:03:44.335268+0100", "src_ip": "91.196.152.148", "dest_ip": "185.254.126.122", "src_port": 56888, "dest_port": 50075}}'); INSERT INTO alerts VALUES(120,1772971424.663022042,'{"timestamp": "2026-03-08T13:03:44.663022+0100", "flow_id": 32911587173041, "event_type": "alert", "src_ip": "65.49.1.235", "src_port": 59317, "dest_ip": "185.254.126.122", "dest_port": 5007, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:03:44.663022+0100", "src_ip": "65.49.1.235", "dest_ip": "185.254.126.122", "src_port": 59317, "dest_port": 5007}}'); INSERT INTO alerts VALUES(121,1772971441.056242943,'{"timestamp": "2026-03-08T13:04:01.056243+0100", "flow_id": 523039813263406, "event_type": "alert", "src_ip": "176.65.139.31", "src_port": 46887, "dest_ip": "185.254.126.122", "dest_port": 389, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ldap", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-08T13:04:01.056243+0100", "src_ip": "176.65.139.31", "dest_ip": "185.254.126.122", "src_port": 46887, "dest_port": 389}}'); INSERT INTO alerts VALUES(122,1772971522.527390003,'{"timestamp": "2026-03-08T13:05:22.527390+0100", "flow_id": 576276115960110, "event_type": "alert", "src_ip": "65.49.20.116", "src_port": 39143, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:05:22.527390+0100", "src_ip": "65.49.20.116", "dest_ip": "185.254.126.122", "src_port": 39143, "dest_port": 3306}}'); INSERT INTO alerts VALUES(123,1772971565.188852071,'{"timestamp": "2026-03-08T13:06:05.188852+0100", "flow_id": 1655541670352639, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 48716, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:06:05.188852+0100", "src_ip": "79.124.62.134", "dest_ip": "185.254.126.122", "src_port": 48716, "dest_port": 3389}}'); INSERT INTO alerts VALUES(124,1772971631.725609064,'{"timestamp": "2026-03-08T13:07:11.725609+0100", "flow_id": 1990569993677657, "event_type": "alert", "src_ip": "193.163.125.32", "src_port": 46411, "dest_ip": "185.254.126.122", "dest_port": 20404, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:07:11.725609+0100", "src_ip": "193.163.125.32", "dest_ip": "185.254.126.122", "src_port": 46411, "dest_port": 20404}}'); INSERT INTO alerts VALUES(125,1772971634.588442088,'{"timestamp": "2026-03-08T13:07:14.588442+0100", "flow_id": 838491663349271, "event_type": "alert", "src_ip": "66.132.153.151", "src_port": 29034, "dest_ip": "185.254.126.122", "dest_port": 47001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T13:07:14.588442+0100", "src_ip": "66.132.153.151", "dest_ip": "185.254.126.122", "src_port": 29034, "dest_port": 47001}}'); INSERT INTO alerts VALUES(126,1772971787.879647016,'{"timestamp": "2026-03-08T13:09:47.879647+0100", "flow_id": 963308864515602, "event_type": "alert", "src_ip": "185.242.3.212", "src_port": 49334, "dest_ip": "185.254.126.122", "dest_port": 14147, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:09:47.879647+0100", "src_ip": "185.242.3.212", "dest_ip": "185.254.126.122", "src_port": 49334, "dest_port": 14147}}'); INSERT INTO alerts VALUES(127,1772971838.892843008,'{"timestamp": "2026-03-08T13:10:38.892843+0100", "flow_id": 1864409081642923, "event_type": "alert", "src_ip": "64.89.160.135", "src_port": 58000, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:10:38.892843+0100", "src_ip": "64.89.160.135", "dest_ip": "185.254.126.122", "src_port": 58000, "dest_port": 22}}'); INSERT INTO alerts VALUES(128,1772971896.958273887,'{"timestamp": "2026-03-08T13:11:36.958274+0100", "flow_id": 175106094416209, "event_type": "alert", "src_ip": "193.163.125.2", "src_port": 48105, "dest_ip": "185.254.126.122", "dest_port": 2096, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:11:36.958274+0100", "src_ip": "193.163.125.2", "dest_ip": "185.254.126.122", "src_port": 48105, "dest_port": 2096}}'); INSERT INTO alerts VALUES(129,1772971898.189261913,'{"timestamp": "2026-03-08T13:11:38.189262+0100", "flow_id": 812877863051322, "event_type": "alert", "src_ip": "64.62.156.150", "src_port": 58537, "dest_ip": "185.254.126.122", "dest_port": 57722, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:11:38.189262+0100", "src_ip": "64.62.156.150", "dest_ip": "185.254.126.122", "src_port": 58537, "dest_port": 57722}}'); INSERT INTO alerts VALUES(130,1772971901.511260033,'{"timestamp": "2026-03-08T13:11:41.511260+0100", "flow_id": 1632896229854465, "event_type": "alert", "src_ip": "65.49.1.17", "src_port": 35052, "dest_ip": "185.254.126.122", "dest_port": 10074, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 34, "bytes_toclient": 0, "start": "2026-03-08T13:11:41.511260+0100", "src_ip": "65.49.1.17", "dest_ip": "185.254.126.122", "src_port": 35052, "dest_port": 10074}}'); INSERT INTO alerts VALUES(131,1772971931.215141058,'{"timestamp": "2026-03-08T13:12:11.215141+0100", "flow_id": 924026505670613, "event_type": "alert", "src_ip": "64.62.197.8", "src_port": 37088, "dest_ip": "185.254.126.122", "dest_port": 4001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:12:11.215141+0100", "src_ip": "64.62.197.8", "dest_ip": "185.254.126.122", "src_port": 37088, "dest_port": 4001}}'); INSERT INTO alerts VALUES(132,1772971965.299175024,'{"timestamp": "2026-03-08T13:12:45.299175+0100", "flow_id": 1566425049670594, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 48725, "dest_ip": "185.254.126.122", "dest_port": 611, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:12:45.299175+0100", "src_ip": "79.124.62.230", "dest_ip": "185.254.126.122", "src_port": 48725, "dest_port": 611}}'); INSERT INTO alerts VALUES(133,1772971992.90737009,'{"timestamp": "2026-03-08T13:13:12.907370+0100", "flow_id": 237950574130844, "event_type": "alert", "src_ip": "45.153.34.187", "src_port": 34965, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:13:12.907370+0100", "src_ip": "45.153.34.187", "dest_ip": "185.254.126.122", "src_port": 34965, "dest_port": 80}}'); INSERT INTO alerts VALUES(134,1772971999.063530922,'{"timestamp": "2026-03-08T13:13:19.063531+0100", "flow_id": 2243190861642602, "event_type": "alert", "src_ip": "80.94.92.168", "src_port": 38216, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:13:19.063531+0100", "src_ip": "80.94.92.168", "dest_ip": "185.254.126.122", "src_port": 38216, "dest_port": 22}}'); INSERT INTO alerts VALUES(135,1772972040.162509918,'{"timestamp": "2026-03-08T13:14:00.162510+0100", "flow_id": 135025382767463, "event_type": "alert", "src_ip": "193.163.125.20", "src_port": 57287, "dest_ip": "185.254.126.122", "dest_port": 7022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:14:00.162510+0100", "src_ip": "193.163.125.20", "dest_ip": "185.254.126.122", "src_port": 57287, "dest_port": 7022}}'); INSERT INTO alerts VALUES(136,1772972097.109163045,'{"timestamp": "2026-03-08T13:14:57.109163+0100", "flow_id": 468853251673517, "event_type": "alert", "src_ip": "81.29.142.50", "src_port": 53524, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:14:57.109163+0100", "src_ip": "81.29.142.50", "dest_ip": "185.254.126.122", "src_port": 53524, "dest_port": 5432}}'); INSERT INTO alerts VALUES(137,1772972173.800925016,'{"timestamp": "2026-03-08T13:16:13.800925+0100", "flow_id": 1469622167206561, "event_type": "alert", "src_ip": "147.185.132.235", "src_port": 53899, "dest_ip": "185.254.126.122", "dest_port": 48847, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:16:13.800925+0100", "src_ip": "147.185.132.235", "dest_ip": "185.254.126.122", "src_port": 53899, "dest_port": 48847}}'); INSERT INTO alerts VALUES(138,1772972221.966645957,'{"timestamp": "2026-03-08T13:17:01.966646+0100", "flow_id": 1618439119854971, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61351, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2057745, "rev": 1, "signature": "ET INFO DNS Query to Cloudflare Page Developer Domain (pages .dev)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_11_20"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_11_20"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5203, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "kaufradar-teaser.pages.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-08T13:17:01.966646+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61351, "dest_port": 53}}'); INSERT INTO alerts VALUES(139,1772972371.418720961,'{"timestamp": "2026-03-08T13:19:31.418721+0100", "flow_id": 953970788366412, "event_type": "alert", "src_ip": "204.76.203.18", "src_port": 38465, "dest_ip": "185.254.126.122", "dest_port": 8000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T13:19:31.418721+0100", "src_ip": "204.76.203.18", "dest_ip": "185.254.126.122", "src_port": 38465, "dest_port": 8000}}'); INSERT INTO alerts VALUES(140,1772972371.418720961,'{"timestamp": "2026-03-08T13:19:31.418721+0100", "flow_id": 953970788366412, "event_type": "alert", "src_ip": "204.76.203.18", "src_port": 38465, "dest_ip": "185.254.126.122", "dest_port": 8000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T13:19:31.418721+0100", "src_ip": "204.76.203.18", "dest_ip": "185.254.126.122", "src_port": 38465, "dest_port": 8000}}'); INSERT INTO alerts VALUES(141,1772972415.026680946,'{"timestamp": "2026-03-08T13:20:15.026681+0100", "flow_id": 2084920358551976, "event_type": "alert", "src_ip": "172.94.9.253", "src_port": 45706, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400031, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 32", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:20:15.026681+0100", "src_ip": "172.94.9.253", "dest_ip": "185.254.126.122", "src_port": 45706, "dest_port": 80}}'); INSERT INTO alerts VALUES(142,1772972522.197484971,'{"timestamp": "2026-03-08T13:22:02.197485+0100", "flow_id": 566718833651455, "event_type": "alert", "src_ip": "64.62.156.101", "src_port": 48932, "dest_ip": "185.254.126.122", "dest_port": 25, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:22:02.197485+0100", "src_ip": "64.62.156.101", "dest_ip": "185.254.126.122", "src_port": 48932, "dest_port": 25}}'); INSERT INTO alerts VALUES(143,1772972622.730004072,'{"timestamp": "2026-03-08T13:23:42.730004+0100", "flow_id": 1727971726173054, "event_type": "alert", "src_ip": "112.135.170.137", "src_port": 46251, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T13:23:42.730004+0100", "src_ip": "112.135.170.137", "dest_ip": "185.254.126.122", "src_port": 46251, "dest_port": 1433}}'); INSERT INTO alerts VALUES(144,1772972639.537672042,'{"timestamp": "2026-03-08T13:23:59.537672+0100", "flow_id": 2027810090184418, "event_type": "alert", "src_ip": "64.62.197.82", "src_port": 48425, "dest_ip": "185.254.126.122", "dest_port": 4840, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:23:59.537672+0100", "src_ip": "64.62.197.82", "dest_ip": "185.254.126.122", "src_port": 48425, "dest_port": 4840}}'); INSERT INTO alerts VALUES(145,1772972652.14081812,'{"timestamp": "2026-03-08T13:24:12.140818+0100", "flow_id": 1167760385250494, "event_type": "alert", "src_ip": "64.89.163.241", "src_port": 49084, "dest_ip": "185.254.126.122", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:24:12.140818+0100", "src_ip": "64.89.163.241", "dest_ip": "185.254.126.122", "src_port": 49084, "dest_port": 3000}}'); INSERT INTO alerts VALUES(146,1772972696.847150087,'{"timestamp": "2026-03-08T13:24:56.847150+0100", "flow_id": 260782663552275, "event_type": "alert", "src_ip": "91.224.92.177", "src_port": 32779, "dest_ip": "185.254.126.122", "dest_port": 3001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:24:56.847150+0100", "src_ip": "91.224.92.177", "dest_ip": "185.254.126.122", "src_port": 32779, "dest_port": 3001}}'); INSERT INTO alerts VALUES(147,1772972772.148148059,'{"timestamp": "2026-03-08T13:26:12.148148+0100", "flow_id": 1199241648899954, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 1443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:26:12.148148+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 1443}}'); INSERT INTO alerts VALUES(148,1772972772.148148059,'{"timestamp": "2026-03-08T13:26:12.148148+0100", "flow_id": 1199241648899954, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 1443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:26:12.148148+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 1443}}'); INSERT INTO alerts VALUES(149,1772972781.278279067,'{"timestamp": "2026-03-08T13:26:21.278279+0100", "flow_id": 1476675263218085, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 57816, "dest_ip": "185.254.126.122", "dest_port": 32123, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:26:21.278279+0100", "src_ip": "79.124.40.82", "dest_ip": "185.254.126.122", "src_port": 57816, "dest_port": 32123}}'); INSERT INTO alerts VALUES(150,1772972799.567433119,'{"timestamp": "2026-03-08T13:26:39.567433+0100", "flow_id": 2155634950020812, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 44493, "dest_ip": "185.254.126.122", "dest_port": 7637, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T13:26:39.567433+0100", "src_ip": "167.94.146.37", "dest_ip": "185.254.126.122", "src_port": 44493, "dest_port": 7637}}'); INSERT INTO alerts VALUES(151,1772972807.564919949,'{"timestamp": "2026-03-08T13:26:47.564920+0100", "flow_id": 2144839997270736, "event_type": "alert", "src_ip": "204.76.203.30", "src_port": 49757, "dest_ip": "185.254.126.122", "dest_port": 8443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:26:47.564920+0100", "src_ip": "204.76.203.30", "dest_ip": "185.254.126.122", "src_port": 49757, "dest_port": 8443}}'); INSERT INTO alerts VALUES(152,1772972807.564919949,'{"timestamp": "2026-03-08T13:26:47.564920+0100", "flow_id": 2144839997270736, "event_type": "alert", "src_ip": "204.76.203.30", "src_port": 49757, "dest_ip": "185.254.126.122", "dest_port": 8443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:26:47.564920+0100", "src_ip": "204.76.203.30", "dest_ip": "185.254.126.122", "src_port": 49757, "dest_port": 8443}}'); INSERT INTO alerts VALUES(153,1772972822.955254077,'{"timestamp": "2026-03-08T13:27:02.955254+0100", "flow_id": 1850986419358875, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54928, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2063117, "rev": 1, "signature": "ET INFO Abused Hosting Domain in DNS Lookup (azurewebsites .net)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_and_Server"], "confidence": ["Medium"], "created_at": ["2025_06_20"], "deployment": ["Perimeter"], "mitre_tactic_id": ["TA0011"], "mitre_tactic_name": ["Command_And_Control"], "mitre_technique_id": ["T1102"], "mitre_technique_name": ["Web_Service"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "updated_at": ["2025_06_20"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16799, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "pinpoll-tracking-live-windows.azurewebsites.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T13:27:02.955254+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54928, "dest_port": 53}}'); INSERT INTO alerts VALUES(154,1772972822.955574035,'{"timestamp": "2026-03-08T13:27:02.955574+0100", "flow_id": 1852359553329611, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53092, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2063117, "rev": 1, "signature": "ET INFO Abused Hosting Domain in DNS Lookup (azurewebsites .net)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_and_Server"], "confidence": ["Medium"], "created_at": ["2025_06_20"], "deployment": ["Perimeter"], "mitre_tactic_id": ["TA0011"], "mitre_tactic_name": ["Command_And_Control"], "mitre_technique_id": ["T1102"], "mitre_technique_name": ["Web_Service"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "updated_at": ["2025_06_20"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3910, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "pinpoll-tracking-live-windows.azurewebsites.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T13:27:02.955574+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53092, "dest_port": 53}}'); INSERT INTO alerts VALUES(155,1772972836.023840905,'{"timestamp": "2026-03-08T13:27:16.023841+0100", "flow_id": 1228297511704843, "event_type": "alert", "src_ip": "167.94.138.107", "src_port": 26282, "dest_ip": "185.254.126.122", "dest_port": 5313, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T13:27:16.023841+0100", "src_ip": "167.94.138.107", "dest_ip": "185.254.126.122", "src_port": 26282, "dest_port": 5313}}'); INSERT INTO alerts VALUES(156,1772972840.957405091,'{"timestamp": "2026-03-08T13:27:20.957405+0100", "flow_id": 171377207655195, "event_type": "alert", "src_ip": "176.65.139.41", "src_port": 50001, "dest_ip": "185.254.126.122", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:27:20.957405+0100", "src_ip": "176.65.139.41", "dest_ip": "185.254.126.122", "src_port": 50001, "dest_port": 3000}}'); INSERT INTO alerts VALUES(157,1772972852.182192088,'{"timestamp": "2026-03-08T13:27:32.182192+0100", "flow_id": 1345462094921172, "event_type": "alert", "src_ip": "178.20.210.152", "src_port": 50165, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:27:32.182192+0100", "src_ip": "178.20.210.152", "dest_ip": "185.254.126.122", "src_port": 50165, "dest_port": 22}}'); INSERT INTO alerts VALUES(158,1772972921.076790094,'{"timestamp": "2026-03-08T13:28:41.076790+0100", "flow_id": 329810678400911, "event_type": "alert", "src_ip": "64.62.156.64", "src_port": 42820, "dest_ip": "185.254.126.122", "dest_port": 830, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:28:41.076790+0100", "src_ip": "64.62.156.64", "dest_ip": "185.254.126.122", "src_port": 42820, "dest_port": 830}}'); INSERT INTO alerts VALUES(159,1772972943.525029897,'{"timestamp": "2026-03-08T13:29:03.525030+0100", "flow_id": 1973514659879785, "event_type": "alert", "src_ip": "65.49.1.141", "src_port": 58198, "dest_ip": "185.254.126.122", "dest_port": 4118, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:29:03.525030+0100", "src_ip": "65.49.1.141", "dest_ip": "185.254.126.122", "src_port": 58198, "dest_port": 4118}}'); INSERT INTO alerts VALUES(160,1772973030.468720912,'{"timestamp": "2026-03-08T13:30:30.468721+0100", "flow_id": 1731668453095284, "event_type": "alert", "src_ip": "165.154.227.162", "src_port": 36383, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400029, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 30", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:30:30.468721+0100", "src_ip": "165.154.227.162", "dest_ip": "185.254.126.122", "src_port": 36383, "dest_port": 443}}'); INSERT INTO alerts VALUES(161,1772973030.468720912,'{"timestamp": "2026-03-08T13:30:30.468721+0100", "flow_id": 1731668453095284, "event_type": "alert", "src_ip": "165.154.227.162", "src_port": 36383, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500014, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:30:30.468721+0100", "src_ip": "165.154.227.162", "dest_ip": "185.254.126.122", "src_port": 36383, "dest_port": 443}}'); INSERT INTO alerts VALUES(162,1772973095.63487506,'{"timestamp": "2026-03-08T13:31:35.634875+0100", "flow_id": 2163818491247111, "event_type": "alert", "src_ip": "176.65.139.45", "src_port": 50217, "dest_ip": "185.254.126.122", "dest_port": 6036, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:31:35.634875+0100", "src_ip": "176.65.139.45", "dest_ip": "185.254.126.122", "src_port": 50217, "dest_port": 6036}}'); INSERT INTO alerts VALUES(163,1772973141.071481943,'{"timestamp": "2026-03-08T13:32:21.071482+0100", "flow_id": 1432913709182443, "event_type": "alert", "src_ip": "87.121.84.67", "src_port": 46227, "dest_ip": "185.254.126.122", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:32:21.071482+0100", "src_ip": "87.121.84.67", "dest_ip": "185.254.126.122", "src_port": 46227, "dest_port": 5900}}'); INSERT INTO alerts VALUES(164,1772973181.837021113,'{"timestamp": "2026-03-08T13:33:01.837021+0100", "flow_id": 1624653500932311, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 3443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:33:01.837021+0100", "src_ip": "185.156.73.86", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 3443}}'); INSERT INTO alerts VALUES(165,1772973212.475070954,'{"timestamp": "2026-03-08T13:33:32.475071+0100", "flow_id": 1195989794777632, "event_type": "alert", "src_ip": "167.94.146.42", "src_port": 17336, "dest_ip": "185.254.126.122", "dest_port": 15214, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T13:33:32.475071+0100", "src_ip": "167.94.146.42", "dest_ip": "185.254.126.122", "src_port": 17336, "dest_port": 15214}}'); INSERT INTO alerts VALUES(166,1772973431.019588947,'{"timestamp": "2026-03-08T13:37:11.019589+0100", "flow_id": 2054463024900712, "event_type": "alert", "src_ip": "193.163.125.9", "src_port": 55256, "dest_ip": "185.254.126.122", "dest_port": 554, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:37:11.019589+0100", "src_ip": "193.163.125.9", "dest_ip": "185.254.126.122", "src_port": 55256, "dest_port": 554}}'); INSERT INTO alerts VALUES(167,1772973470.337503911,'{"timestamp": "2026-03-08T13:37:50.337504+0100", "flow_id": 1731046161389373, "event_type": "alert", "src_ip": "65.49.1.131", "src_port": 45743, "dest_ip": "185.254.126.122", "dest_port": 11211, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:37:50.337504+0100", "src_ip": "65.49.1.131", "dest_ip": "185.254.126.122", "src_port": 45743, "dest_port": 11211}}'); INSERT INTO alerts VALUES(168,1772973474.422059059,'{"timestamp": "2026-03-08T13:37:54.422059+0100", "flow_id": 686830381029697, "event_type": "alert", "src_ip": "64.62.156.149", "src_port": 43921, "dest_ip": "185.254.126.122", "dest_port": 6379, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:37:54.422059+0100", "src_ip": "64.62.156.149", "dest_ip": "185.254.126.122", "src_port": 43921, "dest_port": 6379}}'); INSERT INTO alerts VALUES(169,1772973496.64595604,'{"timestamp": "2026-03-08T13:38:16.645956+0100", "flow_id": 241085918363985, "event_type": "alert", "src_ip": "167.94.146.34", "src_port": 5318, "dest_ip": "185.254.126.122", "dest_port": 33551, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T13:38:16.645956+0100", "src_ip": "167.94.146.34", "dest_ip": "185.254.126.122", "src_port": 5318, "dest_port": 33551}}'); INSERT INTO alerts VALUES(170,1772973544.524960995,'{"timestamp": "2026-03-08T13:39:04.524961+0100", "flow_id": 2892533476583, "event_type": "alert", "src_ip": "167.94.146.39", "src_port": 14487, "dest_ip": "185.254.126.122", "dest_port": 11947, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T13:39:04.524961+0100", "src_ip": "167.94.146.39", "dest_ip": "185.254.126.122", "src_port": 14487, "dest_port": 11947}}'); INSERT INTO alerts VALUES(171,1772973582.314892053,'{"timestamp": "2026-03-08T13:39:42.314892+0100", "flow_id": 1915400937329382, "event_type": "alert", "src_ip": "65.49.1.172", "src_port": 54651, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:39:42.314892+0100", "src_ip": "65.49.1.172", "dest_ip": "185.254.126.122", "src_port": 54651, "dest_port": 22}}'); INSERT INTO alerts VALUES(172,1772973588.780414105,'{"timestamp": "2026-03-08T13:39:48.780414+0100", "flow_id": 1381530166910618, "event_type": "alert", "src_ip": "64.95.96.69", "src_port": 5217, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 435, "bytes_toclient": 0, "start": "2026-03-08T13:39:48.780414+0100", "src_ip": "64.95.96.69", "dest_ip": "185.254.126.122", "src_port": 5217, "dest_port": 5060}}'); INSERT INTO alerts VALUES(173,1772973588.780414105,'{"timestamp": "2026-03-08T13:39:48.780414+0100", "flow_id": 1381530166910618, "event_type": "alert", "src_ip": "64.95.96.69", "src_port": 5217, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 435, "bytes_toclient": 0, "start": "2026-03-08T13:39:48.780414+0100", "src_ip": "64.95.96.69", "dest_ip": "185.254.126.122", "src_port": 5217, "dest_port": 5060}}'); INSERT INTO alerts VALUES(174,1772973619.898673058,'{"timestamp": "2026-03-08T13:40:19.898673+0100", "flow_id": 1045023732564279, "event_type": "alert", "src_ip": "193.163.125.37", "src_port": 44244, "dest_ip": "185.254.126.122", "dest_port": 33060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:40:19.898673+0100", "src_ip": "193.163.125.37", "dest_ip": "185.254.126.122", "src_port": 44244, "dest_port": 33060}}'); INSERT INTO alerts VALUES(175,1772973628.433710098,'{"timestamp": "2026-03-08T13:40:28.433710+0100", "flow_id": 1299822278433029, "event_type": "alert", "src_ip": "2.57.122.238", "src_port": 60735, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2500026, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:40:28.433710+0100", "src_ip": "2.57.122.238", "dest_ip": "185.254.126.122", "src_port": 60735, "dest_port": 22}}'); INSERT INTO alerts VALUES(176,1772973643.356739045,'{"timestamp": "2026-03-08T13:40:43.356739+0100", "flow_id": 969235053572635, "event_type": "alert", "src_ip": "147.185.132.250", "src_port": 52368, "dest_ip": "185.254.126.122", "dest_port": 51202, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:40:43.356739+0100", "src_ip": "147.185.132.250", "dest_ip": "185.254.126.122", "src_port": 52368, "dest_port": 51202}}'); INSERT INTO alerts VALUES(177,1772973692.629972935,'{"timestamp": "2026-03-08T13:41:32.629973+0100", "flow_id": 1298342652442280, "event_type": "alert", "src_ip": "167.94.146.74", "src_port": 3381, "dest_ip": "185.254.126.122", "dest_port": 24989, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T13:41:32.629973+0100", "src_ip": "167.94.146.74", "dest_ip": "185.254.126.122", "src_port": 3381, "dest_port": 24989}}'); INSERT INTO alerts VALUES(178,1772973727.890037059,'{"timestamp": "2026-03-08T13:42:07.890037+0100", "flow_id": 2133834012486163, "event_type": "alert", "src_ip": "167.94.146.41", "src_port": 17847, "dest_ip": "185.254.126.122", "dest_port": 20606, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T13:42:07.890037+0100", "src_ip": "167.94.146.41", "dest_ip": "185.254.126.122", "src_port": 17847, "dest_port": 20606}}'); INSERT INTO alerts VALUES(179,1772973737.667052985,'{"timestamp": "2026-03-08T13:42:17.667053+0100", "flow_id": 331699248882025, "event_type": "alert", "src_ip": "64.62.156.50", "src_port": 36517, "dest_ip": "185.254.126.122", "dest_port": 1200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:42:17.667053+0100", "src_ip": "64.62.156.50", "dest_ip": "185.254.126.122", "src_port": 36517, "dest_port": 1200}}'); INSERT INTO alerts VALUES(180,1772973788.315941096,'{"timestamp": "2026-03-08T13:43:08.315941+0100", "flow_id": 1356956268183854, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 43028, "dest_ip": "185.254.126.122", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:43:08.315941+0100", "src_ip": "130.12.180.174", "dest_ip": "185.254.126.122", "src_port": 43028, "dest_port": 23}}'); INSERT INTO alerts VALUES(181,1772973788.315941096,'{"timestamp": "2026-03-08T13:43:08.315941+0100", "flow_id": 1356956268183854, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 43028, "dest_ip": "185.254.126.122", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:43:08.315941+0100", "src_ip": "130.12.180.174", "dest_ip": "185.254.126.122", "src_port": 43028, "dest_port": 23}}'); INSERT INTO alerts VALUES(182,1772973823.641407967,'{"timestamp": "2026-03-08T13:43:43.641408+0100", "flow_id": 2191880050720735, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 52645, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:43:43.641408+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 52645, "dest_port": 3389}}'); INSERT INTO alerts VALUES(183,1772973823.641407967,'{"timestamp": "2026-03-08T13:43:43.641408+0100", "flow_id": 2191880050720735, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 52645, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:43:43.641408+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 52645, "dest_port": 3389}}'); INSERT INTO alerts VALUES(184,1772973829.991050959,'{"timestamp": "2026-03-08T13:43:49.991051+0100", "flow_id": 1441783460423857, "event_type": "alert", "src_ip": "64.89.163.81", "src_port": 53715, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:43:49.991051+0100", "src_ip": "64.89.163.81", "dest_ip": "185.254.126.122", "src_port": 53715, "dest_port": 5432}}'); INSERT INTO alerts VALUES(185,1772973829.991050959,'{"timestamp": "2026-03-08T13:43:49.991051+0100", "flow_id": 1441783460423857, "event_type": "alert", "src_ip": "64.89.163.81", "src_port": 53715, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:43:49.991051+0100", "src_ip": "64.89.163.81", "dest_ip": "185.254.126.122", "src_port": 53715, "dest_port": 5432}}'); INSERT INTO alerts VALUES(186,1772973839.052125931,'{"timestamp": "2026-03-08T13:43:59.052126+0100", "flow_id": 2194205026372439, "event_type": "alert", "src_ip": "64.62.197.198", "src_port": 34898, "dest_ip": "185.254.126.122", "dest_port": 63256, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:43:59.052126+0100", "src_ip": "64.62.197.198", "dest_ip": "185.254.126.122", "src_port": 34898, "dest_port": 63256}}'); INSERT INTO alerts VALUES(187,1772973882.007618904,'{"timestamp": "2026-03-08T13:44:42.007619+0100", "flow_id": 595677443648176, "event_type": "alert", "src_ip": "64.62.156.76", "src_port": 56747, "dest_ip": "185.254.126.122", "dest_port": 1801, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:44:42.007619+0100", "src_ip": "64.62.156.76", "dest_ip": "185.254.126.122", "src_port": 56747, "dest_port": 1801}}'); INSERT INTO alerts VALUES(188,1772973930.36431694,'{"timestamp": "2026-03-08T13:45:30.364317+0100", "flow_id": 720308272947799, "event_type": "alert", "src_ip": "40.124.172.38", "src_port": 40391, "dest_ip": "185.254.126.122", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-08T13:45:30.364317+0100", "src_ip": "40.124.172.38", "dest_ip": "185.254.126.122", "src_port": 40391, "dest_port": 161}}'); INSERT INTO alerts VALUES(189,1772973951.974888087,'{"timestamp": "2026-03-08T13:45:51.974888+0100", "flow_id": 2216787566896844, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 48482, "dest_ip": "185.254.126.122", "dest_port": 3022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:45:51.974888+0100", "src_ip": "185.242.246.36", "dest_ip": "185.254.126.122", "src_port": 48482, "dest_port": 3022}}'); INSERT INTO alerts VALUES(190,1772973951.974888087,'{"timestamp": "2026-03-08T13:45:51.974888+0100", "flow_id": 2216787566896844, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 48482, "dest_ip": "185.254.126.122", "dest_port": 3022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:45:51.974888+0100", "src_ip": "185.242.246.36", "dest_ip": "185.254.126.122", "src_port": 48482, "dest_port": 3022}}'); INSERT INTO alerts VALUES(191,1772973961.542383909,'{"timestamp": "2026-03-08T13:46:01.542384+0100", "flow_id": 359199473417358, "event_type": "alert", "src_ip": "185.242.3.240", "src_port": 52569, "dest_ip": "185.254.126.122", "dest_port": 17025, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:46:01.542384+0100", "src_ip": "185.242.3.240", "dest_ip": "185.254.126.122", "src_port": 52569, "dest_port": 17025}}'); INSERT INTO alerts VALUES(192,1772974022.320754052,'{"timestamp": "2026-03-08T13:47:02.320754+0100", "flow_id": 1940577973905515, "event_type": "alert", "src_ip": "193.163.125.34", "src_port": 57725, "dest_ip": "185.254.126.122", "dest_port": 10190, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:47:02.320754+0100", "src_ip": "193.163.125.34", "dest_ip": "185.254.126.122", "src_port": 57725, "dest_port": 10190}}'); INSERT INTO alerts VALUES(193,1772974023.271893979,'{"timestamp": "2026-03-08T13:47:03.271894+0100", "flow_id": 2012204121232118, "event_type": "alert", "src_ip": "65.49.1.64", "src_port": 6353, "dest_ip": "185.254.126.122", "dest_port": 5351, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 30, "bytes_toclient": 0, "start": "2026-03-08T13:47:03.271894+0100", "src_ip": "65.49.1.64", "dest_ip": "185.254.126.122", "src_port": 6353, "dest_port": 5351}}'); INSERT INTO alerts VALUES(194,1772974090.970803022,'{"timestamp": "2026-03-08T13:48:10.970803+0100", "flow_id": 791869847134237, "event_type": "alert", "src_ip": "64.62.156.160", "src_port": 45848, "dest_ip": "185.254.126.122", "dest_port": 2002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:48:10.970803+0100", "src_ip": "64.62.156.160", "dest_ip": "185.254.126.122", "src_port": 45848, "dest_port": 2002}}'); INSERT INTO alerts VALUES(195,1772974129.59674406,'{"timestamp": "2026-03-08T13:48:49.596744+0100", "flow_id": 311198089084528, "event_type": "alert", "src_ip": "65.49.1.113", "src_port": 33483, "dest_ip": "185.254.126.122", "dest_port": 7000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:48:49.596744+0100", "src_ip": "65.49.1.113", "dest_ip": "185.254.126.122", "src_port": 33483, "dest_port": 7000}}'); INSERT INTO alerts VALUES(196,1772974188.669056892,'{"timestamp": "2026-03-08T13:49:48.669057+0100", "flow_id": 1184730860365608, "event_type": "alert", "src_ip": "147.185.132.245", "src_port": 52219, "dest_ip": "185.254.126.122", "dest_port": 49168, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:49:48.669057+0100", "src_ip": "147.185.132.245", "dest_ip": "185.254.126.122", "src_port": 52219, "dest_port": 49168}}'); INSERT INTO alerts VALUES(197,1772974195.274682045,'{"timestamp": "2026-03-08T13:49:55.274682+0100", "flow_id": 898275563411791, "event_type": "alert", "src_ip": "185.196.8.218", "src_port": 47348, "dest_ip": "185.254.126.122", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:49:55.274682+0100", "src_ip": "185.196.8.218", "dest_ip": "185.254.126.122", "src_port": 47348, "dest_port": 5900}}'); INSERT INTO alerts VALUES(198,1772974421.832417012,'{"timestamp": "2026-03-08T13:53:41.832417+0100", "flow_id": 1604883136656991, "event_type": "alert", "src_ip": "102.213.28.195", "src_port": 43392, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:53:41.832417+0100", "src_ip": "102.213.28.195", "dest_ip": "185.254.126.122", "src_port": 43392, "dest_port": 1433}}'); INSERT INTO alerts VALUES(199,1772974527.593869924,'{"timestamp": "2026-03-08T13:55:27.593870+0100", "flow_id": 1987706209604265, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 44392, "dest_ip": "185.254.126.122", "dest_port": 3897, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400037, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 38", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T13:55:27.593870+0100", "src_ip": "192.109.200.219", "dest_ip": "185.254.126.122", "src_port": 44392, "dest_port": 3897}}'); INSERT INTO alerts VALUES(200,1772974527.593869924,'{"timestamp": "2026-03-08T13:55:27.593870+0100", "flow_id": 1987706209604265, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 44392, "dest_ip": "185.254.126.122", "dest_port": 3897, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500020, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 11", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T13:55:27.593870+0100", "src_ip": "192.109.200.219", "dest_ip": "185.254.126.122", "src_port": 44392, "dest_port": 3897}}'); INSERT INTO alerts VALUES(201,1772974621.664828063,'{"timestamp": "2026-03-08T13:57:01.664828+0100", "flow_id": 1448039922556477, "event_type": "alert", "src_ip": "193.163.125.26", "src_port": 57034, "dest_ip": "185.254.126.122", "dest_port": 7103, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:57:01.664828+0100", "src_ip": "193.163.125.26", "dest_ip": "185.254.126.122", "src_port": 57034, "dest_port": 7103}}'); INSERT INTO alerts VALUES(202,1772974631.898323059,'{"timestamp": "2026-03-08T13:57:11.898323+0100", "flow_id": 2169421589848876, "event_type": "alert", "src_ip": "65.49.1.156", "src_port": 54364, "dest_ip": "185.254.126.122", "dest_port": 389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:57:11.898323+0100", "src_ip": "65.49.1.156", "dest_ip": "185.254.126.122", "src_port": 54364, "dest_port": 389}}'); INSERT INTO alerts VALUES(203,1772974638.816272974,'{"timestamp": "2026-03-08T13:57:18.816273+0100", "flow_id": 1817019493769203, "event_type": "alert", "src_ip": "167.94.138.140", "src_port": 19003, "dest_ip": "185.254.126.122", "dest_port": 830, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T13:57:18.816273+0100", "src_ip": "167.94.138.140", "dest_ip": "185.254.126.122", "src_port": 19003, "dest_port": 830}}'); INSERT INTO alerts VALUES(204,1772974734.892060995,'{"timestamp": "2026-03-08T13:58:54.892061+0100", "flow_id": 1861048654623477, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "185.254.126.122", "dest_port": 14577, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:58:54.892061+0100", "src_ip": "79.124.40.110", "dest_ip": "185.254.126.122", "src_port": 52537, "dest_port": 14577}}'); INSERT INTO alerts VALUES(205,1772974757.098740101,'{"timestamp": "2026-03-08T13:59:17.098740+0100", "flow_id": 1549985809622479, "event_type": "alert", "src_ip": "87.121.84.72", "src_port": 44065, "dest_ip": "185.254.126.122", "dest_port": 1916, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T13:59:17.098740+0100", "src_ip": "87.121.84.72", "dest_ip": "185.254.126.122", "src_port": 44065, "dest_port": 1916}}'); INSERT INTO alerts VALUES(206,1772974784.395139932,'{"timestamp": "2026-03-08T13:59:44.395140+0100", "flow_id": 8267483913007, "event_type": "alert", "src_ip": "193.163.125.4", "src_port": 45339, "dest_ip": "185.254.126.122", "dest_port": 139, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T13:59:44.395140+0100", "src_ip": "193.163.125.4", "dest_ip": "185.254.126.122", "src_port": 45339, "dest_port": 139}}'); INSERT INTO alerts VALUES(207,1772974792.553770065,'{"timestamp": "2026-03-08T13:59:52.553770+0100", "flow_id": 126624924063193, "event_type": "alert", "src_ip": "51.38.211.50", "src_port": 5104, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 441, "bytes_toclient": 0, "start": "2026-03-08T13:59:52.553770+0100", "src_ip": "51.38.211.50", "dest_ip": "185.254.126.122", "src_port": 5104, "dest_port": 5060}}'); INSERT INTO alerts VALUES(208,1772974792.553770065,'{"timestamp": "2026-03-08T13:59:52.553770+0100", "flow_id": 126624924063193, "event_type": "alert", "src_ip": "51.38.211.50", "src_port": 5104, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 441, "bytes_toclient": 0, "start": "2026-03-08T13:59:52.553770+0100", "src_ip": "51.38.211.50", "dest_ip": "185.254.126.122", "src_port": 5104, "dest_port": 5060}}'); INSERT INTO alerts VALUES(209,1772974827.887116909,'{"timestamp": "2026-03-08T14:00:27.887117+0100", "flow_id": 995392744993017, "event_type": "alert", "src_ip": "64.62.197.199", "src_port": 52265, "dest_ip": "185.254.126.122", "dest_port": 789, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:00:27.887117+0100", "src_ip": "64.62.197.199", "dest_ip": "185.254.126.122", "src_port": 52265, "dest_port": 789}}'); INSERT INTO alerts VALUES(210,1772974976.283885956,'{"timestamp": "2026-03-08T14:02:56.283886+0100", "flow_id": 93382320489786, "event_type": "alert", "src_ip": "64.62.197.221", "src_port": 46531, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:02:56.283886+0100", "src_ip": "64.62.197.221", "dest_ip": "185.254.126.122", "src_port": 46531, "dest_port": 3389}}'); INSERT INTO alerts VALUES(211,1772975137.527179957,'{"timestamp": "2026-03-08T14:05:37.527180+0100", "flow_id": 293896745331994, "event_type": "alert", "src_ip": "167.94.138.157", "src_port": 15710, "dest_ip": "185.254.126.122", "dest_port": 8008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:05:37.527180+0100", "src_ip": "167.94.138.157", "dest_ip": "185.254.126.122", "src_port": 15710, "dest_port": 8008}}'); INSERT INTO alerts VALUES(212,1772975140.774056912,'{"timestamp": "2026-03-08T14:05:40.774057+0100", "flow_id": 1354226936202242, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 57202, "dest_ip": "185.254.126.122", "dest_port": 3433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:05:40.774057+0100", "src_ip": "45.142.193.7", "dest_ip": "185.254.126.122", "src_port": 57202, "dest_port": 3433}}'); INSERT INTO alerts VALUES(213,1772975154.949739934,'{"timestamp": "2026-03-08T14:05:54.949740+0100", "flow_id": 701403291115170, "event_type": "alert", "src_ip": "87.121.84.35", "src_port": 60001, "dest_ip": "185.254.126.122", "dest_port": 22123, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:05:54.949740+0100", "src_ip": "87.121.84.35", "dest_ip": "185.254.126.122", "src_port": 60001, "dest_port": 22123}}'); INSERT INTO alerts VALUES(214,1772975165.684034109,'{"timestamp": "2026-03-08T14:06:05.684034+0100", "flow_id": 1530531227498072, "event_type": "alert", "src_ip": "64.89.161.182", "src_port": 46029, "dest_ip": "185.254.126.122", "dest_port": 61080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T14:06:05.684034+0100", "src_ip": "64.89.161.182", "dest_ip": "185.254.126.122", "src_port": 46029, "dest_port": 61080}}'); INSERT INTO alerts VALUES(215,1772975214.755250931,'{"timestamp": "2026-03-08T14:06:54.755251+0100", "flow_id": 1836405428198177, "event_type": "alert", "src_ip": "77.83.39.250", "src_port": 51984, "dest_ip": "185.254.126.122", "dest_port": 2525, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400008, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 9", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:06:54.755251+0100", "src_ip": "77.83.39.250", "dest_ip": "185.254.126.122", "src_port": 51984, "dest_port": 2525}}'); INSERT INTO alerts VALUES(216,1772975221.367921114,'{"timestamp": "2026-03-08T14:07:01.367921+0100", "flow_id": 1580208902948040, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59828, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2057745, "rev": 1, "signature": "ET INFO DNS Query to Cloudflare Page Developer Domain (pages .dev)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_11_20"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_11_20"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14505, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "kaufradar-teaser.pages.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-08T14:07:01.367921+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59828, "dest_port": 53}}'); INSERT INTO alerts VALUES(217,1772975223.293417931,'{"timestamp": "2026-03-08T14:07:03.293418+0100", "flow_id": 2104648963315777, "event_type": "alert", "src_ip": "147.185.132.56", "src_port": 51517, "dest_ip": "185.254.126.122", "dest_port": 47004, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:07:03.293418+0100", "src_ip": "147.185.132.56", "dest_ip": "185.254.126.122", "src_port": 51517, "dest_port": 47004}}'); INSERT INTO alerts VALUES(218,1772975263.982474088,'{"timestamp": "2026-03-08T14:07:43.982474+0100", "flow_id": 2249371001362020, "event_type": "alert", "src_ip": "167.94.138.147", "src_port": 35527, "dest_ip": "185.254.126.122", "dest_port": 47809, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 45, "bytes_toclient": 0, "start": "2026-03-08T14:07:43.982474+0100", "src_ip": "167.94.138.147", "dest_ip": "185.254.126.122", "src_port": 35527, "dest_port": 47809}}'); INSERT INTO alerts VALUES(219,1772975265.34902811,'{"timestamp": "2026-03-08T14:07:45.349028+0100", "flow_id": 373164906832185, "event_type": "alert", "src_ip": "193.163.125.30", "src_port": 53232, "dest_ip": "185.254.126.122", "dest_port": 50004, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:07:45.349028+0100", "src_ip": "193.163.125.30", "dest_ip": "185.254.126.122", "src_port": 53232, "dest_port": 50004}}'); INSERT INTO alerts VALUES(220,1772975299.792582036,'{"timestamp": "2026-03-08T14:08:19.792582+0100", "flow_id": 870839898506859, "event_type": "alert", "src_ip": "181.214.147.43", "src_port": 43387, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400033, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 34", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:08:19.792582+0100", "src_ip": "181.214.147.43", "dest_ip": "185.254.126.122", "src_port": 43387, "dest_port": 80}}'); INSERT INTO alerts VALUES(221,1772975320.238785983,'{"timestamp": "2026-03-08T14:08:40.238786+0100", "flow_id": 181154653190122, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 44979, "dest_ip": "185.254.126.122", "dest_port": 26040, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:08:40.238786+0100", "src_ip": "167.94.146.40", "dest_ip": "185.254.126.122", "src_port": 44979, "dest_port": 26040}}'); INSERT INTO alerts VALUES(222,1772975340.78540206,'{"timestamp": "2026-03-08T14:09:00.785402+0100", "flow_id": 1402952326132448, "event_type": "alert", "src_ip": "87.121.84.85", "src_port": 45644, "dest_ip": "185.254.126.122", "dest_port": 2011, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:09:00.785402+0100", "src_ip": "87.121.84.85", "dest_ip": "185.254.126.122", "src_port": 45644, "dest_port": 2011}}'); INSERT INTO alerts VALUES(223,1772975485.243180036,'{"timestamp": "2026-03-08T14:11:25.243180+0100", "flow_id": 1607401251848786, "event_type": "alert", "src_ip": "64.62.156.70", "src_port": 56076, "dest_ip": "185.254.126.122", "dest_port": 389, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ldap", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 80, "bytes_toclient": 0, "start": "2026-03-08T14:11:25.243180+0100", "src_ip": "64.62.156.70", "dest_ip": "185.254.126.122", "src_port": 56076, "dest_port": 389}}'); INSERT INTO alerts VALUES(224,1772975571.847101927,'{"timestamp": "2026-03-08T14:12:51.847102+0100", "flow_id": 1105003646254402, "event_type": "alert", "src_ip": "193.163.125.23", "src_port": 48449, "dest_ip": "185.254.126.122", "dest_port": 135, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:12:51.847102+0100", "src_ip": "193.163.125.23", "dest_ip": "185.254.126.122", "src_port": 48449, "dest_port": 135}}'); INSERT INTO alerts VALUES(225,1772975623.74753189,'{"timestamp": "2026-03-08T14:13:43.747532+0100", "flow_id": 2084725983153193, "event_type": "alert", "src_ip": "147.185.132.160", "src_port": 54614, "dest_ip": "185.254.126.122", "dest_port": 47320, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:13:43.747532+0100", "src_ip": "147.185.132.160", "dest_ip": "185.254.126.122", "src_port": 54614, "dest_port": 47320}}'); INSERT INTO alerts VALUES(226,1772975783.735387087,'{"timestamp": "2026-03-08T14:16:23.735387+0100", "flow_id": 2032564759054825, "event_type": "alert", "src_ip": "193.163.125.19", "src_port": 44347, "dest_ip": "185.254.126.122", "dest_port": 5052, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:16:23.735387+0100", "src_ip": "193.163.125.19", "dest_ip": "185.254.126.122", "src_port": 44347, "dest_port": 5052}}'); INSERT INTO alerts VALUES(227,1772975806.25959897,'{"timestamp": "2026-03-08T14:16:46.259599+0100", "flow_id": 1959396805034725, "event_type": "alert", "src_ip": "193.32.162.142", "src_port": 55802, "dest_ip": "185.254.126.122", "dest_port": 40190, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:16:46.259599+0100", "src_ip": "193.32.162.142", "dest_ip": "185.254.126.122", "src_port": 55802, "dest_port": 40190}}'); INSERT INTO alerts VALUES(228,1772975868.314323903,'{"timestamp": "2026-03-08T14:17:48.314324+0100", "flow_id": 1350012979855452, "event_type": "alert", "src_ip": "147.185.132.164", "src_port": 52283, "dest_ip": "185.254.126.122", "dest_port": 37321, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:17:48.314324+0100", "src_ip": "147.185.132.164", "dest_ip": "185.254.126.122", "src_port": 52283, "dest_port": 37321}}'); INSERT INTO alerts VALUES(229,1772975913.3621099,'{"timestamp": "2026-03-08T14:18:33.362110+0100", "flow_id": 429350844378781, "event_type": "alert", "src_ip": "167.94.138.143", "src_port": 52285, "dest_ip": "185.254.126.122", "dest_port": 5349, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 150, "bytes_toclient": 0, "start": "2026-03-08T14:18:33.362110+0100", "src_ip": "167.94.138.143", "dest_ip": "185.254.126.122", "src_port": 52285, "dest_port": 5349}}'); INSERT INTO alerts VALUES(230,1772975924.410053968,'{"timestamp": "2026-03-08T14:18:44.410054+0100", "flow_id": 1198219233316296, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 49460, "dest_ip": "185.254.126.122", "dest_port": 50022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:18:44.410054+0100", "src_ip": "185.242.246.37", "dest_ip": "185.254.126.122", "src_port": 49460, "dest_port": 50022}}'); INSERT INTO alerts VALUES(231,1772975924.410053968,'{"timestamp": "2026-03-08T14:18:44.410054+0100", "flow_id": 1198219233316296, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 49460, "dest_ip": "185.254.126.122", "dest_port": 50022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:18:44.410054+0100", "src_ip": "185.242.246.37", "dest_ip": "185.254.126.122", "src_port": 49460, "dest_port": 50022}}'); INSERT INTO alerts VALUES(232,1772975946.425246,'{"timestamp": "2026-03-08T14:19:06.425246+0100", "flow_id": 700521355454167, "event_type": "alert", "src_ip": "40.160.34.88", "src_port": 46706, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2500028, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 15", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:19:06.425246+0100", "src_ip": "40.160.34.88", "dest_ip": "185.254.126.122", "src_port": 46706, "dest_port": 22}}'); INSERT INTO alerts VALUES(233,1772975998.562417984,'{"timestamp": "2026-03-08T14:19:58.562418+0100", "flow_id": 1852617234728918, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 55296, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:19:58.562418+0100", "src_ip": "79.124.62.126", "dest_ip": "185.254.126.122", "src_port": 55296, "dest_port": 3389}}'); INSERT INTO alerts VALUES(234,1772975999.720503091,'{"timestamp": "2026-03-08T14:19:59.720503+0100", "flow_id": 2250112204786612, "event_type": "alert", "src_ip": "193.163.125.53", "src_port": 20400, "dest_ip": "185.254.126.122", "dest_port": 12346, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-08T14:19:59.720503+0100", "src_ip": "193.163.125.53", "dest_ip": "185.254.126.122", "src_port": 20400, "dest_port": 12346}}'); INSERT INTO alerts VALUES(235,1772976044.807852984,'{"timestamp": "2026-03-08T14:20:44.807853+0100", "flow_id": 1217904660873880, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56841, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2057745, "rev": 1, "signature": "ET INFO DNS Query to Cloudflare Page Developer Domain (pages .dev)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_11_20"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_11_20"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39806, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "kaufradar-teaser.pages.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-08T14:20:44.807853+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56841, "dest_port": 53}}'); INSERT INTO alerts VALUES(236,1772976050.982892991,'{"timestamp": "2026-03-08T14:20:50.982893+0100", "flow_id": 843795587048910, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 53983, "dest_ip": "185.254.126.122", "dest_port": 30314, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:20:50.982893+0100", "src_ip": "79.124.62.134", "dest_ip": "185.254.126.122", "src_port": 53983, "dest_port": 30314}}'); INSERT INTO alerts VALUES(237,1772976073.724261999,'{"timestamp": "2026-03-08T14:21:13.724262+0100", "flow_id": 295933604250087, "event_type": "alert", "src_ip": "88.210.63.191", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 44346, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:21:13.724262+0100", "src_ip": "88.210.63.191", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 44346}}'); INSERT INTO alerts VALUES(238,1772976116.456006051,'{"timestamp": "2026-03-08T14:21:56.456006+0100", "flow_id": 1395583690010345, "event_type": "alert", "src_ip": "167.94.138.158", "src_port": 20725, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:21:56.456006+0100", "src_ip": "167.94.138.158", "dest_ip": "185.254.126.122", "src_port": 20725, "dest_port": 5432}}'); INSERT INTO alerts VALUES(239,1772976116.456006051,'{"timestamp": "2026-03-08T14:21:56.456006+0100", "flow_id": 1395583690010345, "event_type": "alert", "src_ip": "167.94.138.158", "src_port": 20725, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:21:56.456006+0100", "src_ip": "167.94.138.158", "dest_ip": "185.254.126.122", "src_port": 20725, "dest_port": 5432}}'); INSERT INTO alerts VALUES(240,1772976120.276458979,'{"timestamp": "2026-03-08T14:22:00.276459+0100", "flow_id": 61486045096029, "event_type": "alert", "src_ip": "66.132.153.149", "src_port": 22362, "dest_ip": "185.254.126.122", "dest_port": 3702, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 655, "bytes_toclient": 0, "start": "2026-03-08T14:22:00.276459+0100", "src_ip": "66.132.153.149", "dest_ip": "185.254.126.122", "src_port": 22362, "dest_port": 3702}}'); INSERT INTO alerts VALUES(241,1772976235.51304698,'{"timestamp": "2026-03-08T14:23:55.513047+0100", "flow_id": 1077623695247081, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 6087, "dest_ip": "185.254.126.122", "dest_port": 2135, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:23:55.513047+0100", "src_ip": "167.94.146.45", "dest_ip": "185.254.126.122", "src_port": 6087, "dest_port": 2135}}'); INSERT INTO alerts VALUES(242,1772976293.109487057,'{"timestamp": "2026-03-08T14:24:53.109487+0100", "flow_id": 1596145766071911, "event_type": "alert", "src_ip": "193.163.125.55", "src_port": 22144, "dest_ip": "185.254.126.122", "dest_port": 427, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-08T14:24:53.109487+0100", "src_ip": "193.163.125.55", "dest_ip": "185.254.126.122", "src_port": 22144, "dest_port": 427}}'); INSERT INTO alerts VALUES(243,1772976308.540764094,'{"timestamp": "2026-03-08T14:25:08.540764+0100", "flow_id": 1196665475403879, "event_type": "alert", "src_ip": "147.185.132.142", "src_port": 52121, "dest_ip": "185.254.126.122", "dest_port": 49467, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:25:08.540764+0100", "src_ip": "147.185.132.142", "dest_ip": "185.254.126.122", "src_port": 52121, "dest_port": 49467}}'); INSERT INTO alerts VALUES(244,1772976318.810043097,'{"timestamp": "2026-03-08T14:25:18.810043+0100", "flow_id": 1790261935344446, "event_type": "alert", "src_ip": "193.163.125.21", "src_port": 37579, "dest_ip": "185.254.126.122", "dest_port": 7444, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:25:18.810043+0100", "src_ip": "193.163.125.21", "dest_ip": "185.254.126.122", "src_port": 37579, "dest_port": 7444}}'); INSERT INTO alerts VALUES(245,1772976321.865226985,'{"timestamp": "2026-03-08T14:25:21.865227+0100", "flow_id": 338424183228074, "event_type": "alert", "src_ip": "64.62.156.107", "src_port": 40182, "dest_ip": "185.254.126.122", "dest_port": 4786, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:25:21.865227+0100", "src_ip": "64.62.156.107", "dest_ip": "185.254.126.122", "src_port": 40182, "dest_port": 4786}}'); INSERT INTO alerts VALUES(246,1772976380.630831004,'{"timestamp": "2026-03-08T14:26:20.630831+0100", "flow_id": 1302027836661937, "event_type": "alert", "src_ip": "65.49.1.34", "src_port": 49895, "dest_ip": "185.254.126.122", "dest_port": 50075, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:26:20.630831+0100", "src_ip": "65.49.1.34", "dest_ip": "185.254.126.122", "src_port": 49895, "dest_port": 50075}}'); INSERT INTO alerts VALUES(247,1772976399.886068106,'{"timestamp": "2026-03-08T14:26:39.886068+0100", "flow_id": 2116783698364033, "event_type": "alert", "src_ip": "193.163.125.20", "src_port": 48530, "dest_ip": "185.254.126.122", "dest_port": 111, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:26:39.886068+0100", "src_ip": "193.163.125.20", "dest_ip": "185.254.126.122", "src_port": 48530, "dest_port": 111}}'); INSERT INTO alerts VALUES(248,1772976505.395400047,'{"timestamp": "2026-03-08T14:28:25.395400+0100", "flow_id": 290857235626246, "event_type": "alert", "src_ip": "185.156.73.180", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 666, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:28:25.395400+0100", "src_ip": "185.156.73.180", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 666}}'); INSERT INTO alerts VALUES(249,1772976543.955166102,'{"timestamp": "2026-03-08T14:29:03.955166+0100", "flow_id": 2132084681709813, "event_type": "alert", "src_ip": "64.62.156.20", "src_port": 39615, "dest_ip": "185.254.126.122", "dest_port": 212, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:29:03.955166+0100", "src_ip": "64.62.156.20", "dest_ip": "185.254.126.122", "src_port": 39615, "dest_port": 212}}'); INSERT INTO alerts VALUES(250,1772976571.801059008,'{"timestamp": "2026-03-08T14:29:31.801059+0100", "flow_id": 907248417813152, "event_type": "alert", "src_ip": "64.62.197.93", "src_port": 48207, "dest_ip": "185.254.126.122", "dest_port": 6161, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:29:31.801059+0100", "src_ip": "64.62.197.93", "dest_ip": "185.254.126.122", "src_port": 48207, "dest_port": 6161}}'); INSERT INTO alerts VALUES(251,1772976610.414431095,'{"timestamp": "2026-03-08T14:30:10.414431+0100", "flow_id": 654071762892043, "event_type": "alert", "src_ip": "65.49.1.207", "src_port": 42368, "dest_ip": "185.254.126.122", "dest_port": 135, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:30:10.414431+0100", "src_ip": "65.49.1.207", "dest_ip": "185.254.126.122", "src_port": 42368, "dest_port": 135}}'); INSERT INTO alerts VALUES(252,1772976658.338177919,'{"timestamp": "2026-03-08T14:30:58.338178+0100", "flow_id": 608040691409149, "event_type": "alert", "src_ip": "65.49.1.237", "src_port": 53312, "dest_ip": "185.254.126.122", "dest_port": 993, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:30:58.338178+0100", "src_ip": "65.49.1.237", "dest_ip": "185.254.126.122", "src_port": 53312, "dest_port": 993}}'); INSERT INTO alerts VALUES(253,1772976673.524997949,'{"timestamp": "2026-03-08T14:31:13.524998+0100", "flow_id": 284527817534552, "event_type": "alert", "src_ip": "147.185.132.170", "src_port": 54362, "dest_ip": "185.254.126.122", "dest_port": 1688, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:31:13.524998+0100", "src_ip": "147.185.132.170", "dest_ip": "185.254.126.122", "src_port": 54362, "dest_port": 1688}}'); INSERT INTO alerts VALUES(254,1772976694.443005085,'{"timestamp": "2026-03-08T14:31:34.443005+0100", "flow_id": 1902692197817503, "event_type": "alert", "src_ip": "65.49.1.210", "src_port": 54940, "dest_ip": "185.254.126.122", "dest_port": 17000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:31:34.443005+0100", "src_ip": "65.49.1.210", "dest_ip": "185.254.126.122", "src_port": 54940, "dest_port": 17000}}'); INSERT INTO alerts VALUES(255,1772976704.1768291,'{"timestamp": "2026-03-08T14:31:44.176829+0100", "flow_id": 196528782679061, "event_type": "alert", "src_ip": "65.49.1.146", "src_port": 44718, "dest_ip": "185.254.126.122", "dest_port": 8873, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:31:44.176829+0100", "src_ip": "65.49.1.146", "dest_ip": "185.254.126.122", "src_port": 44718, "dest_port": 8873}}'); INSERT INTO alerts VALUES(256,1772976714.83255291,'{"timestamp": "2026-03-08T14:31:54.832553+0100", "flow_id": 761038257219682, "event_type": "alert", "src_ip": "64.62.156.229", "src_port": 35668, "dest_ip": "185.254.126.122", "dest_port": 6000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:31:54.832553+0100", "src_ip": "64.62.156.229", "dest_ip": "185.254.126.122", "src_port": 35668, "dest_port": 6000}}'); INSERT INTO alerts VALUES(257,1772976726.60194707,'{"timestamp": "2026-03-08T14:32:06.601947+0100", "flow_id": 1740921021944363, "event_type": "alert", "src_ip": "64.62.156.127", "src_port": 32781, "dest_ip": "185.254.126.122", "dest_port": 49665, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:32:06.601947+0100", "src_ip": "64.62.156.127", "dest_ip": "185.254.126.122", "src_port": 32781, "dest_port": 49665}}'); INSERT INTO alerts VALUES(258,1772976735.599164009,'{"timestamp": "2026-03-08T14:32:15.599164+0100", "flow_id": 2010440681685534, "event_type": "alert", "src_ip": "167.94.138.129", "src_port": 44038, "dest_ip": "185.254.126.122", "dest_port": 1194, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 42, "bytes_toclient": 0, "start": "2026-03-08T14:32:15.599164+0100", "src_ip": "167.94.138.129", "dest_ip": "185.254.126.122", "src_port": 44038, "dest_port": 1194}}'); INSERT INTO alerts VALUES(259,1772976738.309305906,'{"timestamp": "2026-03-08T14:32:18.309306+0100", "flow_id": 765511726626055, "event_type": "alert", "src_ip": "147.185.132.205", "src_port": 52049, "dest_ip": "185.254.126.122", "dest_port": 50921, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:32:18.309306+0100", "src_ip": "147.185.132.205", "dest_ip": "185.254.126.122", "src_port": 52049, "dest_port": 50921}}'); INSERT INTO alerts VALUES(260,1772976795.745842934,'{"timestamp": "2026-03-08T14:33:15.745843+0100", "flow_id": 951575417814810, "event_type": "alert", "src_ip": "64.62.197.180", "src_port": 40286, "dest_ip": "185.254.126.122", "dest_port": 5803, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:33:15.745843+0100", "src_ip": "64.62.197.180", "dest_ip": "185.254.126.122", "src_port": 40286, "dest_port": 5803}}'); INSERT INTO alerts VALUES(261,1772976874.44428897,'{"timestamp": "2026-03-08T14:34:34.444289+0100", "flow_id": 782307165606820, "event_type": "alert", "src_ip": "88.210.63.192", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 44341, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:34:34.444289+0100", "src_ip": "88.210.63.192", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 44341}}'); INSERT INTO alerts VALUES(262,1772976940.380983114,'{"timestamp": "2026-03-08T14:35:40.380983+0100", "flow_id": 1354836114410276, "event_type": "alert", "src_ip": "204.76.203.18", "src_port": 44177, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T14:35:40.380983+0100", "src_ip": "204.76.203.18", "dest_ip": "185.254.126.122", "src_port": 44177, "dest_port": 8080}}'); INSERT INTO alerts VALUES(263,1772976940.380983114,'{"timestamp": "2026-03-08T14:35:40.380983+0100", "flow_id": 1354836114410276, "event_type": "alert", "src_ip": "204.76.203.18", "src_port": 44177, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T14:35:40.380983+0100", "src_ip": "204.76.203.18", "dest_ip": "185.254.126.122", "src_port": 44177, "dest_port": 8080}}'); INSERT INTO alerts VALUES(264,1772976994.542766094,'{"timestamp": "2026-03-08T14:36:34.542766+0100", "flow_id": 642316289251841, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 56397, "dest_ip": "185.254.126.122", "dest_port": 10030, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:36:34.542766+0100", "src_ip": "185.242.246.38", "dest_ip": "185.254.126.122", "src_port": 56397, "dest_port": 10030}}'); INSERT INTO alerts VALUES(265,1772976994.542766094,'{"timestamp": "2026-03-08T14:36:34.542766+0100", "flow_id": 642316289251841, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 56397, "dest_ip": "185.254.126.122", "dest_port": 10030, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:36:34.542766+0100", "src_ip": "185.242.246.38", "dest_ip": "185.254.126.122", "src_port": 56397, "dest_port": 10030}}'); INSERT INTO alerts VALUES(266,1772977003.980624914,'{"timestamp": "2026-03-08T14:36:43.980625+0100", "flow_id": 1115529438221406, "event_type": "alert", "src_ip": "64.62.156.45", "src_port": 37707, "dest_ip": "185.254.126.122", "dest_port": 21, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:36:43.980625+0100", "src_ip": "64.62.156.45", "dest_ip": "185.254.126.122", "src_port": 37707, "dest_port": 21}}'); INSERT INTO alerts VALUES(267,1772977028.916932106,'{"timestamp": "2026-03-08T14:37:08.916932+0100", "flow_id": 1404918568163931, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 53812, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:37:08.916932+0100", "src_ip": "79.124.62.230", "dest_ip": "185.254.126.122", "src_port": 53812, "dest_port": 3389}}'); INSERT INTO alerts VALUES(268,1772977040.146516084,'{"timestamp": "2026-03-08T14:37:20.146516+0100", "flow_id": 66335159063691, "event_type": "alert", "src_ip": "167.94.146.35", "src_port": 26703, "dest_ip": "185.254.126.122", "dest_port": 28106, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:37:20.146516+0100", "src_ip": "167.94.146.35", "dest_ip": "185.254.126.122", "src_port": 26703, "dest_port": 28106}}'); INSERT INTO alerts VALUES(269,1772977052.007858991,'{"timestamp": "2026-03-08T14:37:32.007859+0100", "flow_id": 1159658200109061, "event_type": "alert", "src_ip": "45.156.87.50", "src_port": 53442, "dest_ip": "185.254.126.122", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:37:32.007859+0100", "src_ip": "45.156.87.50", "dest_ip": "185.254.126.122", "src_port": 53442, "dest_port": 23}}'); INSERT INTO alerts VALUES(270,1772977056.940897942,'{"timestamp": "2026-03-08T14:37:36.940898+0100", "flow_id": 100476886327177, "event_type": "alert", "src_ip": "65.49.1.129", "src_port": 55729, "dest_ip": "185.254.126.122", "dest_port": 5672, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:37:36.940898+0100", "src_ip": "65.49.1.129", "dest_ip": "185.254.126.122", "src_port": 55729, "dest_port": 5672}}'); INSERT INTO alerts VALUES(271,1772977060.931516886,'{"timestamp": "2026-03-08T14:37:40.931517+0100", "flow_id": 1186085421884307, "event_type": "alert", "src_ip": "64.62.197.60", "src_port": 46684, "dest_ip": "185.254.126.122", "dest_port": 44818, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:37:40.931517+0100", "src_ip": "64.62.197.60", "dest_ip": "185.254.126.122", "src_port": 46684, "dest_port": 44818}}'); INSERT INTO alerts VALUES(272,1772977114.180310965,'{"timestamp": "2026-03-08T14:38:34.180311+0100", "flow_id": 774431810500726, "event_type": "alert", "src_ip": "172.94.9.253", "src_port": 45706, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400031, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 32", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:38:34.180311+0100", "src_ip": "172.94.9.253", "dest_ip": "185.254.126.122", "src_port": 45706, "dest_port": 443}}'); INSERT INTO alerts VALUES(273,1772977144.908554077,'{"timestamp": "2026-03-08T14:39:04.908554+0100", "flow_id": 243035760034035, "event_type": "alert", "src_ip": "167.94.138.138", "src_port": 54868, "dest_ip": "185.254.126.122", "dest_port": 1311, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:39:04.908554+0100", "src_ip": "167.94.138.138", "dest_ip": "185.254.126.122", "src_port": 54868, "dest_port": 1311}}'); INSERT INTO alerts VALUES(274,1772977162.459465026,'{"timestamp": "2026-03-08T14:39:22.459465+0100", "flow_id": 566015522290740, "event_type": "alert", "src_ip": "193.163.125.14", "src_port": 44761, "dest_ip": "185.254.126.122", "dest_port": 20243, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:39:22.459465+0100", "src_ip": "193.163.125.14", "dest_ip": "185.254.126.122", "src_port": 44761, "dest_port": 20243}}'); INSERT INTO alerts VALUES(275,1772977213.662091971,'{"timestamp": "2026-03-08T14:40:13.662092+0100", "flow_id": 1436289439013923, "event_type": "alert", "src_ip": "167.94.146.34", "src_port": 50047, "dest_ip": "185.254.126.122", "dest_port": 40965, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:40:13.662092+0100", "src_ip": "167.94.146.34", "dest_ip": "185.254.126.122", "src_port": 50047, "dest_port": 40965}}'); INSERT INTO alerts VALUES(276,1772977308.700778962,'{"timestamp": "2026-03-08T14:41:48.700779+0100", "flow_id": 1320976130264721, "event_type": "alert", "src_ip": "91.196.152.60", "src_port": 48905, "dest_ip": "185.254.126.122", "dest_port": 666, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:41:48.700779+0100", "src_ip": "91.196.152.60", "dest_ip": "185.254.126.122", "src_port": 48905, "dest_port": 666}}'); INSERT INTO alerts VALUES(277,1772977350.017081975,'{"timestamp": "2026-03-08T14:42:30.017082+0100", "flow_id": 1762216513746088, "event_type": "alert", "src_ip": "176.65.149.45", "src_port": 43418, "dest_ip": "185.254.126.122", "dest_port": 8081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:42:30.017082+0100", "src_ip": "176.65.149.45", "dest_ip": "185.254.126.122", "src_port": 43418, "dest_port": 8081}}'); INSERT INTO alerts VALUES(278,1772977457.0069561,'{"timestamp": "2026-03-08T14:44:17.006956+0100", "flow_id": 311353605634711, "event_type": "alert", "src_ip": "91.196.152.52", "src_port": 55732, "dest_ip": "185.254.126.122", "dest_port": 63210, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:44:17.006956+0100", "src_ip": "91.196.152.52", "dest_ip": "185.254.126.122", "src_port": 55732, "dest_port": 63210}}'); INSERT INTO alerts VALUES(279,1772977471.248222113,'{"timestamp": "2026-03-08T14:44:31.248222+0100", "flow_id": 2192007565483533, "event_type": "alert", "src_ip": "167.94.138.108", "src_port": 6344, "dest_ip": "185.254.126.122", "dest_port": 15167, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:44:31.248222+0100", "src_ip": "167.94.138.108", "dest_ip": "185.254.126.122", "src_port": 6344, "dest_port": 15167}}'); INSERT INTO alerts VALUES(280,1772977474.122344017,'{"timestamp": "2026-03-08T14:44:34.122344+0100", "flow_id": 806938616802784, "event_type": "alert", "src_ip": "64.62.156.226", "src_port": 33800, "dest_ip": "185.254.126.122", "dest_port": 5904, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:44:34.122344+0100", "src_ip": "64.62.156.226", "dest_ip": "185.254.126.122", "src_port": 33800, "dest_port": 5904}}'); INSERT INTO alerts VALUES(281,1772977508.366415977,'{"timestamp": "2026-03-08T14:45:08.366416+0100", "flow_id": 1292272911205355, "event_type": "alert", "src_ip": "167.94.146.38", "src_port": 22149, "dest_ip": "185.254.126.122", "dest_port": 14097, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:45:08.366416+0100", "src_ip": "167.94.146.38", "dest_ip": "185.254.126.122", "src_port": 22149, "dest_port": 14097}}'); INSERT INTO alerts VALUES(282,1772977620.483668088,'{"timestamp": "2026-03-08T14:47:00.483668+0100", "flow_id": 1232916084521345, "event_type": "alert", "src_ip": "64.89.163.154", "src_port": 57398, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:47:00.483668+0100", "src_ip": "64.89.163.154", "dest_ip": "185.254.126.122", "src_port": 57398, "dest_port": 3306}}'); INSERT INTO alerts VALUES(283,1772977620.483668088,'{"timestamp": "2026-03-08T14:47:00.483668+0100", "flow_id": 1232916084521345, "event_type": "alert", "src_ip": "64.89.163.154", "src_port": 57398, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:47:00.483668+0100", "src_ip": "64.89.163.154", "dest_ip": "185.254.126.122", "src_port": 57398, "dest_port": 3306}}'); INSERT INTO alerts VALUES(284,1772977644.444873095,'{"timestamp": "2026-03-08T14:47:24.444873+0100", "flow_id": 1347766599900891, "event_type": "alert", "src_ip": "65.49.1.170", "src_port": 52795, "dest_ip": "185.254.126.122", "dest_port": 50070, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:47:24.444873+0100", "src_ip": "65.49.1.170", "dest_ip": "185.254.126.122", "src_port": 52795, "dest_port": 50070}}'); INSERT INTO alerts VALUES(285,1772977657.760354043,'{"timestamp": "2026-03-08T14:47:37.760354+0100", "flow_id": 450948415718539, "event_type": "alert", "src_ip": "64.62.156.133", "src_port": 55238, "dest_ip": "185.254.126.122", "dest_port": 2323, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:47:37.760354+0100", "src_ip": "64.62.156.133", "dest_ip": "185.254.126.122", "src_port": 55238, "dest_port": 2323}}'); INSERT INTO alerts VALUES(286,1772977678.790333986,'{"timestamp": "2026-03-08T14:47:58.790334+0100", "flow_id": 1705611108388327, "event_type": "alert", "src_ip": "185.242.226.61", "src_port": 47537, "dest_ip": "185.254.126.122", "dest_port": 10633, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:47:58.790334+0100", "src_ip": "185.242.226.61", "dest_ip": "185.254.126.122", "src_port": 47537, "dest_port": 10633}}'); INSERT INTO alerts VALUES(287,1772977679.146720886,'{"timestamp": "2026-03-08T14:47:59.146721+0100", "flow_id": 2037540990493370, "event_type": "alert", "src_ip": "198.38.89.100", "src_port": 45865, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:47:59.146721+0100", "src_ip": "198.38.89.100", "dest_ip": "185.254.126.122", "src_port": 45865, "dest_port": 1433}}'); INSERT INTO alerts VALUES(288,1772977707.427251101,'{"timestamp": "2026-03-08T14:48:27.427251+0100", "flow_id": 990605684423138, "event_type": "alert", "src_ip": "64.62.156.214", "src_port": 37543, "dest_ip": "185.254.126.122", "dest_port": 2375, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:48:27.427251+0100", "src_ip": "64.62.156.214", "dest_ip": "185.254.126.122", "src_port": 37543, "dest_port": 2375}}'); INSERT INTO alerts VALUES(289,1772977745.803937911,'{"timestamp": "2026-03-08T14:49:05.803938+0100", "flow_id": 356665957727382, "event_type": "alert", "src_ip": "193.163.125.35", "src_port": 38126, "dest_ip": "185.254.126.122", "dest_port": 9015, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:49:05.803938+0100", "src_ip": "193.163.125.35", "dest_ip": "185.254.126.122", "src_port": 38126, "dest_port": 9015}}'); INSERT INTO alerts VALUES(290,1772977764.452572108,'{"timestamp": "2026-03-08T14:49:24.452572+0100", "flow_id": 1380833434061771, "event_type": "alert", "src_ip": "64.62.197.84", "src_port": 58569, "dest_ip": "185.254.126.122", "dest_port": 1911, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:49:24.452572+0100", "src_ip": "64.62.197.84", "dest_ip": "185.254.126.122", "src_port": 58569, "dest_port": 1911}}'); INSERT INTO alerts VALUES(291,1772977901.854152918,'{"timestamp": "2026-03-08T14:51:41.854153+0100", "flow_id": 1416762149649366, "event_type": "alert", "src_ip": "45.142.154.99", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 18080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:51:41.854153+0100", "src_ip": "45.142.154.99", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 18080}}'); INSERT INTO alerts VALUES(292,1772977912.220045089,'{"timestamp": "2026-03-08T14:51:52.220045+0100", "flow_id": 100661274231855, "event_type": "alert", "src_ip": "65.49.1.150", "src_port": 48757, "dest_ip": "185.254.126.122", "dest_port": 61617, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:51:52.220045+0100", "src_ip": "65.49.1.150", "dest_ip": "185.254.126.122", "src_port": 48757, "dest_port": 61617}}'); INSERT INTO alerts VALUES(293,1772977953.834024907,'{"timestamp": "2026-03-08T14:52:33.834025+0100", "flow_id": 485888926761719, "event_type": "alert", "src_ip": "65.49.1.112", "src_port": 53811, "dest_ip": "185.254.126.122", "dest_port": 63210, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:52:33.834025+0100", "src_ip": "65.49.1.112", "dest_ip": "185.254.126.122", "src_port": 53811, "dest_port": 63210}}'); INSERT INTO alerts VALUES(294,1772977967.267400026,'{"timestamp": "2026-03-08T14:52:47.267400+0100", "flow_id": 1992902314480801, "event_type": "alert", "src_ip": "103.31.82.141", "src_port": 40947, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:52:47.267400+0100", "src_ip": "103.31.82.141", "dest_ip": "185.254.126.122", "src_port": 40947, "dest_port": 1433}}'); INSERT INTO alerts VALUES(295,1772978004.295329093,'{"timestamp": "2026-03-08T14:53:24.295329+0100", "flow_id": 1268428987857058, "event_type": "alert", "src_ip": "91.224.92.177", "src_port": 59680, "dest_ip": "185.254.126.122", "dest_port": 4001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:53:24.295329+0100", "src_ip": "91.224.92.177", "dest_ip": "185.254.126.122", "src_port": 59680, "dest_port": 4001}}'); INSERT INTO alerts VALUES(296,1772978036.751208067,'{"timestamp": "2026-03-08T14:53:56.751208+0100", "flow_id": 1255980536490385, "event_type": "alert", "src_ip": "54.83.110.109", "src_port": 443, "dest_ip": "192.168.2.20", "dest_port": 56247, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2031231, "rev": 3, "signature": "ET INFO Observed ZeroSSL SSL/TLS Certificate", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2020_11_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_12_01"]}}, "ts_progress": "client_handshake_done", "tc_progress": "server_handshake_done", "tls": {"subject": "CN=*.greencolumnart.com", "issuerdn": "C=AT, O=ZeroSSL, CN=ZeroSSL ECC Domain Secure Site CA", "subjectaltname": ["*.greencolumnart.com"], "serial": "4B:EF:18:4A:8A:7C:65:6C:1F:EA:F5:F8:CF:8B:44:B9", "fingerprint": "67:5a:2e:5e:86:89:c8:05:8e:e1:94:82:25:7e:42:a6:0f:98:18:04", "sni": "obs.greencolumnart.com", "version": "TLS 1.2", "notbefore": "2026-01-22T00:00:00", "notafter": "2026-04-22T23:59:59", "ja3": {"hash": "773906b0efdefa24a7f2b8eb6985bf37", "string": "771,4865-4866-4867-49196-49195-52393-49200-49199-52392-49162-49161-49172-49171-157-156-53-47-49160-49170-10,0-23-65281-10-11-16-5-13-18-51-45-43-27-21,29-23-24-25,0"}, "ja3s": {"hash": "80d47c47e3ce91bc3bd0a026dbd1664d", "string": "771,49196,5-65281-16"}, "ja4": "t13d2014h2_a09f3c656075_14788d8d241b", "client_alpns": ["h2", "http/1.1"], "server_alpns": ["h2"]}, "app_proto": "tls", "direction": "to_client", "flow": {"pkts_toserver": 3, "pkts_toclient": 5, "bytes_toserver": 685, "bytes_toclient": 3727, "start": "2026-03-08T14:53:56.554574+0100", "src_ip": "192.168.2.20", "dest_ip": "54.83.110.109", "src_port": 56247, "dest_port": 443}}'); INSERT INTO alerts VALUES(297,1772978062.809751034,'{"timestamp": "2026-03-08T14:54:22.809751+0100", "flow_id": 1789007109473370, "event_type": "alert", "src_ip": "170.82.253.76", "src_port": 41424, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:54:22.809751+0100", "src_ip": "170.82.253.76", "dest_ip": "185.254.126.122", "src_port": 41424, "dest_port": 1433}}'); INSERT INTO alerts VALUES(298,1772978154.10167098,'{"timestamp": "2026-03-08T14:55:54.101671+0100", "flow_id": 718149674629553, "event_type": "alert", "src_ip": "185.254.95.141", "src_port": 58141, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:55:54.101671+0100", "src_ip": "185.254.95.141", "dest_ip": "185.254.126.122", "src_port": 58141, "dest_port": 1433}}'); INSERT INTO alerts VALUES(299,1772978167.896723031,'{"timestamp": "2026-03-08T14:56:07.896723+0100", "flow_id": 2162548169987210, "event_type": "alert", "src_ip": "167.94.138.150", "src_port": 15155, "dest_ip": "185.254.126.122", "dest_port": 4839, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:56:07.896723+0100", "src_ip": "167.94.138.150", "dest_ip": "185.254.126.122", "src_port": 15155, "dest_port": 4839}}'); INSERT INTO alerts VALUES(300,1772978170.863950967,'{"timestamp": "2026-03-08T14:56:10.863951+0100", "flow_id": 614419758101140, "event_type": "alert", "src_ip": "65.49.1.93", "src_port": 38266, "dest_ip": "185.254.126.122", "dest_port": 2001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:56:10.863951+0100", "src_ip": "65.49.1.93", "dest_ip": "185.254.126.122", "src_port": 38266, "dest_port": 2001}}'); INSERT INTO alerts VALUES(301,1772978179.223906041,'{"timestamp": "2026-03-08T14:56:19.223906+0100", "flow_id": 961671031451438, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 52743, "dest_ip": "185.254.126.122", "dest_port": 8081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:56:19.223906+0100", "src_ip": "193.142.146.230", "dest_ip": "185.254.126.122", "src_port": 52743, "dest_port": 8081}}'); INSERT INTO alerts VALUES(302,1772978255.826021909,'{"timestamp": "2026-03-08T14:57:35.826022+0100", "flow_id": 2140363918711364, "event_type": "alert", "src_ip": "167.94.146.33", "src_port": 7666, "dest_ip": "185.254.126.122", "dest_port": 28756, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T14:57:35.826022+0100", "src_ip": "167.94.146.33", "dest_ip": "185.254.126.122", "src_port": 7666, "dest_port": 28756}}'); INSERT INTO alerts VALUES(303,1772978323.258819103,'{"timestamp": "2026-03-08T14:58:43.258819+0100", "flow_id": 1111620896924354, "event_type": "alert", "src_ip": "64.89.163.244", "src_port": 58222, "dest_ip": "185.254.126.122", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T14:58:43.258819+0100", "src_ip": "64.89.163.244", "dest_ip": "185.254.126.122", "src_port": 58222, "dest_port": 27017}}'); INSERT INTO alerts VALUES(304,1772978351.37641406,'{"timestamp": "2026-03-08T14:59:11.376414+0100", "flow_id": 2179638336929960, "event_type": "alert", "src_ip": "64.62.156.149", "src_port": 48201, "dest_ip": "185.254.126.122", "dest_port": 502, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:59:11.376414+0100", "src_ip": "64.62.156.149", "dest_ip": "185.254.126.122", "src_port": 48201, "dest_port": 502}}'); INSERT INTO alerts VALUES(305,1772978359.588695049,'{"timestamp": "2026-03-08T14:59:19.588695+0100", "flow_id": 2246951673986149, "event_type": "alert", "src_ip": "88.210.63.190", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 541, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T14:59:19.588695+0100", "src_ip": "88.210.63.190", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 541}}'); INSERT INTO alerts VALUES(306,1772978359.632603884,'{"timestamp": "2026-03-08T14:59:19.632604+0100", "flow_id": 2154064430409254, "event_type": "alert", "src_ip": "167.94.138.133", "src_port": 33553, "dest_ip": "185.254.126.122", "dest_port": 427, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-08T14:59:19.632604+0100", "src_ip": "167.94.138.133", "dest_ip": "185.254.126.122", "src_port": 33553, "dest_port": 427}}'); INSERT INTO alerts VALUES(307,1772978617.040899992,'{"timestamp": "2026-03-08T15:03:37.040900+0100", "flow_id": 457139305095300, "event_type": "alert", "src_ip": "64.62.197.238", "src_port": 37827, "dest_ip": "185.254.126.122", "dest_port": 110, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:03:37.040900+0100", "src_ip": "64.62.197.238", "dest_ip": "185.254.126.122", "src_port": 37827, "dest_port": 110}}'); INSERT INTO alerts VALUES(308,1772978623.503376008,'{"timestamp": "2026-03-08T15:03:43.503376+0100", "flow_id": 2161984710361720, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 50089, "dest_ip": "185.254.126.122", "dest_port": 17701, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:03:43.503376+0100", "src_ip": "167.94.146.32", "dest_ip": "185.254.126.122", "src_port": 50089, "dest_port": 17701}}'); INSERT INTO alerts VALUES(309,1772978655.803062916,'{"timestamp": "2026-03-08T15:04:15.803063+0100", "flow_id": 2041757672264833, "event_type": "alert", "src_ip": "45.153.34.117", "src_port": 36565, "dest_ip": "185.254.126.122", "dest_port": 52678, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:04:15.803063+0100", "src_ip": "45.153.34.117", "dest_ip": "185.254.126.122", "src_port": 36565, "dest_port": 52678}}'); INSERT INTO alerts VALUES(310,1772978673.298707008,'{"timestamp": "2026-03-08T15:04:33.298707+0100", "flow_id": 438513154925701, "event_type": "alert", "src_ip": "185.196.11.50", "src_port": 57441, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:04:33.298707+0100", "src_ip": "185.196.11.50", "dest_ip": "185.254.126.122", "src_port": 57441, "dest_port": 443}}'); INSERT INTO alerts VALUES(311,1772978764.377511024,'{"timestamp": "2026-03-08T15:06:04.377511+0100", "flow_id": 1339924603349364, "event_type": "alert", "src_ip": "45.135.194.48", "src_port": 44702, "dest_ip": "185.254.126.122", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:06:04.377511+0100", "src_ip": "45.135.194.48", "dest_ip": "185.254.126.122", "src_port": 44702, "dest_port": 5555}}'); INSERT INTO alerts VALUES(312,1772978767.736008883,'{"timestamp": "2026-03-08T15:06:07.736009+0100", "flow_id": 2035236772257529, "event_type": "alert", "src_ip": "64.89.160.47", "src_port": 41074, "dest_ip": "185.254.126.122", "dest_port": 6377, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:06:07.736009+0100", "src_ip": "64.89.160.47", "dest_ip": "185.254.126.122", "src_port": 41074, "dest_port": 6377}}'); INSERT INTO alerts VALUES(313,1772978767.736008883,'{"timestamp": "2026-03-08T15:06:07.736009+0100", "flow_id": 2035236772257529, "event_type": "alert", "src_ip": "64.89.160.47", "src_port": 41074, "dest_ip": "185.254.126.122", "dest_port": 6377, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500032, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 17", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:06:07.736009+0100", "src_ip": "64.89.160.47", "dest_ip": "185.254.126.122", "src_port": 41074, "dest_port": 6377}}'); INSERT INTO alerts VALUES(314,1772978772.550520896,'{"timestamp": "2026-03-08T15:06:12.550521+0100", "flow_id": 1238573662956981, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "185.254.126.122", "dest_port": 12982, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:06:12.550521+0100", "src_ip": "79.124.40.110", "dest_ip": "185.254.126.122", "src_port": 52537, "dest_port": 12982}}'); INSERT INTO alerts VALUES(315,1772978779.102061987,'{"timestamp": "2026-03-08T15:06:19.102062+0100", "flow_id": 1001306210571311, "event_type": "alert", "src_ip": "64.89.163.154", "src_port": 58640, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:06:19.102062+0100", "src_ip": "64.89.163.154", "dest_ip": "185.254.126.122", "src_port": 58640, "dest_port": 3306}}'); INSERT INTO alerts VALUES(316,1772978794.107745885,'{"timestamp": "2026-03-08T15:06:34.107746+0100", "flow_id": 744242972815247, "event_type": "alert", "src_ip": "65.49.1.25", "src_port": 34859, "dest_ip": "185.254.126.122", "dest_port": 5805, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:06:34.107746+0100", "src_ip": "65.49.1.25", "dest_ip": "185.254.126.122", "src_port": 34859, "dest_port": 5805}}'); INSERT INTO alerts VALUES(317,1772978818.852236987,'{"timestamp": "2026-03-08T15:06:58.852237+0100", "flow_id": 564107305682488, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 2019, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:06:58.852237+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 2019}}'); INSERT INTO alerts VALUES(318,1772978818.852236987,'{"timestamp": "2026-03-08T15:06:58.852237+0100", "flow_id": 564107305682488, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 2019, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:06:58.852237+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 2019}}'); INSERT INTO alerts VALUES(319,1772978824.45904708,'{"timestamp": "2026-03-08T15:07:04.459047+0100", "flow_id": 1267157985310, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 57043, "dest_ip": "185.254.126.122", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:07:04.459047+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 57043, "dest_port": 8545}}'); INSERT INTO alerts VALUES(320,1772978824.45904708,'{"timestamp": "2026-03-08T15:07:04.459047+0100", "flow_id": 1267157985310, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 57043, "dest_ip": "185.254.126.122", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:07:04.459047+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 57043, "dest_port": 8545}}'); INSERT INTO alerts VALUES(321,1772978847.110227109,'{"timestamp": "2026-03-08T15:07:27.110227+0100", "flow_id": 2162272647177939, "event_type": "alert", "src_ip": "64.89.160.47", "src_port": 37577, "dest_ip": "185.254.126.122", "dest_port": 42412, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500032, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 17", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:07:27.110227+0100", "src_ip": "64.89.160.47", "dest_ip": "185.254.126.122", "src_port": 37577, "dest_port": 42412}}'); INSERT INTO alerts VALUES(322,1772978895.225888968,'{"timestamp": "2026-03-08T15:08:15.225889+0100", "flow_id": 2096089983004347, "event_type": "alert", "src_ip": "45.156.87.10", "src_port": 58867, "dest_ip": "185.254.126.122", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:08:15.225889+0100", "src_ip": "45.156.87.10", "dest_ip": "185.254.126.122", "src_port": 58867, "dest_port": 27017}}'); INSERT INTO alerts VALUES(323,1772978924.517597914,'{"timestamp": "2026-03-08T15:08:44.517598+0100", "flow_id": 1378644550848378, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 24431, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:08:44.517598+0100", "src_ip": "185.156.73.181", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 24431}}'); INSERT INTO alerts VALUES(324,1772978925.454385043,'{"timestamp": "2026-03-08T15:08:45.454385+0100", "flow_id": 1670095020810037, "event_type": "alert", "src_ip": "64.95.96.68", "src_port": 5718, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-08T15:08:45.454385+0100", "src_ip": "64.95.96.68", "dest_ip": "185.254.126.122", "src_port": 5718, "dest_port": 5060}}'); INSERT INTO alerts VALUES(325,1772978925.454385043,'{"timestamp": "2026-03-08T15:08:45.454385+0100", "flow_id": 1670095020810037, "event_type": "alert", "src_ip": "64.95.96.68", "src_port": 5718, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-08T15:08:45.454385+0100", "src_ip": "64.95.96.68", "dest_ip": "185.254.126.122", "src_port": 5718, "dest_port": 5060}}'); INSERT INTO alerts VALUES(326,1772978951.137222052,'{"timestamp": "2026-03-08T15:09:11.137222+0100", "flow_id": 1996739036582411, "event_type": "alert", "src_ip": "176.65.134.22", "src_port": 40235, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:09:11.137222+0100", "src_ip": "176.65.134.22", "dest_ip": "185.254.126.122", "src_port": 40235, "dest_port": 22}}'); INSERT INTO alerts VALUES(327,1772978997.056056977,'{"timestamp": "2026-03-08T15:09:57.056057+0100", "flow_id": 1648140591896778, "event_type": "alert", "src_ip": "64.89.160.47", "src_port": 37165, "dest_ip": "185.254.126.122", "dest_port": 1145, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500032, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 17", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:09:57.056057+0100", "src_ip": "64.89.160.47", "dest_ip": "185.254.126.122", "src_port": 37165, "dest_port": 1145}}'); INSERT INTO alerts VALUES(328,1772979047.567065954,'{"timestamp": "2026-03-08T15:10:47.567066+0100", "flow_id": 2154056241856737, "event_type": "alert", "src_ip": "167.94.138.149", "src_port": 4988, "dest_ip": "185.254.126.122", "dest_port": 2363, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 42, "bytes_toclient": 0, "start": "2026-03-08T15:10:47.567066+0100", "src_ip": "167.94.138.149", "dest_ip": "185.254.126.122", "src_port": 4988, "dest_port": 2363}}'); INSERT INTO alerts VALUES(329,1772979122.942819118,'{"timestamp": "2026-03-08T15:12:02.942819+0100", "flow_id": 671679898747074, "event_type": "alert", "src_ip": "64.89.163.23", "src_port": 56433, "dest_ip": "185.254.126.122", "dest_port": 465, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:12:02.942819+0100", "src_ip": "64.89.163.23", "dest_ip": "185.254.126.122", "src_port": 56433, "dest_port": 465}}'); INSERT INTO alerts VALUES(330,1772979181.502993107,'{"timestamp": "2026-03-08T15:13:01.502993+0100", "flow_id": 1597388901963030, "event_type": "alert", "src_ip": "64.62.156.169", "src_port": 39718, "dest_ip": "185.254.126.122", "dest_port": 61616, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:13:01.502993+0100", "src_ip": "64.62.156.169", "dest_ip": "185.254.126.122", "src_port": 39718, "dest_port": 61616}}'); INSERT INTO alerts VALUES(331,1772979275.018647909,'{"timestamp": "2026-03-08T15:14:35.018648+0100", "flow_id": 924520226850912, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:14:35.018648+0100", "src_ip": "204.76.203.73", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 80}}'); INSERT INTO alerts VALUES(332,1772979275.018647909,'{"timestamp": "2026-03-08T15:14:35.018648+0100", "flow_id": 924520226850912, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:14:35.018648+0100", "src_ip": "204.76.203.73", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 80}}'); INSERT INTO alerts VALUES(333,1772979280.835081101,'{"timestamp": "2026-03-08T15:14:40.835081+0100", "flow_id": 208946456549767, "event_type": "alert", "src_ip": "45.156.87.24", "src_port": 49741, "dest_ip": "185.254.126.122", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:14:40.835081+0100", "src_ip": "45.156.87.24", "dest_ip": "185.254.126.122", "src_port": 49741, "dest_port": 5555}}'); INSERT INTO alerts VALUES(334,1772979316.877593995,'{"timestamp": "2026-03-08T15:15:16.877594+0100", "flow_id": 1235964534233565, "event_type": "alert", "src_ip": "167.94.138.97", "src_port": 60224, "dest_ip": "185.254.126.122", "dest_port": 13940, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:15:16.877594+0100", "src_ip": "167.94.138.97", "dest_ip": "185.254.126.122", "src_port": 60224, "dest_port": 13940}}'); INSERT INTO alerts VALUES(335,1772979350.153620959,'{"timestamp": "2026-03-08T15:15:50.153621+0100", "flow_id": 1785700801563926, "event_type": "alert", "src_ip": "130.12.181.157", "src_port": 53995, "dest_ip": "185.254.126.122", "dest_port": 2528, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:15:50.153621+0100", "src_ip": "130.12.181.157", "dest_ip": "185.254.126.122", "src_port": 53995, "dest_port": 2528}}'); INSERT INTO alerts VALUES(336,1772979350.153620959,'{"timestamp": "2026-03-08T15:15:50.153621+0100", "flow_id": 1785700801563926, "event_type": "alert", "src_ip": "130.12.181.157", "src_port": 53995, "dest_ip": "185.254.126.122", "dest_port": 2528, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500006, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:15:50.153621+0100", "src_ip": "130.12.181.157", "dest_ip": "185.254.126.122", "src_port": 53995, "dest_port": 2528}}'); INSERT INTO alerts VALUES(337,1772979382.998568058,'{"timestamp": "2026-03-08T15:16:22.998568+0100", "flow_id": 1755546297147624, "event_type": "alert", "src_ip": "66.132.153.153", "src_port": 45773, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 46, "bytes_toclient": 0, "start": "2026-03-08T15:16:22.998568+0100", "src_ip": "66.132.153.153", "dest_ip": "185.254.126.122", "src_port": 45773, "dest_port": 3389}}'); INSERT INTO alerts VALUES(338,1772979410.487582922,'{"timestamp": "2026-03-08T15:16:50.487583+0100", "flow_id": 686782173724125, "event_type": "alert", "src_ip": "130.12.181.157", "src_port": 33752, "dest_ip": "185.254.126.122", "dest_port": 21080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500006, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:16:50.487583+0100", "src_ip": "130.12.181.157", "dest_ip": "185.254.126.122", "src_port": 33752, "dest_port": 21080}}'); INSERT INTO alerts VALUES(339,1772979566.41088295,'{"timestamp": "2026-03-08T15:19:26.410883+0100", "flow_id": 1764731080536225, "event_type": "alert", "src_ip": "130.12.181.157", "src_port": 46508, "dest_ip": "185.254.126.122", "dest_port": 8989, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500006, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:19:26.410883+0100", "src_ip": "130.12.181.157", "dest_ip": "185.254.126.122", "src_port": 46508, "dest_port": 8989}}'); INSERT INTO alerts VALUES(340,1772979694.411992073,'{"timestamp": "2026-03-08T15:21:34.411992+0100", "flow_id": 1769496215121366, "event_type": "alert", "src_ip": "43.228.157.14", "src_port": 40953, "dest_ip": "185.254.126.122", "dest_port": 24442, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:21:34.411992+0100", "src_ip": "43.228.157.14", "dest_ip": "185.254.126.122", "src_port": 40953, "dest_port": 24442}}'); INSERT INTO alerts VALUES(341,1772979722.447546006,'{"timestamp": "2026-03-08T15:22:02.447546+0100", "flow_id": 796298226694662, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 10201, "dest_ip": "185.254.126.122", "dest_port": 5580, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:22:02.447546+0100", "src_ip": "167.94.146.40", "dest_ip": "185.254.126.122", "src_port": 10201, "dest_port": 5580}}'); INSERT INTO alerts VALUES(342,1772979751.222141027,'{"timestamp": "2026-03-08T15:22:31.222141+0100", "flow_id": 2079988906977732, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 55312, "dest_ip": "185.254.126.122", "dest_port": 24220, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:22:31.222141+0100", "src_ip": "79.124.62.126", "dest_ip": "185.254.126.122", "src_port": 55312, "dest_port": 24220}}'); INSERT INTO alerts VALUES(343,1772979820.78015089,'{"timestamp": "2026-03-08T15:23:40.780151+0100", "flow_id": 1380400178017957, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59755, "dest_ip": "185.254.126.122", "dest_port": 3298, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:23:40.780151+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59755, "dest_port": 3298}}'); INSERT INTO alerts VALUES(344,1772979820.78015089,'{"timestamp": "2026-03-08T15:23:40.780151+0100", "flow_id": 1380400178017957, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59755, "dest_ip": "185.254.126.122", "dest_port": 3298, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:23:40.780151+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59755, "dest_port": 3298}}'); INSERT INTO alerts VALUES(345,1772979906.060815096,'{"timestamp": "2026-03-08T15:25:06.060815+0100", "flow_id": 824151369616408, "event_type": "alert", "src_ip": "176.65.139.45", "src_port": 36710, "dest_ip": "185.254.126.122", "dest_port": 17000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:25:06.060815+0100", "src_ip": "176.65.139.45", "dest_ip": "185.254.126.122", "src_port": 36710, "dest_port": 17000}}'); INSERT INTO alerts VALUES(346,1772979976.820085048,'{"timestamp": "2026-03-08T15:26:16.820085+0100", "flow_id": 144542452003644, "event_type": "alert", "src_ip": "64.62.197.198", "src_port": 34679, "dest_ip": "185.254.126.122", "dest_port": 1337, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:26:16.820085+0100", "src_ip": "64.62.197.198", "dest_ip": "185.254.126.122", "src_port": 34679, "dest_port": 1337}}'); INSERT INTO alerts VALUES(347,1772980005.626754046,'{"timestamp": "2026-03-08T15:26:45.626754+0100", "flow_id": 1565988098015418, "event_type": "alert", "src_ip": "64.62.156.53", "src_port": 47118, "dest_ip": "185.254.126.122", "dest_port": 49664, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:26:45.626754+0100", "src_ip": "64.62.156.53", "dest_ip": "185.254.126.122", "src_port": 47118, "dest_port": 49664}}'); INSERT INTO alerts VALUES(348,1772980027.307018996,'{"timestamp": "2026-03-08T15:27:07.307019+0100", "flow_id": 1037162284729467, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 56784, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25924, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T15:27:07.307019+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 56784, "dest_port": 53}}'); INSERT INTO alerts VALUES(349,1772980027.307019949,'{"timestamp": "2026-03-08T15:27:07.307020+0100", "flow_id": 1037169041657053, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57798, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22714, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T15:27:07.307020+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57798, "dest_port": 53}}'); INSERT INTO alerts VALUES(350,1772980027.307019949,'{"timestamp": "2026-03-08T15:27:07.307020+0100", "flow_id": 1037168762901710, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8933, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T15:27:07.307020+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33596, "dest_port": 53}}'); INSERT INTO alerts VALUES(351,1772980174.632450103,'{"timestamp": "2026-03-08T15:29:34.632450+0100", "flow_id": 1871930840807342, "event_type": "alert", "src_ip": "193.163.125.37", "src_port": 37381, "dest_ip": "185.254.126.122", "dest_port": 21845, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:29:34.632450+0100", "src_ip": "193.163.125.37", "dest_ip": "185.254.126.122", "src_port": 37381, "dest_port": 21845}}'); INSERT INTO alerts VALUES(352,1772980190.405270099,'{"timestamp": "2026-03-08T15:29:50.405270+0100", "flow_id": 1740622598521962, "event_type": "alert", "src_ip": "64.62.197.59", "src_port": 60132, "dest_ip": "185.254.126.122", "dest_port": 3001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:29:50.405270+0100", "src_ip": "64.62.197.59", "dest_ip": "185.254.126.122", "src_port": 60132, "dest_port": 3001}}'); INSERT INTO alerts VALUES(353,1772980268.981903077,'{"timestamp": "2026-03-08T15:31:08.981903+0100", "flow_id": 1402492493568460, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 56649, "dest_ip": "185.254.126.122", "dest_port": 2202, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:31:08.981903+0100", "src_ip": "185.242.246.37", "dest_ip": "185.254.126.122", "src_port": 56649, "dest_port": 2202}}'); INSERT INTO alerts VALUES(354,1772980268.981903077,'{"timestamp": "2026-03-08T15:31:08.981903+0100", "flow_id": 1402492493568460, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 56649, "dest_ip": "185.254.126.122", "dest_port": 2202, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:31:08.981903+0100", "src_ip": "185.242.246.37", "dest_ip": "185.254.126.122", "src_port": 56649, "dest_port": 2202}}'); INSERT INTO alerts VALUES(355,1772980345.519526958,'{"timestamp": "2026-03-08T15:32:25.519527+0100", "flow_id": 542502995580290, "event_type": "alert", "src_ip": "195.184.76.28", "src_port": 26479, "dest_ip": "185.254.126.122", "dest_port": 8081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:32:25.519527+0100", "src_ip": "195.184.76.28", "dest_ip": "185.254.126.122", "src_port": 26479, "dest_port": 8081}}'); INSERT INTO alerts VALUES(356,1772980351.500325918,'{"timestamp": "2026-03-08T15:32:31.500326+0100", "flow_id": 2148884491113062, "event_type": "alert", "src_ip": "167.94.146.41", "src_port": 32401, "dest_ip": "185.254.126.122", "dest_port": 2024, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:32:31.500326+0100", "src_ip": "167.94.146.41", "dest_ip": "185.254.126.122", "src_port": 32401, "dest_port": 2024}}'); INSERT INTO alerts VALUES(357,1772980362.55824089,'{"timestamp": "2026-03-08T15:32:42.558241+0100", "flow_id": 708778380202934, "event_type": "alert", "src_ip": "195.184.76.100", "src_port": 13752, "dest_ip": "185.254.126.122", "dest_port": 7777, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:32:42.558241+0100", "src_ip": "195.184.76.100", "dest_ip": "185.254.126.122", "src_port": 13752, "dest_port": 7777}}'); INSERT INTO alerts VALUES(358,1772980369.600790978,'{"timestamp": "2026-03-08T15:32:49.600791+0100", "flow_id": 328581070665480, "event_type": "alert", "src_ip": "91.196.152.4", "src_port": 32502, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:32:49.600791+0100", "src_ip": "91.196.152.4", "dest_ip": "185.254.126.122", "src_port": 32502, "dest_port": 3306}}'); INSERT INTO alerts VALUES(359,1772980369.600790978,'{"timestamp": "2026-03-08T15:32:49.600791+0100", "flow_id": 328581070665480, "event_type": "alert", "src_ip": "91.196.152.4", "src_port": 32502, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:32:49.600791+0100", "src_ip": "91.196.152.4", "dest_ip": "185.254.126.122", "src_port": 32502, "dest_port": 3306}}'); INSERT INTO alerts VALUES(360,1772980629.271651984,'{"timestamp": "2026-03-08T15:37:09.271652+0100", "flow_id": 1448213137697720, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59003, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29995, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T15:37:09.271652+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59003, "dest_port": 53}}'); INSERT INTO alerts VALUES(361,1772980629.839574098,'{"timestamp": "2026-03-08T15:37:09.839574+0100", "flow_id": 1635620935338762, "event_type": "alert", "src_ip": "193.163.125.30", "src_port": 45017, "dest_ip": "185.254.126.122", "dest_port": 40120, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:37:09.839574+0100", "src_ip": "193.163.125.30", "dest_ip": "185.254.126.122", "src_port": 45017, "dest_port": 40120}}'); INSERT INTO alerts VALUES(362,1772980637.582231044,'{"timestamp": "2026-03-08T15:37:17.582231+0100", "flow_id": 1656241771213834, "event_type": "alert", "src_ip": "176.65.149.76", "src_port": 45187, "dest_ip": "185.254.126.122", "dest_port": 8070, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:37:17.582231+0100", "src_ip": "176.65.149.76", "dest_ip": "185.254.126.122", "src_port": 45187, "dest_port": 8070}}'); INSERT INTO alerts VALUES(363,1772980644.294059992,'{"timestamp": "2026-03-08T15:37:24.294060+0100", "flow_id": 1196192744635730, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 48416, "dest_ip": "94.130.164.126", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053282, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "relays.syncthing.net", "version": "TLS 1.3", "ja3": {"hash": "473cd7cb9faa642487833865d516e578", "string": "771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-156-157-47-53-49170-10-4865-4866-4867,0-5-10-11-13-65281-18-43-51,29-23-24-25,0"}, "ja4": "t13d190900_9dc949149365_97f8aa674fd9"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 3, "pkts_toclient": 1, "bytes_toserver": 432, "bytes_toclient": 60, "start": "2026-03-08T15:37:24.278510+0100", "src_ip": "192.168.2.16", "dest_ip": "94.130.164.126", "src_port": 48416, "dest_port": 443}}'); INSERT INTO alerts VALUES(364,1772980645.390136957,'{"timestamp": "2026-03-08T15:37:25.390137+0100", "flow_id": 1675627027537378, "event_type": "alert", "src_ip": "65.49.1.194", "src_port": 40026, "dest_ip": "185.254.126.122", "dest_port": 22522, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:37:25.390137+0100", "src_ip": "65.49.1.194", "dest_ip": "185.254.126.122", "src_port": 40026, "dest_port": 22522}}'); INSERT INTO alerts VALUES(365,1772980647.738533021,'{"timestamp": "2026-03-08T15:37:27.738533+0100", "flow_id": 2046078653376325, "event_type": "alert", "src_ip": "195.184.76.12", "src_port": 55991, "dest_ip": "185.254.126.122", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:37:27.738533+0100", "src_ip": "195.184.76.12", "dest_ip": "185.254.126.122", "src_port": 55991, "dest_port": 8088}}'); INSERT INTO alerts VALUES(366,1772980656.726146936,'{"timestamp": "2026-03-08T15:37:36.726147+0100", "flow_id": 22553151150084, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49254, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32251, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T15:37:36.726147+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49254, "dest_port": 53}}'); INSERT INTO alerts VALUES(367,1772980656.72614789,'{"timestamp": "2026-03-08T15:37:36.726148+0100", "flow_id": 22558874267661, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42809, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37669, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T15:37:36.726148+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42809, "dest_port": 53}}'); INSERT INTO alerts VALUES(368,1772980656.72614789,'{"timestamp": "2026-03-08T15:37:36.726148+0100", "flow_id": 22557583493779, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34671, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65044, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T15:37:36.726148+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34671, "dest_port": 53}}'); INSERT INTO alerts VALUES(369,1772980699.803031921,'{"timestamp": "2026-03-08T15:38:19.803032+0100", "flow_id": 915724712890475, "event_type": "alert", "src_ip": "64.62.197.177", "src_port": 46236, "dest_ip": "185.254.126.122", "dest_port": 22122, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:38:19.803032+0100", "src_ip": "64.62.197.177", "dest_ip": "185.254.126.122", "src_port": 46236, "dest_port": 22122}}'); INSERT INTO alerts VALUES(370,1772980798.138375044,'{"timestamp": "2026-03-08T15:39:58.138375+0100", "flow_id": 1720217895443506, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 57816, "dest_ip": "185.254.126.122", "dest_port": 52025, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:39:58.138375+0100", "src_ip": "79.124.40.82", "dest_ip": "185.254.126.122", "src_port": 57816, "dest_port": 52025}}'); INSERT INTO alerts VALUES(371,1772980811.07210207,'{"timestamp": "2026-03-08T15:40:11.072102+0100", "flow_id": 872628638475082, "event_type": "alert", "src_ip": "167.94.146.35", "src_port": 24231, "dest_ip": "185.254.126.122", "dest_port": 54521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:40:11.072102+0100", "src_ip": "167.94.146.35", "dest_ip": "185.254.126.122", "src_port": 24231, "dest_port": 54521}}'); INSERT INTO alerts VALUES(372,1772980811.549523116,'{"timestamp": "2026-03-08T15:40:11.549523+0100", "flow_id": 952810633060443, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 57906, "dest_ip": "185.254.126.122", "dest_port": 28770, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:40:11.549523+0100", "src_ip": "79.124.62.230", "dest_ip": "185.254.126.122", "src_port": 57906, "dest_port": 28770}}'); INSERT INTO alerts VALUES(373,1772980823.352852107,'{"timestamp": "2026-03-08T15:40:23.352852+0100", "flow_id": 2078439502931310, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "185.254.126.122", "dest_port": 10525, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:40:23.352852+0100", "src_ip": "79.124.40.110", "dest_ip": "185.254.126.122", "src_port": 52537, "dest_port": 10525}}'); INSERT INTO alerts VALUES(374,1772980823.689249993,'{"timestamp": "2026-03-08T15:40:23.689250+0100", "flow_id": 2115884575608004, "event_type": "alert", "src_ip": "185.156.73.180", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 53443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:40:23.689250+0100", "src_ip": "185.156.73.180", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 53443}}'); INSERT INTO alerts VALUES(375,1772980829.774457931,'{"timestamp": "2026-03-08T15:40:29.774458+0100", "flow_id": 1637422744637909, "event_type": "alert", "src_ip": "176.65.148.4", "src_port": 58489, "dest_ip": "185.254.126.122", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:40:29.774458+0100", "src_ip": "176.65.148.4", "dest_ip": "185.254.126.122", "src_port": 58489, "dest_port": 25565}}'); INSERT INTO alerts VALUES(376,1772980829.774457931,'{"timestamp": "2026-03-08T15:40:29.774458+0100", "flow_id": 1637422744637909, "event_type": "alert", "src_ip": "176.65.148.4", "src_port": 58489, "dest_ip": "185.254.126.122", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:40:29.774458+0100", "src_ip": "176.65.148.4", "dest_ip": "185.254.126.122", "src_port": 58489, "dest_port": 25565}}'); INSERT INTO alerts VALUES(377,1772980897.237416028,'{"timestamp": "2026-03-08T15:41:37.237416+0100", "flow_id": 456747567470524, "event_type": "alert", "src_ip": "172.94.9.253", "src_port": 49962, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400031, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 32", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:41:37.237416+0100", "src_ip": "172.94.9.253", "dest_ip": "185.254.126.122", "src_port": 49962, "dest_port": 443}}'); INSERT INTO alerts VALUES(378,1772980897.452095031,'{"timestamp": "2026-03-08T15:41:37.452095+0100", "flow_id": 534361844273463, "event_type": "alert", "src_ip": "66.132.153.153", "src_port": 45680, "dest_ip": "185.254.126.122", "dest_port": 5349, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:41:37.452095+0100", "src_ip": "66.132.153.153", "dest_ip": "185.254.126.122", "src_port": 45680, "dest_port": 5349}}'); INSERT INTO alerts VALUES(379,1772980911.019380092,'{"timestamp": "2026-03-08T15:41:51.019380+0100", "flow_id": 2053562374948795, "event_type": "alert", "src_ip": "193.163.125.13", "src_port": 59138, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:41:51.019380+0100", "src_ip": "193.163.125.13", "dest_ip": "185.254.126.122", "src_port": 59138, "dest_port": 3306}}'); INSERT INTO alerts VALUES(380,1772980911.019380092,'{"timestamp": "2026-03-08T15:41:51.019380+0100", "flow_id": 2053562374948795, "event_type": "alert", "src_ip": "193.163.125.13", "src_port": 59138, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:41:51.019380+0100", "src_ip": "193.163.125.13", "dest_ip": "185.254.126.122", "src_port": 59138, "dest_port": 3306}}'); INSERT INTO alerts VALUES(381,1772980927.34415698,'{"timestamp": "2026-03-08T15:42:07.344157+0100", "flow_id": 2041096872956737, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 39074, "dest_ip": "185.254.126.122", "dest_port": 9090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:42:07.344157+0100", "src_ip": "193.142.146.230", "dest_ip": "185.254.126.122", "src_port": 39074, "dest_port": 9090}}'); INSERT INTO alerts VALUES(382,1772980930.725150109,'{"timestamp": "2026-03-08T15:42:10.725150+0100", "flow_id": 581222547700758, "event_type": "alert", "src_ip": "64.62.156.103", "src_port": 43944, "dest_ip": "185.254.126.122", "dest_port": 873, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:42:10.725150+0100", "src_ip": "64.62.156.103", "dest_ip": "185.254.126.122", "src_port": 43944, "dest_port": 873}}'); INSERT INTO alerts VALUES(383,1772981035.172468901,'{"timestamp": "2026-03-08T15:43:55.172469+0100", "flow_id": 1022227964077684, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 44551, "dest_ip": "185.254.126.122", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:43:55.172469+0100", "src_ip": "130.12.180.174", "dest_ip": "185.254.126.122", "src_port": 44551, "dest_port": 23}}'); INSERT INTO alerts VALUES(384,1772981035.172468901,'{"timestamp": "2026-03-08T15:43:55.172469+0100", "flow_id": 1022227964077684, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 44551, "dest_ip": "185.254.126.122", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:43:55.172469+0100", "src_ip": "130.12.180.174", "dest_ip": "185.254.126.122", "src_port": 44551, "dest_port": 23}}'); INSERT INTO alerts VALUES(385,1772981220.869481086,'{"timestamp": "2026-03-08T15:47:00.869481+0100", "flow_id": 1201120304086962, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 59277, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:47:00.869481+0100", "src_ip": "79.124.62.134", "dest_ip": "185.254.126.122", "src_port": 59277, "dest_port": 3389}}'); INSERT INTO alerts VALUES(386,1772981268.788646936,'{"timestamp": "2026-03-08T15:47:48.788647+0100", "flow_id": 1135413813019582, "event_type": "alert", "src_ip": "66.132.153.152", "src_port": 59214, "dest_ip": "185.254.126.122", "dest_port": 10001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:47:48.788647+0100", "src_ip": "66.132.153.152", "dest_ip": "185.254.126.122", "src_port": 59214, "dest_port": 10001}}'); INSERT INTO alerts VALUES(387,1772981299.430335999,'{"timestamp": "2026-03-08T15:48:19.430336+0100", "flow_id": 1003857693274182, "event_type": "alert", "src_ip": "178.20.210.151", "src_port": 52898, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:48:19.430336+0100", "src_ip": "178.20.210.151", "dest_ip": "185.254.126.122", "src_port": 52898, "dest_port": 22}}'); INSERT INTO alerts VALUES(388,1772981343.490191936,'{"timestamp": "2026-03-08T15:49:03.490192+0100", "flow_id": 2105358734110838, "event_type": "alert", "src_ip": "195.184.76.156", "src_port": 16831, "dest_ip": "185.254.126.122", "dest_port": 55443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:49:03.490192+0100", "src_ip": "195.184.76.156", "dest_ip": "185.254.126.122", "src_port": 16831, "dest_port": 55443}}'); INSERT INTO alerts VALUES(389,1772981359.308738947,'{"timestamp": "2026-03-08T15:49:19.308739+0100", "flow_id": 2170450856740126, "event_type": "alert", "src_ip": "167.94.138.151", "src_port": 9442, "dest_ip": "185.254.126.122", "dest_port": 1961, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:49:19.308739+0100", "src_ip": "167.94.138.151", "dest_ip": "185.254.126.122", "src_port": 9442, "dest_port": 1961}}'); INSERT INTO alerts VALUES(390,1772981424.542810916,'{"timestamp": "2026-03-08T15:50:24.542811+0100", "flow_id": 79557181520536, "event_type": "alert", "src_ip": "64.62.197.144", "src_port": 60015, "dest_ip": "185.254.126.122", "dest_port": 5800, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:50:24.542811+0100", "src_ip": "64.62.197.144", "dest_ip": "185.254.126.122", "src_port": 60015, "dest_port": 5800}}'); INSERT INTO alerts VALUES(391,1772981426.484626055,'{"timestamp": "2026-03-08T15:50:26.484626+0100", "flow_id": 674079977960912, "event_type": "alert", "src_ip": "176.65.148.66", "src_port": 50381, "dest_ip": "185.254.126.122", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:50:26.484626+0100", "src_ip": "176.65.148.66", "dest_ip": "185.254.126.122", "src_port": 50381, "dest_port": 3000}}'); INSERT INTO alerts VALUES(392,1772981426.484626055,'{"timestamp": "2026-03-08T15:50:26.484626+0100", "flow_id": 674079977960912, "event_type": "alert", "src_ip": "176.65.148.66", "src_port": 50381, "dest_ip": "185.254.126.122", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:50:26.484626+0100", "src_ip": "176.65.148.66", "dest_ip": "185.254.126.122", "src_port": 50381, "dest_port": 3000}}'); INSERT INTO alerts VALUES(393,1772981491.606759072,'{"timestamp": "2026-03-08T15:51:31.606759+0100", "flow_id": 917163425099184, "event_type": "alert", "src_ip": "193.163.125.34", "src_port": 49270, "dest_ip": "185.254.126.122", "dest_port": 8531, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:51:31.606759+0100", "src_ip": "193.163.125.34", "dest_ip": "185.254.126.122", "src_port": 49270, "dest_port": 8531}}'); INSERT INTO alerts VALUES(394,1772981515.427350044,'{"timestamp": "2026-03-08T15:51:55.427350+0100", "flow_id": 991032214535575, "event_type": "alert", "src_ip": "64.62.197.198", "src_port": 40903, "dest_ip": "185.254.126.122", "dest_port": 5001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:51:55.427350+0100", "src_ip": "64.62.197.198", "dest_ip": "185.254.126.122", "src_port": 40903, "dest_port": 5001}}'); INSERT INTO alerts VALUES(395,1772981610.26158309,'{"timestamp": "2026-03-08T15:53:30.261583+0100", "flow_id": 842016641838929, "event_type": "alert", "src_ip": "64.89.163.23", "src_port": 56433, "dest_ip": "185.254.126.122", "dest_port": 25, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:53:30.261583+0100", "src_ip": "64.89.163.23", "dest_ip": "185.254.126.122", "src_port": 56433, "dest_port": 25}}'); INSERT INTO alerts VALUES(396,1772981623.547583103,'{"timestamp": "2026-03-08T15:53:43.547583+0100", "flow_id": 2070380385689246, "event_type": "alert", "src_ip": "45.135.194.65", "src_port": 5409, "dest_ip": "185.254.126.122", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 57, "bytes_toclient": 0, "start": "2026-03-08T15:53:43.547583+0100", "src_ip": "45.135.194.65", "dest_ip": "185.254.126.122", "src_port": 5409, "dest_port": 53}}'); INSERT INTO alerts VALUES(397,1772981628.456990958,'{"timestamp": "2026-03-08T15:53:48.456991+0100", "flow_id": 1399813129805788, "event_type": "alert", "src_ip": "176.65.139.31", "src_port": 8424, "dest_ip": "185.254.126.122", "dest_port": 389, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ldap", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-08T15:53:48.456991+0100", "src_ip": "176.65.139.31", "dest_ip": "185.254.126.122", "src_port": 8424, "dest_port": 389}}'); INSERT INTO alerts VALUES(398,1772981635.802337884,'{"timestamp": "2026-03-08T15:53:55.802338+0100", "flow_id": 912742238458150, "event_type": "alert", "src_ip": "77.83.39.250", "src_port": 41340, "dest_ip": "185.254.126.122", "dest_port": 2525, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400008, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 9", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:53:55.802338+0100", "src_ip": "77.83.39.250", "dest_ip": "185.254.126.122", "src_port": 41340, "dest_port": 2525}}'); INSERT INTO alerts VALUES(399,1772981680.456034898,'{"timestamp": "2026-03-08T15:54:40.456035+0100", "flow_id": 269808830391275, "event_type": "alert", "src_ip": "167.94.146.36", "src_port": 4694, "dest_ip": "185.254.126.122", "dest_port": 52165, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:54:40.456035+0100", "src_ip": "167.94.146.36", "dest_ip": "185.254.126.122", "src_port": 4694, "dest_port": 52165}}'); INSERT INTO alerts VALUES(400,1772981697.638850927,'{"timestamp": "2026-03-08T15:54:57.638851+0100", "flow_id": 492046251667944, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 55312, "dest_ip": "185.254.126.122", "dest_port": 20997, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:54:57.638851+0100", "src_ip": "79.124.62.126", "dest_ip": "185.254.126.122", "src_port": 55312, "dest_port": 20997}}'); INSERT INTO alerts VALUES(401,1772981698.672915936,'{"timestamp": "2026-03-08T15:54:58.672916+0100", "flow_id": 638354059658192, "event_type": "alert", "src_ip": "195.184.76.148", "src_port": 1076, "dest_ip": "185.254.126.122", "dest_port": 52951, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:54:58.672916+0100", "src_ip": "195.184.76.148", "dest_ip": "185.254.126.122", "src_port": 1076, "dest_port": 52951}}'); INSERT INTO alerts VALUES(402,1772981714.08215189,'{"timestamp": "2026-03-08T15:55:14.082152+0100", "flow_id": 634315666181216, "event_type": "alert", "src_ip": "65.49.1.159", "src_port": 43283, "dest_ip": "185.254.126.122", "dest_port": 2000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:55:14.082152+0100", "src_ip": "65.49.1.159", "dest_ip": "185.254.126.122", "src_port": 43283, "dest_port": 2000}}'); INSERT INTO alerts VALUES(403,1772981816.086250066,'{"timestamp": "2026-03-08T15:56:56.086250+0100", "flow_id": 88966794091111, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59739, "dest_ip": "185.254.126.122", "dest_port": 36680, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:56:56.086250+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59739, "dest_port": 36680}}'); INSERT INTO alerts VALUES(404,1772981816.086250066,'{"timestamp": "2026-03-08T15:56:56.086250+0100", "flow_id": 88966794091111, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59739, "dest_ip": "185.254.126.122", "dest_port": 36680, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:56:56.086250+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59739, "dest_port": 36680}}'); INSERT INTO alerts VALUES(405,1772981822.245215893,'{"timestamp": "2026-03-08T15:57:02.245216+0100", "flow_id": 1897620458581306, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 53108, "dest_ip": "185.254.126.122", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:57:02.245216+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 53108, "dest_port": 8545}}'); INSERT INTO alerts VALUES(406,1772981822.245215893,'{"timestamp": "2026-03-08T15:57:02.245216+0100", "flow_id": 1897620458581306, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 53108, "dest_ip": "185.254.126.122", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T15:57:02.245216+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 53108, "dest_port": 8545}}'); INSERT INTO alerts VALUES(407,1772981847.195748091,'{"timestamp": "2026-03-08T15:57:27.195748+0100", "flow_id": 2248109721357703, "event_type": "alert", "src_ip": "167.94.146.44", "src_port": 21956, "dest_ip": "185.254.126.122", "dest_port": 3408, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T15:57:27.195748+0100", "src_ip": "167.94.146.44", "dest_ip": "185.254.126.122", "src_port": 21956, "dest_port": 3408}}'); INSERT INTO alerts VALUES(408,1772981871.141413927,'{"timestamp": "2026-03-08T15:57:51.141414+0100", "flow_id": 2014746752692622, "event_type": "alert", "src_ip": "64.62.197.10", "src_port": 38292, "dest_ip": "185.254.126.122", "dest_port": 1723, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:57:51.141414+0100", "src_ip": "64.62.197.10", "dest_ip": "185.254.126.122", "src_port": 38292, "dest_port": 1723}}'); INSERT INTO alerts VALUES(409,1772981911.127892017,'{"timestamp": "2026-03-08T15:58:31.127892+0100", "flow_id": 2238142554034898, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 59825, "dest_ip": "185.254.126.122", "dest_port": 8181, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T15:58:31.127892+0100", "src_ip": "87.121.84.57", "dest_ip": "185.254.126.122", "src_port": 59825, "dest_port": 8181}}'); INSERT INTO alerts VALUES(410,1772981918.657738925,'{"timestamp": "2026-03-08T15:58:38.657739+0100", "flow_id": 1699070444478570, "event_type": "alert", "src_ip": "185.242.226.87", "src_port": 55780, "dest_ip": "185.254.126.122", "dest_port": 8200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T15:58:38.657739+0100", "src_ip": "185.242.226.87", "dest_ip": "185.254.126.122", "src_port": 55780, "dest_port": 8200}}'); INSERT INTO alerts VALUES(411,1772982051.375852108,'{"timestamp": "2026-03-08T16:00:51.375852+0100", "flow_id": 1051324799752390, "event_type": "alert", "src_ip": "64.62.156.217", "src_port": 58350, "dest_ip": "185.254.126.122", "dest_port": 5801, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:00:51.375852+0100", "src_ip": "64.62.156.217", "dest_ip": "185.254.126.122", "src_port": 58350, "dest_port": 5801}}'); INSERT INTO alerts VALUES(412,1772982067.580059052,'{"timestamp": "2026-03-08T16:01:07.580059+0100", "flow_id": 1083961644637008, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 35751, "dest_ip": "185.254.126.122", "dest_port": 36282, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:01:07.580059+0100", "src_ip": "167.94.146.32", "dest_ip": "185.254.126.122", "src_port": 35751, "dest_port": 36282}}'); INSERT INTO alerts VALUES(413,1772982093.956510066,'{"timestamp": "2026-03-08T16:01:33.956510+0100", "flow_id": 1574907982001894, "event_type": "alert", "src_ip": "88.210.63.191", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 31443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:01:33.956510+0100", "src_ip": "88.210.63.191", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 31443}}'); INSERT INTO alerts VALUES(414,1772982118.79122591,'{"timestamp": "2026-03-08T16:01:58.791226+0100", "flow_id": 1709443006557988, "event_type": "alert", "src_ip": "64.62.197.222", "src_port": 37586, "dest_ip": "185.254.126.122", "dest_port": 8001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:01:58.791226+0100", "src_ip": "64.62.197.222", "dest_ip": "185.254.126.122", "src_port": 37586, "dest_port": 8001}}'); INSERT INTO alerts VALUES(415,1772982164.517153979,'{"timestamp": "2026-03-08T16:02:44.517154+0100", "flow_id": 1376737769282370, "event_type": "alert", "src_ip": "45.142.154.10", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 123, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ntp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-08T16:02:44.517154+0100", "src_ip": "45.142.154.10", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 123}}'); INSERT INTO alerts VALUES(416,1772982165.732769013,'{"timestamp": "2026-03-08T16:02:45.732769+0100", "flow_id": 1458372740713912, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 53222, "dest_ip": "185.254.126.122", "dest_port": 45750, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:02:45.732769+0100", "src_ip": "167.94.146.37", "dest_ip": "185.254.126.122", "src_port": 53222, "dest_port": 45750}}'); INSERT INTO alerts VALUES(417,1772982186.498567105,'{"timestamp": "2026-03-08T16:03:06.498567+0100", "flow_id": 733958223971213, "event_type": "alert", "src_ip": "178.20.210.152", "src_port": 41612, "dest_ip": "185.254.126.122", "dest_port": 3001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:03:06.498567+0100", "src_ip": "178.20.210.152", "dest_ip": "185.254.126.122", "src_port": 41612, "dest_port": 3001}}'); INSERT INTO alerts VALUES(418,1772982202.566750049,'{"timestamp": "2026-03-08T16:03:22.566750+0100", "flow_id": 745324926560660, "event_type": "alert", "src_ip": "167.94.138.147", "src_port": 16147, "dest_ip": "185.254.126.122", "dest_port": 5902, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:03:22.566750+0100", "src_ip": "167.94.138.147", "dest_ip": "185.254.126.122", "src_port": 16147, "dest_port": 5902}}'); INSERT INTO alerts VALUES(419,1772982345.265608073,'{"timestamp": "2026-03-08T16:05:45.265608+0100", "flow_id": 296354661809009, "event_type": "alert", "src_ip": "193.163.125.20", "src_port": 43603, "dest_ip": "185.254.126.122", "dest_port": 20102, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:05:45.265608+0100", "src_ip": "193.163.125.20", "dest_ip": "185.254.126.122", "src_port": 43603, "dest_port": 20102}}'); INSERT INTO alerts VALUES(420,1772982381.194309949,'{"timestamp": "2026-03-08T16:06:21.194310+0100", "flow_id": 1678984042587869, "event_type": "alert", "src_ip": "178.16.52.218", "src_port": 40814, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:06:21.194310+0100", "src_ip": "178.16.52.218", "dest_ip": "185.254.126.122", "src_port": 40814, "dest_port": 80}}'); INSERT INTO alerts VALUES(421,1772982412.821803092,'{"timestamp": "2026-03-08T16:06:52.821803+0100", "flow_id": 1277819723063414, "event_type": "alert", "src_ip": "87.121.84.72", "src_port": 44065, "dest_ip": "185.254.126.122", "dest_port": 1094, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:06:52.821803+0100", "src_ip": "87.121.84.72", "dest_ip": "185.254.126.122", "src_port": 44065, "dest_port": 1094}}'); INSERT INTO alerts VALUES(422,1772982423.243834972,'{"timestamp": "2026-03-08T16:07:03.243835+0100", "flow_id": 2173166323928449, "event_type": "alert", "src_ip": "52.146.90.191", "src_port": 34361, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T16:07:03.243835+0100", "src_ip": "52.146.90.191", "dest_ip": "185.254.126.122", "src_port": 34361, "dest_port": 3306}}'); INSERT INTO alerts VALUES(423,1772982433.802041054,'{"timestamp": "2026-03-08T16:07:13.802041+0100", "flow_id": 348516830134667, "event_type": "alert", "src_ip": "193.163.125.17", "src_port": 48855, "dest_ip": "185.254.126.122", "dest_port": 5010, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:07:13.802041+0100", "src_ip": "193.163.125.17", "dest_ip": "185.254.126.122", "src_port": 48855, "dest_port": 5010}}'); INSERT INTO alerts VALUES(424,1772982462.431876897,'{"timestamp": "2026-03-08T16:07:42.431877+0100", "flow_id": 1854898706125948, "event_type": "alert", "src_ip": "185.242.226.108", "src_port": 38408, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T16:07:42.431877+0100", "src_ip": "185.242.226.108", "dest_ip": "185.254.126.122", "src_port": 38408, "dest_port": 80}}'); INSERT INTO alerts VALUES(425,1772982473.2489779,'{"timestamp": "2026-03-08T16:07:53.248978+0100", "flow_id": 506405866285413, "event_type": "alert", "src_ip": "204.76.203.18", "src_port": 43597, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T16:07:53.248978+0100", "src_ip": "204.76.203.18", "dest_ip": "185.254.126.122", "src_port": 43597, "dest_port": 443}}'); INSERT INTO alerts VALUES(426,1772982473.2489779,'{"timestamp": "2026-03-08T16:07:53.248978+0100", "flow_id": 506405866285413, "event_type": "alert", "src_ip": "204.76.203.18", "src_port": 43597, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T16:07:53.248978+0100", "src_ip": "204.76.203.18", "dest_ip": "185.254.126.122", "src_port": 43597, "dest_port": 443}}'); INSERT INTO alerts VALUES(427,1772982493.046178102,'{"timestamp": "2026-03-08T16:08:13.046178+0100", "flow_id": 1605709488647841, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63731, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2057745, "rev": 1, "signature": "ET INFO DNS Query to Cloudflare Page Developer Domain (pages .dev)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_11_20"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_11_20"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54218, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "kaufradar-teaser.pages.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-08T16:08:13.046178+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63731, "dest_port": 53}}'); INSERT INTO alerts VALUES(428,1772982583.441432,'{"timestamp": "2026-03-08T16:09:43.441432+0100", "flow_id": 2177411352080296, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 54977, "dest_ip": "185.254.126.122", "dest_port": 8968, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:09:43.441432+0100", "src_ip": "167.94.146.45", "dest_ip": "185.254.126.122", "src_port": 54977, "dest_port": 8968}}'); INSERT INTO alerts VALUES(429,1772982593.318993092,'{"timestamp": "2026-03-08T16:09:53.318993+0100", "flow_id": 525641132905385, "event_type": "alert", "src_ip": "88.210.63.190", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 55555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:09:53.318993+0100", "src_ip": "88.210.63.190", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 55555}}'); INSERT INTO alerts VALUES(430,1772982623.864649057,'{"timestamp": "2026-03-08T16:10:23.864649+0100", "flow_id": 2024789963708310, "event_type": "alert", "src_ip": "64.89.163.134", "src_port": 42604, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:10:23.864649+0100", "src_ip": "64.89.163.134", "dest_ip": "185.254.126.122", "src_port": 42604, "dest_port": 5432}}'); INSERT INTO alerts VALUES(431,1772982623.864649057,'{"timestamp": "2026-03-08T16:10:23.864649+0100", "flow_id": 2024789963708310, "event_type": "alert", "src_ip": "64.89.163.134", "src_port": 42604, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:10:23.864649+0100", "src_ip": "64.89.163.134", "dest_ip": "185.254.126.122", "src_port": 42604, "dest_port": 5432}}'); INSERT INTO alerts VALUES(432,1772982645.049240112,'{"timestamp": "2026-03-08T16:10:45.049240+0100", "flow_id": 1618861834004802, "event_type": "alert", "src_ip": "193.163.125.24", "src_port": 54849, "dest_ip": "185.254.126.122", "dest_port": 20211, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:10:45.049240+0100", "src_ip": "193.163.125.24", "dest_ip": "185.254.126.122", "src_port": 54849, "dest_port": 20211}}'); INSERT INTO alerts VALUES(433,1772982659.086494923,'{"timestamp": "2026-03-08T16:10:59.086495+0100", "flow_id": 934445011851045, "event_type": "alert", "src_ip": "205.210.31.66", "src_port": 49253, "dest_ip": "185.254.126.122", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-08T16:10:59.086495+0100", "src_ip": "205.210.31.66", "dest_ip": "185.254.126.122", "src_port": 49253, "dest_port": 161}}'); INSERT INTO alerts VALUES(434,1772982659.086494923,'{"timestamp": "2026-03-08T16:10:59.086495+0100", "flow_id": 934445011851045, "event_type": "alert", "src_ip": "205.210.31.66", "src_port": 49253, "dest_ip": "185.254.126.122", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-08T16:10:59.086495+0100", "src_ip": "205.210.31.66", "dest_ip": "185.254.126.122", "src_port": 49253, "dest_port": 161}}'); INSERT INTO alerts VALUES(435,1772982748.459856986,'{"timestamp": "2026-03-08T16:12:28.459857+0100", "flow_id": 1130650119023993, "event_type": "alert", "src_ip": "176.65.148.65", "src_port": 57439, "dest_ip": "185.254.126.122", "dest_port": 123, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 36, "bytes_toclient": 0, "start": "2026-03-08T16:12:28.459857+0100", "src_ip": "176.65.148.65", "dest_ip": "185.254.126.122", "src_port": 57439, "dest_port": 123}}'); INSERT INTO alerts VALUES(436,1772982748.459856986,'{"timestamp": "2026-03-08T16:12:28.459857+0100", "flow_id": 1130650119023993, "event_type": "alert", "src_ip": "176.65.148.65", "src_port": 57439, "dest_ip": "185.254.126.122", "dest_port": 123, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 36, "bytes_toclient": 0, "start": "2026-03-08T16:12:28.459857+0100", "src_ip": "176.65.148.65", "dest_ip": "185.254.126.122", "src_port": 57439, "dest_port": 123}}'); INSERT INTO alerts VALUES(437,1772982826.703056098,'{"timestamp": "2026-03-08T16:13:46.703056+0100", "flow_id": 767802976497768, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 64432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:13:46.703056+0100", "src_ip": "185.156.73.181", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 64432}}'); INSERT INTO alerts VALUES(438,1772982852.657496929,'{"timestamp": "2026-03-08T16:14:12.657497+0100", "flow_id": 1135078407871130, "event_type": "alert", "src_ip": "45.153.34.187", "src_port": 51349, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:14:12.657497+0100", "src_ip": "45.153.34.187", "dest_ip": "185.254.126.122", "src_port": 51349, "dest_port": 80}}'); INSERT INTO alerts VALUES(439,1772983127.678901911,'{"timestamp": "2026-03-08T16:18:47.678902+0100", "flow_id": 2071439756189379, "event_type": "alert", "src_ip": "87.121.84.76", "src_port": 37025, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:18:47.678902+0100", "src_ip": "87.121.84.76", "dest_ip": "185.254.126.122", "src_port": 37025, "dest_port": 80}}'); INSERT INTO alerts VALUES(440,1772983165.272049904,'{"timestamp": "2026-03-08T16:19:25.272050+0100", "flow_id": 1449922172572110, "event_type": "alert", "src_ip": "193.163.125.16", "src_port": 46532, "dest_ip": "185.254.126.122", "dest_port": 19222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:19:25.272050+0100", "src_ip": "193.163.125.16", "dest_ip": "185.254.126.122", "src_port": 46532, "dest_port": 19222}}'); INSERT INTO alerts VALUES(441,1772983187.243932008,'{"timestamp": "2026-03-08T16:19:47.243932+0100", "flow_id": 1047681507445392, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59317, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1928, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T16:19:47.243932+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59317, "dest_port": 53}}'); INSERT INTO alerts VALUES(442,1772983187.243932008,'{"timestamp": "2026-03-08T16:19:47.243932+0100", "flow_id": 1047683387832980, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 35279, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13303, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T16:19:47.243932+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 35279, "dest_port": 53}}'); INSERT INTO alerts VALUES(443,1772983192.758270978,'{"timestamp": "2026-03-08T16:19:52.758271+0100", "flow_id": 160528073746398, "event_type": "alert", "src_ip": "167.94.146.34", "src_port": 43984, "dest_ip": "185.254.126.122", "dest_port": 41449, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:19:52.758271+0100", "src_ip": "167.94.146.34", "dest_ip": "185.254.126.122", "src_port": 43984, "dest_port": 41449}}'); INSERT INTO alerts VALUES(444,1772983327.290122986,'{"timestamp": "2026-03-08T16:22:07.290123+0100", "flow_id": 2090494553513625, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36016, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31813, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T16:22:07.290123+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36016, "dest_port": 53}}'); INSERT INTO alerts VALUES(445,1772983327.290599108,'{"timestamp": "2026-03-08T16:22:07.290599+0100", "flow_id": 2092540515724860, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43935, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63730, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T16:22:07.290599+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43935, "dest_port": 53}}'); INSERT INTO alerts VALUES(446,1772983466.492854118,'{"timestamp": "2026-03-08T16:24:26.492854+0100", "flow_id": 709417954493710, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57705, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3477, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T16:24:26.492854+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57705, "dest_port": 53}}'); INSERT INTO alerts VALUES(447,1772983481.520857095,'{"timestamp": "2026-03-08T16:24:41.520857+0100", "flow_id": 490540381332187, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34632, "dest_ip": "94.130.164.126", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053282, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "relays.syncthing.net", "version": "TLS 1.3", "ja3": {"hash": "473cd7cb9faa642487833865d516e578", "string": "771,49195-49199-49196-49200-52393-52392-49161-49171-49162-49172-156-157-47-53-49170-10-4865-4866-4867,0-5-10-11-13-65281-18-43-51,29-23-24-25,0"}, "ja4": "t13d190900_9dc949149365_97f8aa674fd9"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 3, "pkts_toclient": 1, "bytes_toserver": 432, "bytes_toclient": 60, "start": "2026-03-08T16:24:41.507428+0100", "src_ip": "192.168.2.16", "dest_ip": "94.130.164.126", "src_port": 34632, "dest_port": 443}}'); INSERT INTO alerts VALUES(448,1772983493.994020938,'{"timestamp": "2026-03-08T16:24:53.994021+0100", "flow_id": 1454538958475829, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40157, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37876, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T16:24:53.994021+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40157, "dest_port": 53}}'); INSERT INTO alerts VALUES(449,1772983493.994874001,'{"timestamp": "2026-03-08T16:24:53.994874+0100", "flow_id": 1458204093888085, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40417, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1433, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T16:24:53.994874+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40417, "dest_port": 53}}'); INSERT INTO alerts VALUES(450,1772983493.994874001,'{"timestamp": "2026-03-08T16:24:53.994874+0100", "flow_id": 1458203153664638, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 53667, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58221, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T16:24:53.994874+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 53667, "dest_port": 53}}'); INSERT INTO alerts VALUES(451,1772983509.603434085,'{"timestamp": "2026-03-08T16:25:09.603434+0100", "flow_id": 1465830021168698, "event_type": "alert", "src_ip": "85.217.140.13", "src_port": 60039, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T16:25:09.603434+0100", "src_ip": "85.217.140.13", "dest_ip": "185.254.126.122", "src_port": 60039, "dest_port": 5432}}'); INSERT INTO alerts VALUES(452,1772983544.106472969,'{"timestamp": "2026-03-08T16:25:44.106473+0100", "flow_id": 175823174883444, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "185.254.126.122", "dest_port": 14382, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:25:44.106473+0100", "src_ip": "79.124.40.110", "dest_ip": "185.254.126.122", "src_port": 52537, "dest_port": 14382}}'); INSERT INTO alerts VALUES(453,1772983572.972450018,'{"timestamp": "2026-03-08T16:26:12.972450+0100", "flow_id": 1361893309862427, "event_type": "alert", "src_ip": "193.163.125.30", "src_port": 54460, "dest_ip": "185.254.126.122", "dest_port": 1801, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:26:12.972450+0100", "src_ip": "193.163.125.30", "dest_ip": "185.254.126.122", "src_port": 54460, "dest_port": 1801}}'); INSERT INTO alerts VALUES(454,1772983581.66011095,'{"timestamp": "2026-03-08T16:26:21.660111+0100", "flow_id": 1427782223230921, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 42133, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:26:21.660111+0100", "src_ip": "79.124.62.126", "dest_ip": "185.254.126.122", "src_port": 42133, "dest_port": 3389}}'); INSERT INTO alerts VALUES(455,1772983630.504271984,'{"timestamp": "2026-03-08T16:27:10.504272+0100", "flow_id": 1884357145532917, "event_type": "alert", "src_ip": "167.94.138.98", "src_port": 9566, "dest_ip": "185.254.126.122", "dest_port": 43767, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:27:10.504272+0100", "src_ip": "167.94.138.98", "dest_ip": "185.254.126.122", "src_port": 9566, "dest_port": 43767}}'); INSERT INTO alerts VALUES(456,1772983643.422702075,'{"timestamp": "2026-03-08T16:27:23.422702+0100", "flow_id": 971068947125134, "event_type": "alert", "src_ip": "64.89.163.244", "src_port": 43516, "dest_ip": "185.254.126.122", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:27:23.422702+0100", "src_ip": "64.89.163.244", "dest_ip": "185.254.126.122", "src_port": 43516, "dest_port": 27017}}'); INSERT INTO alerts VALUES(457,1772983650.108805894,'{"timestamp": "2026-03-08T16:27:30.108806+0100", "flow_id": 748795235021661, "event_type": "alert", "src_ip": "91.196.152.20", "src_port": 53353, "dest_ip": "185.254.126.122", "dest_port": 2080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:27:30.108806+0100", "src_ip": "91.196.152.20", "dest_ip": "185.254.126.122", "src_port": 53353, "dest_port": 2080}}'); INSERT INTO alerts VALUES(458,1772983657.880790949,'{"timestamp": "2026-03-08T16:27:37.880791+0100", "flow_id": 405269963638629, "event_type": "alert", "src_ip": "176.65.134.34", "src_port": 53397, "dest_ip": "185.254.126.122", "dest_port": 40000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:27:37.880791+0100", "src_ip": "176.65.134.34", "dest_ip": "185.254.126.122", "src_port": 53397, "dest_port": 40000}}'); INSERT INTO alerts VALUES(459,1772983666.850575923,'{"timestamp": "2026-03-08T16:27:46.850576+0100", "flow_id": 838448564608170, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 43036, "dest_ip": "185.254.126.122", "dest_port": 9097, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:27:46.850576+0100", "src_ip": "79.124.62.230", "dest_ip": "185.254.126.122", "src_port": 43036, "dest_port": 9097}}'); INSERT INTO alerts VALUES(460,1772983671.504198075,'{"timestamp": "2026-03-08T16:27:51.504198+0100", "flow_id": 2165515840670180, "event_type": "alert", "src_ip": "167.94.146.42", "src_port": 55866, "dest_ip": "185.254.126.122", "dest_port": 11964, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:27:51.504198+0100", "src_ip": "167.94.146.42", "dest_ip": "185.254.126.122", "src_port": 55866, "dest_port": 11964}}'); INSERT INTO alerts VALUES(461,1772983684.054572105,'{"timestamp": "2026-03-08T16:28:04.054572+0100", "flow_id": 1360288157410758, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 2080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:28:04.054572+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 2080}}'); INSERT INTO alerts VALUES(462,1772983684.054572105,'{"timestamp": "2026-03-08T16:28:04.054572+0100", "flow_id": 1360288157410758, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 2080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:28:04.054572+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 2080}}'); INSERT INTO alerts VALUES(463,1772983715.16189003,'{"timestamp": "2026-03-08T16:28:35.161890+0100", "flow_id": 976788752273050, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 57202, "dest_ip": "185.254.126.122", "dest_port": 3447, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:28:35.161890+0100", "src_ip": "45.142.193.7", "dest_ip": "185.254.126.122", "src_port": 57202, "dest_port": 3447}}'); INSERT INTO alerts VALUES(464,1772983755.092349052,'{"timestamp": "2026-03-08T16:29:15.092349+0100", "flow_id": 959589416409074, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 43653, "dest_ip": "185.254.126.122", "dest_port": 71, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:29:15.092349+0100", "src_ip": "79.124.62.134", "dest_ip": "185.254.126.122", "src_port": 43653, "dest_port": 71}}'); INSERT INTO alerts VALUES(465,1772983836.755261899,'{"timestamp": "2026-03-08T16:30:36.755262+0100", "flow_id": 1273501191537648, "event_type": "alert", "src_ip": "117.40.159.18", "src_port": 54793, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T16:30:36.755262+0100", "src_ip": "117.40.159.18", "dest_ip": "185.254.126.122", "src_port": 54793, "dest_port": 1433}}'); INSERT INTO alerts VALUES(466,1772983842.878675938,'{"timestamp": "2026-03-08T16:30:42.878676+0100", "flow_id": 677662959913846, "event_type": "alert", "src_ip": "178.16.52.218", "src_port": 40798, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:30:42.878676+0100", "src_ip": "178.16.52.218", "dest_ip": "185.254.126.122", "src_port": 40798, "dest_port": 443}}'); INSERT INTO alerts VALUES(467,1772983854.827991963,'{"timestamp": "2026-03-08T16:30:54.827992+0100", "flow_id": 1867350179979252, "event_type": "alert", "src_ip": "77.83.39.250", "src_port": 41340, "dest_ip": "185.254.126.122", "dest_port": 587, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400008, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 9", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:30:54.827992+0100", "src_ip": "77.83.39.250", "dest_ip": "185.254.126.122", "src_port": 41340, "dest_port": 587}}'); INSERT INTO alerts VALUES(468,1772983877.221784114,'{"timestamp": "2026-03-08T16:31:17.221784+0100", "flow_id": 1515509212608294, "event_type": "alert", "src_ip": "167.94.146.65", "src_port": 36649, "dest_ip": "185.254.126.122", "dest_port": 16982, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:31:17.221784+0100", "src_ip": "167.94.146.65", "dest_ip": "185.254.126.122", "src_port": 36649, "dest_port": 16982}}'); INSERT INTO alerts VALUES(469,1772983909.313740969,'{"timestamp": "2026-03-08T16:31:49.313741+0100", "flow_id": 1628984434743085, "event_type": "alert", "src_ip": "130.12.180.65", "src_port": 58231, "dest_ip": "185.254.126.122", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:31:49.313741+0100", "src_ip": "130.12.180.65", "dest_ip": "185.254.126.122", "src_port": 58231, "dest_port": 5555}}'); INSERT INTO alerts VALUES(470,1772983909.313740969,'{"timestamp": "2026-03-08T16:31:49.313741+0100", "flow_id": 1628984434743085, "event_type": "alert", "src_ip": "130.12.180.65", "src_port": 58231, "dest_ip": "185.254.126.122", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:31:49.313741+0100", "src_ip": "130.12.180.65", "dest_ip": "185.254.126.122", "src_port": 58231, "dest_port": 5555}}'); INSERT INTO alerts VALUES(471,1772983938.554352046,'{"timestamp": "2026-03-08T16:32:18.554352+0100", "flow_id": 692075385005553, "event_type": "alert", "src_ip": "147.185.132.241", "src_port": 57300, "dest_ip": "185.254.126.122", "dest_port": 65529, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:32:18.554352+0100", "src_ip": "147.185.132.241", "dest_ip": "185.254.126.122", "src_port": 57300, "dest_port": 65529}}'); INSERT INTO alerts VALUES(472,1772984022.269624948,'{"timestamp": "2026-03-08T16:33:42.269625+0100", "flow_id": 1720983614622157, "event_type": "alert", "src_ip": "167.94.146.46", "src_port": 27787, "dest_ip": "185.254.126.122", "dest_port": 20264, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:33:42.269625+0100", "src_ip": "167.94.146.46", "dest_ip": "185.254.126.122", "src_port": 27787, "dest_port": 20264}}'); INSERT INTO alerts VALUES(473,1772984057.322400093,'{"timestamp": "2026-03-08T16:34:17.322400+0100", "flow_id": 540274483024759, "event_type": "alert", "src_ip": "167.94.138.151", "src_port": 16312, "dest_ip": "185.254.126.122", "dest_port": 2456, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:34:17.322400+0100", "src_ip": "167.94.138.151", "dest_ip": "185.254.126.122", "src_port": 16312, "dest_port": 2456}}'); INSERT INTO alerts VALUES(474,1772984075.039175987,'{"timestamp": "2026-03-08T16:34:35.039176+0100", "flow_id": 1012688685913352, "event_type": "alert", "src_ip": "91.196.152.156", "src_port": 19577, "dest_ip": "185.254.126.122", "dest_port": 55443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:34:35.039176+0100", "src_ip": "91.196.152.156", "dest_ip": "185.254.126.122", "src_port": 19577, "dest_port": 55443}}'); INSERT INTO alerts VALUES(475,1772984173.15208006,'{"timestamp": "2026-03-08T16:36:13.152080+0100", "flow_id": 1497605465607160, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 43123, "dest_ip": "185.254.126.122", "dest_port": 21906, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:36:13.152080+0100", "src_ip": "167.94.146.40", "dest_ip": "185.254.126.122", "src_port": 43123, "dest_port": 21906}}'); INSERT INTO alerts VALUES(476,1772984243.760792971,'{"timestamp": "2026-03-08T16:37:23.760793+0100", "flow_id": 1015784818253085, "event_type": "alert", "src_ip": "147.185.132.44", "src_port": 55057, "dest_ip": "185.254.126.122", "dest_port": 28009, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:37:23.760793+0100", "src_ip": "147.185.132.44", "dest_ip": "185.254.126.122", "src_port": 55057, "dest_port": 28009}}'); INSERT INTO alerts VALUES(477,1772984272.033152103,'{"timestamp": "2026-03-08T16:37:52.033152+0100", "flow_id": 142390535535138, "event_type": "alert", "src_ip": "88.210.63.190", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 8000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:37:52.033152+0100", "src_ip": "88.210.63.190", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 8000}}'); INSERT INTO alerts VALUES(478,1772984367.719733954,'{"timestamp": "2026-03-08T16:39:27.719734+0100", "flow_id": 2246810946611821, "event_type": "alert", "src_ip": "167.94.138.107", "src_port": 2602, "dest_ip": "185.254.126.122", "dest_port": 13202, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:39:27.719734+0100", "src_ip": "167.94.138.107", "dest_ip": "185.254.126.122", "src_port": 2602, "dest_port": 13202}}'); INSERT INTO alerts VALUES(479,1772984375.429728031,'{"timestamp": "2026-03-08T16:39:35.429728+0100", "flow_id": 2127144414309605, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 57816, "dest_ip": "185.254.126.122", "dest_port": 22222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:39:35.429728+0100", "src_ip": "79.124.40.82", "dest_ip": "185.254.126.122", "src_port": 57816, "dest_port": 22222}}'); INSERT INTO alerts VALUES(480,1772984497.230559111,'{"timestamp": "2026-03-08T16:41:37.230559+0100", "flow_id": 427293491306551, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 9444, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:41:37.230559+0100", "src_ip": "185.156.73.181", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 9444}}'); INSERT INTO alerts VALUES(481,1772984611.955027104,'{"timestamp": "2026-03-08T16:43:31.955027+0100", "flow_id": 1005586561665684, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 41362, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:43:31.955027+0100", "src_ip": "193.142.146.230", "dest_ip": "185.254.126.122", "src_port": 41362, "dest_port": 8080}}'); INSERT INTO alerts VALUES(482,1772984648.190538884,'{"timestamp": "2026-03-08T16:44:08.190539+0100", "flow_id": 255411237477906, "event_type": "alert", "src_ip": "176.65.139.46", "src_port": 59949, "dest_ip": "185.254.126.122", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:44:08.190539+0100", "src_ip": "176.65.139.46", "dest_ip": "185.254.126.122", "src_port": 59949, "dest_port": 23}}'); INSERT INTO alerts VALUES(483,1772984746.732268095,'{"timestamp": "2026-03-08T16:45:46.732268+0100", "flow_id": 611795875234246, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41416, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47671, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T16:45:46.732268+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41416, "dest_port": 53}}'); INSERT INTO alerts VALUES(484,1772984746.733058929,'{"timestamp": "2026-03-08T16:45:46.733059+0100", "flow_id": 615190894534619, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 37924, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33850, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T16:45:46.733059+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 37924, "dest_port": 53}}'); INSERT INTO alerts VALUES(485,1772984751.175523043,'{"timestamp": "2026-03-08T16:45:51.175523+0100", "flow_id": 2161240942577694, "event_type": "alert", "src_ip": "45.156.87.91", "src_port": 56716, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T16:45:51.175523+0100", "src_ip": "45.156.87.91", "dest_ip": "185.254.126.122", "src_port": 56716, "dest_port": 8080}}'); INSERT INTO alerts VALUES(486,1772984763.10732007,'{"timestamp": "2026-03-08T16:46:03.107320+0100", "flow_id": 1023889040145372, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 38355, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59018, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T16:46:03.107320+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 38355, "dest_port": 53}}'); INSERT INTO alerts VALUES(487,1772984763.107321024,'{"timestamp": "2026-03-08T16:46:03.107321+0100", "flow_id": 1023893575620540, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 54325, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62797, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T16:46:03.107321+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 54325, "dest_port": 53}}'); INSERT INTO alerts VALUES(488,1772984763.294047118,'{"timestamp": "2026-03-08T16:46:03.294047+0100", "flow_id": 981447365254387, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33250, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28653, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-08T16:46:03.294047+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33250, "dest_port": 53}}'); INSERT INTO alerts VALUES(489,1772984844.709384919,'{"timestamp": "2026-03-08T16:47:24.709385+0100", "flow_id": 1357939193647459, "event_type": "alert", "src_ip": "91.196.152.44", "src_port": 26843, "dest_ip": "185.254.126.122", "dest_port": 53, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:47:24.709385+0100", "src_ip": "91.196.152.44", "dest_ip": "185.254.126.122", "src_port": 26843, "dest_port": 53}}'); INSERT INTO alerts VALUES(490,1772984845.280729056,'{"timestamp": "2026-03-08T16:47:25.280729+0100", "flow_id": 1487199445022307, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59739, "dest_ip": "185.254.126.122", "dest_port": 61453, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:47:25.280729+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59739, "dest_port": 61453}}'); INSERT INTO alerts VALUES(491,1772984845.280729056,'{"timestamp": "2026-03-08T16:47:25.280729+0100", "flow_id": 1487199445022307, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59739, "dest_ip": "185.254.126.122", "dest_port": 61453, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:47:25.280729+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59739, "dest_port": 61453}}'); INSERT INTO alerts VALUES(492,1772984845.604773045,'{"timestamp": "2026-03-08T16:47:25.604773+0100", "flow_id": 1471583418366983, "event_type": "alert", "src_ip": "185.94.111.1", "src_port": 47023, "dest_ip": "185.254.126.122", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 61, "bytes_toclient": 0, "start": "2026-03-08T16:47:25.604773+0100", "src_ip": "185.94.111.1", "dest_ip": "185.254.126.122", "src_port": 47023, "dest_port": 161}}'); INSERT INTO alerts VALUES(493,1772984863.947989941,'{"timestamp": "2026-03-08T16:47:43.947990+0100", "flow_id": 2101263352202529, "event_type": "alert", "src_ip": "205.210.31.132", "src_port": 52947, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:47:43.947990+0100", "src_ip": "205.210.31.132", "dest_ip": "185.254.126.122", "src_port": 52947, "dest_port": 5432}}'); INSERT INTO alerts VALUES(494,1772984863.947989941,'{"timestamp": "2026-03-08T16:47:43.947990+0100", "flow_id": 2101263352202529, "event_type": "alert", "src_ip": "205.210.31.132", "src_port": 52947, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:47:43.947990+0100", "src_ip": "205.210.31.132", "dest_ip": "185.254.126.122", "src_port": 52947, "dest_port": 5432}}'); INSERT INTO alerts VALUES(495,1772984870.335284949,'{"timestamp": "2026-03-08T16:47:50.335285+0100", "flow_id": 1721516847082093, "event_type": "alert", "src_ip": "193.163.125.29", "src_port": 41636, "dest_ip": "185.254.126.122", "dest_port": 30005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:47:50.335285+0100", "src_ip": "193.163.125.29", "dest_ip": "185.254.126.122", "src_port": 41636, "dest_port": 30005}}'); INSERT INTO alerts VALUES(496,1772984870.800051928,'{"timestamp": "2026-03-08T16:47:50.800052+0100", "flow_id": 1747349447680093, "event_type": "alert", "src_ip": "176.65.148.29", "src_port": 49114, "dest_ip": "185.254.126.122", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T16:47:50.800052+0100", "src_ip": "176.65.148.29", "dest_ip": "185.254.126.122", "src_port": 49114, "dest_port": 8332}}'); INSERT INTO alerts VALUES(497,1772984870.800051928,'{"timestamp": "2026-03-08T16:47:50.800052+0100", "flow_id": 1747349447680093, "event_type": "alert", "src_ip": "176.65.148.29", "src_port": 49114, "dest_ip": "185.254.126.122", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T16:47:50.800052+0100", "src_ip": "176.65.148.29", "dest_ip": "185.254.126.122", "src_port": 49114, "dest_port": 8332}}'); INSERT INTO alerts VALUES(498,1772984886.791811943,'{"timestamp": "2026-03-08T16:48:06.791812+0100", "flow_id": 1711960166613676, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60838, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18536, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T16:48:06.791812+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60838, "dest_port": 53}}'); INSERT INTO alerts VALUES(499,1772984886.791811943,'{"timestamp": "2026-03-08T16:48:06.791812+0100", "flow_id": 1711958716474617, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 53860, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30282, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T16:48:06.791812+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 53860, "dest_port": 53}}'); INSERT INTO alerts VALUES(500,1772985026.853801012,'{"timestamp": "2026-03-08T16:50:26.853801+0100", "flow_id": 570826508932384, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 55064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24898, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T16:50:26.853801+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 55064, "dest_port": 53}}'); INSERT INTO alerts VALUES(501,1772985026.853801012,'{"timestamp": "2026-03-08T16:50:26.853801+0100", "flow_id": 570823973247065, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33636, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14034, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-08T16:50:26.853801+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33636, "dest_port": 53}}'); INSERT INTO alerts VALUES(502,1772985076.927608967,'{"timestamp": "2026-03-08T16:51:16.927609+0100", "flow_id": 1169300840297615, "event_type": "alert", "src_ip": "91.196.152.12", "src_port": 47150, "dest_ip": "185.254.126.122", "dest_port": 2095, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T16:51:16.927609+0100", "src_ip": "91.196.152.12", "dest_ip": "185.254.126.122", "src_port": 47150, "dest_port": 2095}}'); INSERT INTO alerts VALUES(503,1772985132.016962051,'{"timestamp": "2026-03-08T16:52:12.016962+0100", "flow_id": 1198753056931526, "event_type": "alert", "src_ip": "185.242.226.11", "src_port": 60011, "dest_ip": "185.254.126.122", "dest_port": 12268, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:52:12.016962+0100", "src_ip": "185.242.226.11", "dest_ip": "185.254.126.122", "src_port": 60011, "dest_port": 12268}}'); INSERT INTO alerts VALUES(504,1772985181.097464084,'{"timestamp": "2026-03-08T16:53:01.097464+0100", "flow_id": 1544505320349018, "event_type": "alert", "src_ip": "193.163.125.9", "src_port": 58376, "dest_ip": "185.254.126.122", "dest_port": 2112, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:53:01.097464+0100", "src_ip": "193.163.125.9", "dest_ip": "185.254.126.122", "src_port": 58376, "dest_port": 2112}}'); INSERT INTO alerts VALUES(505,1772985352.46607089,'{"timestamp": "2026-03-08T16:55:52.466071+0100", "flow_id": 31437781227380, "event_type": "alert", "src_ip": "193.163.125.11", "src_port": 47534, "dest_ip": "185.254.126.122", "dest_port": 104, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T16:55:52.466071+0100", "src_ip": "193.163.125.11", "dest_ip": "185.254.126.122", "src_port": 47534, "dest_port": 104}}'); INSERT INTO alerts VALUES(506,1772985418.183990956,'{"timestamp": "2026-03-08T16:56:58.183991+0100", "flow_id": 790238038850189, "event_type": "alert", "src_ip": "213.209.159.158", "src_port": 57602, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400060, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 61", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T16:56:58.183991+0100", "src_ip": "213.209.159.158", "dest_ip": "185.254.126.122", "src_port": 57602, "dest_port": 22}}'); INSERT INTO alerts VALUES(507,1772985635.792778015,'{"timestamp": "2026-03-08T17:00:35.792778+0100", "flow_id": 871684757101732, "event_type": "alert", "src_ip": "45.153.34.226", "src_port": 38092, "dest_ip": "185.254.126.122", "dest_port": 3328, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T17:00:35.792778+0100", "src_ip": "45.153.34.226", "dest_ip": "185.254.126.122", "src_port": 38092, "dest_port": 3328}}'); INSERT INTO alerts VALUES(508,1772985635.792778015,'{"timestamp": "2026-03-08T17:00:35.792778+0100", "flow_id": 871684757101732, "event_type": "alert", "src_ip": "45.153.34.226", "src_port": 38092, "dest_ip": "185.254.126.122", "dest_port": 3328, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500030, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 16", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T17:00:35.792778+0100", "src_ip": "45.153.34.226", "dest_ip": "185.254.126.122", "src_port": 38092, "dest_port": 3328}}'); INSERT INTO alerts VALUES(509,1772985804.399805069,'{"timestamp": "2026-03-08T17:03:24.399805+0100", "flow_id": 1154202378636500, "event_type": "alert", "src_ip": "88.210.63.192", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 64432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:03:24.399805+0100", "src_ip": "88.210.63.192", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 64432}}'); INSERT INTO alerts VALUES(510,1772985881.500466109,'{"timestamp": "2026-03-08T17:04:41.500466+0100", "flow_id": 460636328538988, "event_type": "alert", "src_ip": "45.194.92.56", "src_port": 39787, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:04:41.500466+0100", "src_ip": "45.194.92.56", "dest_ip": "185.254.126.122", "src_port": 39787, "dest_port": 8080}}'); INSERT INTO alerts VALUES(511,1772985895.110693931,'{"timestamp": "2026-03-08T17:04:55.110694+0100", "flow_id": 2164277069763005, "event_type": "alert", "src_ip": "167.94.138.99", "src_port": 60135, "dest_ip": "185.254.126.122", "dest_port": 31182, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:04:55.110694+0100", "src_ip": "167.94.138.99", "dest_ip": "185.254.126.122", "src_port": 60135, "dest_port": 31182}}'); INSERT INTO alerts VALUES(512,1772985951.181596041,'{"timestamp": "2026-03-08T17:05:51.181596+0100", "flow_id": 2187326930518817, "event_type": "alert", "src_ip": "91.224.92.177", "src_port": 46716, "dest_ip": "185.254.126.122", "dest_port": 3001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:05:51.181596+0100", "src_ip": "91.224.92.177", "dest_ip": "185.254.126.122", "src_port": 46716, "dest_port": 3001}}'); INSERT INTO alerts VALUES(513,1772985974.768934965,'{"timestamp": "2026-03-08T17:06:14.768935+0100", "flow_id": 1895178490011227, "event_type": "alert", "src_ip": "91.230.168.108", "src_port": 43191, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:06:14.768935+0100", "src_ip": "91.230.168.108", "dest_ip": "185.254.126.122", "src_port": 43191, "dest_port": 1433}}'); INSERT INTO alerts VALUES(514,1772985988.192663908,'{"timestamp": "2026-03-08T17:06:28.192664+0100", "flow_id": 1390439411127155, "event_type": "alert", "src_ip": "198.235.24.227", "src_port": 50539, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:06:28.192664+0100", "src_ip": "198.235.24.227", "dest_ip": "185.254.126.122", "src_port": 50539, "dest_port": 5060}}'); INSERT INTO alerts VALUES(515,1772986131.379471064,'{"timestamp": "2026-03-08T17:08:51.379471+0100", "flow_id": 1066869836856356, "event_type": "alert", "src_ip": "172.94.9.253", "src_port": 58397, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400031, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 32", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:08:51.379471+0100", "src_ip": "172.94.9.253", "dest_ip": "185.254.126.122", "src_port": 58397, "dest_port": 80}}'); INSERT INTO alerts VALUES(516,1772986152.767803907,'{"timestamp": "2026-03-08T17:09:12.767804+0100", "flow_id": 201469669823368, "event_type": "alert", "src_ip": "193.163.125.20", "src_port": 42946, "dest_ip": "185.254.126.122", "dest_port": 1080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:09:12.767804+0100", "src_ip": "193.163.125.20", "dest_ip": "185.254.126.122", "src_port": 42946, "dest_port": 1080}}'); INSERT INTO alerts VALUES(517,1772986158.972491025,'{"timestamp": "2026-03-08T17:09:18.972491+0100", "flow_id": 1925018381297669, "event_type": "alert", "src_ip": "45.142.154.98", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 139, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:09:18.972491+0100", "src_ip": "45.142.154.98", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 139}}'); INSERT INTO alerts VALUES(518,1772986263.586312055,'{"timestamp": "2026-03-08T17:11:03.586312+0100", "flow_id": 2236715950949126, "event_type": "alert", "src_ip": "167.94.138.152", "src_port": 41740, "dest_ip": "185.254.126.122", "dest_port": 20548, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:11:03.586312+0100", "src_ip": "167.94.138.152", "dest_ip": "185.254.126.122", "src_port": 41740, "dest_port": 20548}}'); INSERT INTO alerts VALUES(519,1772986279.691457033,'{"timestamp": "2026-03-08T17:11:19.691457+0100", "flow_id": 2125362974157734, "event_type": "alert", "src_ip": "185.156.73.182", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 62000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:11:19.691457+0100", "src_ip": "185.156.73.182", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 62000}}'); INSERT INTO alerts VALUES(520,1772986417.062252999,'{"timestamp": "2026-03-08T17:13:37.062253+0100", "flow_id": 548849980893369, "event_type": "alert", "src_ip": "43.228.157.15", "src_port": 59739, "dest_ip": "185.254.126.122", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:13:37.062253+0100", "src_ip": "43.228.157.15", "dest_ip": "185.254.126.122", "src_port": 59739, "dest_port": 23}}'); INSERT INTO alerts VALUES(521,1772986677.170263051,'{"timestamp": "2026-03-08T17:17:57.170263+0100", "flow_id": 1575702313068434, "event_type": "alert", "src_ip": "176.65.148.95", "src_port": 33173, "dest_ip": "185.254.126.122", "dest_port": 12345, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:17:57.170263+0100", "src_ip": "176.65.148.95", "dest_ip": "185.254.126.122", "src_port": 33173, "dest_port": 12345}}'); INSERT INTO alerts VALUES(522,1772986677.170263051,'{"timestamp": "2026-03-08T17:17:57.170263+0100", "flow_id": 1575702313068434, "event_type": "alert", "src_ip": "176.65.148.95", "src_port": 33173, "dest_ip": "185.254.126.122", "dest_port": 12345, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:17:57.170263+0100", "src_ip": "176.65.148.95", "dest_ip": "185.254.126.122", "src_port": 33173, "dest_port": 12345}}'); INSERT INTO alerts VALUES(523,1772986773.618047953,'{"timestamp": "2026-03-08T17:19:33.618048+0100", "flow_id": 1528599759614899, "event_type": "alert", "src_ip": "176.65.148.55", "src_port": 39337, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:19:33.618048+0100", "src_ip": "176.65.148.55", "dest_ip": "185.254.126.122", "src_port": 39337, "dest_port": 8080}}'); INSERT INTO alerts VALUES(524,1772986773.618047953,'{"timestamp": "2026-03-08T17:19:33.618048+0100", "flow_id": 1528599759614899, "event_type": "alert", "src_ip": "176.65.148.55", "src_port": 39337, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:19:33.618048+0100", "src_ip": "176.65.148.55", "dest_ip": "185.254.126.122", "src_port": 39337, "dest_port": 8080}}'); INSERT INTO alerts VALUES(525,1772986825.173356056,'{"timestamp": "2026-03-08T17:20:25.173356+0100", "flow_id": 463085884454150, "event_type": "alert", "src_ip": "79.124.62.178", "src_port": 56406, "dest_ip": "185.254.126.122", "dest_port": 3397, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:20:25.173356+0100", "src_ip": "79.124.62.178", "dest_ip": "185.254.126.122", "src_port": 56406, "dest_port": 3397}}'); INSERT INTO alerts VALUES(526,1772986847.175776004,'{"timestamp": "2026-03-08T17:20:47.175776+0100", "flow_id": 2162330757419835, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 44718, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:20:47.175776+0100", "src_ip": "185.242.246.36", "dest_ip": "185.254.126.122", "src_port": 44718, "dest_port": 22}}'); INSERT INTO alerts VALUES(527,1772986847.175776004,'{"timestamp": "2026-03-08T17:20:47.175776+0100", "flow_id": 2162330757419835, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 44718, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:20:47.175776+0100", "src_ip": "185.242.246.36", "dest_ip": "185.254.126.122", "src_port": 44718, "dest_port": 22}}'); INSERT INTO alerts VALUES(528,1772986875.989116908,'{"timestamp": "2026-03-08T17:21:15.989117+0100", "flow_id": 870527751277538, "event_type": "alert", "src_ip": "147.185.132.43", "src_port": 54917, "dest_ip": "185.254.126.122", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:21:15.989117+0100", "src_ip": "147.185.132.43", "dest_ip": "185.254.126.122", "src_port": 54917, "dest_port": 23}}'); INSERT INTO alerts VALUES(529,1772986884.069772959,'{"timestamp": "2026-03-08T17:21:24.069773+0100", "flow_id": 1144100433554644, "event_type": "alert", "src_ip": "167.94.138.154", "src_port": 65316, "dest_ip": "185.254.126.122", "dest_port": 6362, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:21:24.069773+0100", "src_ip": "167.94.138.154", "dest_ip": "185.254.126.122", "src_port": 65316, "dest_port": 6362}}'); INSERT INTO alerts VALUES(530,1772986903.932306052,'{"timestamp": "2026-03-08T17:21:43.932306+0100", "flow_id": 2033903009339874, "event_type": "alert", "src_ip": "167.94.138.109", "src_port": 8896, "dest_ip": "185.254.126.122", "dest_port": 38607, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:21:43.932306+0100", "src_ip": "167.94.138.109", "dest_ip": "185.254.126.122", "src_port": 8896, "dest_port": 38607}}'); INSERT INTO alerts VALUES(531,1772986910.993628978,'{"timestamp": "2026-03-08T17:21:50.993629+0100", "flow_id": 1734329929855982, "event_type": "alert", "src_ip": "185.156.73.180", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 33, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:21:50.993629+0100", "src_ip": "185.156.73.180", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 33}}'); INSERT INTO alerts VALUES(532,1772987011.133872033,'{"timestamp": "2026-03-08T17:23:31.133872+0100", "flow_id": 856453682475244, "event_type": "alert", "src_ip": "45.142.154.99", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 9999, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:23:31.133872+0100", "src_ip": "45.142.154.99", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 9999}}'); INSERT INTO alerts VALUES(533,1772987167.081490039,'{"timestamp": "2026-03-08T17:26:07.081490+0100", "flow_id": 2038847005226053, "event_type": "alert", "src_ip": "167.94.138.137", "src_port": 24203, "dest_ip": "185.254.126.122", "dest_port": 5672, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:26:07.081490+0100", "src_ip": "167.94.138.137", "dest_ip": "185.254.126.122", "src_port": 24203, "dest_port": 5672}}'); INSERT INTO alerts VALUES(534,1772987186.152793884,'{"timestamp": "2026-03-08T17:26:26.152794+0100", "flow_id": 656249351098835, "event_type": "alert", "src_ip": "176.65.139.31", "src_port": 61475, "dest_ip": "185.254.126.122", "dest_port": 389, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ldap", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-08T17:26:26.152794+0100", "src_ip": "176.65.139.31", "dest_ip": "185.254.126.122", "src_port": 61475, "dest_port": 389}}'); INSERT INTO alerts VALUES(535,1772987256.545439004,'{"timestamp": "2026-03-08T17:27:36.545439+0100", "flow_id": 90846710140892, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "185.254.126.122", "dest_port": 14306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:27:36.545439+0100", "src_ip": "79.124.40.110", "dest_ip": "185.254.126.122", "src_port": 52537, "dest_port": 14306}}'); INSERT INTO alerts VALUES(536,1772987258.981443881,'{"timestamp": "2026-03-08T17:27:38.981444+0100", "flow_id": 837573782271992, "event_type": "alert", "src_ip": "167.94.146.39", "src_port": 40595, "dest_ip": "185.254.126.122", "dest_port": 32045, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:27:38.981444+0100", "src_ip": "167.94.146.39", "dest_ip": "185.254.126.122", "src_port": 40595, "dest_port": 32045}}'); INSERT INTO alerts VALUES(537,1772987287.527376891,'{"timestamp": "2026-03-08T17:28:07.527377+0100", "flow_id": 1983592515889478, "event_type": "alert", "src_ip": "88.210.63.193", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 55, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:28:07.527377+0100", "src_ip": "88.210.63.193", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 55}}'); INSERT INTO alerts VALUES(538,1772987291.563910961,'{"timestamp": "2026-03-08T17:28:11.563911+0100", "flow_id": 1014604614574069, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 42117, "dest_ip": "185.254.126.122", "dest_port": 8612, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:28:11.563911+0100", "src_ip": "79.124.62.126", "dest_ip": "185.254.126.122", "src_port": 42117, "dest_port": 8612}}'); INSERT INTO alerts VALUES(539,1772987321.691730022,'{"timestamp": "2026-03-08T17:28:41.691730+0100", "flow_id": 437684056379201, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 48114, "dest_ip": "185.254.126.122", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T17:28:41.691730+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 48114, "dest_port": 8332}}'); INSERT INTO alerts VALUES(540,1772987321.691730022,'{"timestamp": "2026-03-08T17:28:41.691730+0100", "flow_id": 437684056379201, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 48114, "dest_ip": "185.254.126.122", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T17:28:41.691730+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 48114, "dest_port": 8332}}'); INSERT INTO alerts VALUES(541,1772987377.755420924,'{"timestamp": "2026-03-08T17:29:37.755421+0100", "flow_id": 429760179565612, "event_type": "alert", "src_ip": "193.163.125.37", "src_port": 41353, "dest_ip": "185.254.126.122", "dest_port": 1300, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:29:37.755421+0100", "src_ip": "193.163.125.37", "dest_ip": "185.254.126.122", "src_port": 41353, "dest_port": 1300}}'); INSERT INTO alerts VALUES(542,1772987412.914531946,'{"timestamp": "2026-03-08T17:30:12.914532+0100", "flow_id": 1394610302042271, "event_type": "alert", "src_ip": "64.89.163.97", "src_port": 47426, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:30:12.914532+0100", "src_ip": "64.89.163.97", "dest_ip": "185.254.126.122", "src_port": 47426, "dest_port": 3306}}'); INSERT INTO alerts VALUES(543,1772987412.914531946,'{"timestamp": "2026-03-08T17:30:12.914532+0100", "flow_id": 1394610302042271, "event_type": "alert", "src_ip": "64.89.163.97", "src_port": 47426, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:30:12.914532+0100", "src_ip": "64.89.163.97", "dest_ip": "185.254.126.122", "src_port": 47426, "dest_port": 3306}}'); INSERT INTO alerts VALUES(544,1772987478.527916908,'{"timestamp": "2026-03-08T17:31:18.527917+0100", "flow_id": 1704438498143800, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 43036, "dest_ip": "185.254.126.122", "dest_port": 63186, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:31:18.527917+0100", "src_ip": "79.124.62.230", "dest_ip": "185.254.126.122", "src_port": 43036, "dest_port": 63186}}'); INSERT INTO alerts VALUES(545,1772987527.055741072,'{"timestamp": "2026-03-08T17:32:07.055741+0100", "flow_id": 2209734552843701, "event_type": "alert", "src_ip": "46.19.137.194", "src_port": 48453, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:32:07.055741+0100", "src_ip": "46.19.137.194", "dest_ip": "185.254.126.122", "src_port": 48453, "dest_port": 5432}}'); INSERT INTO alerts VALUES(546,1772987539.156482934,'{"timestamp": "2026-03-08T17:32:19.156483+0100", "flow_id": 953567712418953, "event_type": "alert", "src_ip": "193.163.125.27", "src_port": 33433, "dest_ip": "185.254.126.122", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:32:19.156483+0100", "src_ip": "193.163.125.27", "dest_ip": "185.254.126.122", "src_port": 33433, "dest_port": 27017}}'); INSERT INTO alerts VALUES(547,1772987542.40350008,'{"timestamp": "2026-03-08T17:32:22.403500+0100", "flow_id": 1733021780739585, "event_type": "alert", "src_ip": "193.163.125.4", "src_port": 50999, "dest_ip": "185.254.126.122", "dest_port": 10115, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:32:22.403500+0100", "src_ip": "193.163.125.4", "dest_ip": "185.254.126.122", "src_port": 50999, "dest_port": 10115}}'); INSERT INTO alerts VALUES(548,1772987582.248450995,'{"timestamp": "2026-03-08T17:33:02.248451+0100", "flow_id": 1911516171293268, "event_type": "alert", "src_ip": "102.53.12.221", "src_port": 54015, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:33:02.248451+0100", "src_ip": "102.53.12.221", "dest_ip": "185.254.126.122", "src_port": 54015, "dest_port": 1433}}'); INSERT INTO alerts VALUES(549,1772987728.901315927,'{"timestamp": "2026-03-08T17:35:28.901316+0100", "flow_id": 211950452284474, "event_type": "alert", "src_ip": "91.196.152.28", "src_port": 57030, "dest_ip": "185.254.126.122", "dest_port": 24442, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:35:28.901316+0100", "src_ip": "91.196.152.28", "dest_ip": "185.254.126.122", "src_port": 57030, "dest_port": 24442}}'); INSERT INTO alerts VALUES(550,1772987758.450225115,'{"timestamp": "2026-03-08T17:35:58.450225+0100", "flow_id": 1933701951331983, "event_type": "alert", "src_ip": "167.94.146.38", "src_port": 1609, "dest_ip": "185.254.126.122", "dest_port": 56746, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:35:58.450225+0100", "src_ip": "167.94.146.38", "dest_ip": "185.254.126.122", "src_port": 1609, "dest_port": 56746}}'); INSERT INTO alerts VALUES(551,1772987808.139030934,'{"timestamp": "2026-03-08T17:36:48.139031+0100", "flow_id": 34187210940472, "event_type": "alert", "src_ip": "176.120.22.135", "src_port": 50979, "dest_ip": "185.254.126.122", "dest_port": 5405, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:36:48.139031+0100", "src_ip": "176.120.22.135", "dest_ip": "185.254.126.122", "src_port": 50979, "dest_port": 5405}}'); INSERT INTO alerts VALUES(552,1772987875.393194914,'{"timestamp": "2026-03-08T17:37:55.393195+0100", "flow_id": 1125810053581051, "event_type": "alert", "src_ip": "45.156.87.127", "src_port": 56511, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:37:55.393195+0100", "src_ip": "45.156.87.127", "dest_ip": "185.254.126.122", "src_port": 56511, "dest_port": 3306}}'); INSERT INTO alerts VALUES(553,1772987875.393194914,'{"timestamp": "2026-03-08T17:37:55.393195+0100", "flow_id": 1125810053581051, "event_type": "alert", "src_ip": "45.156.87.127", "src_port": 56511, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:37:55.393195+0100", "src_ip": "45.156.87.127", "dest_ip": "185.254.126.122", "src_port": 56511, "dest_port": 3306}}'); INSERT INTO alerts VALUES(554,1772987966.420342923,'{"timestamp": "2026-03-08T17:39:26.420343+0100", "flow_id": 1805363210431817, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 57202, "dest_ip": "185.254.126.122", "dest_port": 3431, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:39:26.420343+0100", "src_ip": "45.142.193.7", "dest_ip": "185.254.126.122", "src_port": 57202, "dest_port": 3431}}'); INSERT INTO alerts VALUES(555,1772988074.489778041,'{"timestamp": "2026-03-08T17:41:14.489778+0100", "flow_id": 696208800040104, "event_type": "alert", "src_ip": "64.89.161.182", "src_port": 38494, "dest_ip": "185.254.126.122", "dest_port": 63938, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T17:41:14.489778+0100", "src_ip": "64.89.161.182", "dest_ip": "185.254.126.122", "src_port": 38494, "dest_port": 63938}}'); INSERT INTO alerts VALUES(556,1772988151.078849077,'{"timestamp": "2026-03-08T17:42:31.078849+0100", "flow_id": 2027506143826378, "event_type": "alert", "src_ip": "147.185.132.144", "src_port": 51778, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:42:31.078849+0100", "src_ip": "147.185.132.144", "dest_ip": "185.254.126.122", "src_port": 51778, "dest_port": 3306}}'); INSERT INTO alerts VALUES(557,1772988151.078849077,'{"timestamp": "2026-03-08T17:42:31.078849+0100", "flow_id": 2027506143826378, "event_type": "alert", "src_ip": "147.185.132.144", "src_port": 51778, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:42:31.078849+0100", "src_ip": "147.185.132.144", "dest_ip": "185.254.126.122", "src_port": 51778, "dest_port": 3306}}'); INSERT INTO alerts VALUES(558,1772988206.581197024,'{"timestamp": "2026-03-08T17:43:26.581197+0100", "flow_id": 1933272332946708, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 43653, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:43:26.581197+0100", "src_ip": "79.124.62.134", "dest_ip": "185.254.126.122", "src_port": 43653, "dest_port": 3389}}'); INSERT INTO alerts VALUES(559,1772988372.851629019,'{"timestamp": "2026-03-08T17:46:12.851629+0100", "flow_id": 1405921388664115, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 34090, "dest_ip": "185.254.126.122", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:46:12.851629+0100", "src_ip": "130.12.180.174", "dest_ip": "185.254.126.122", "src_port": 34090, "dest_port": 23}}'); INSERT INTO alerts VALUES(560,1772988372.851629019,'{"timestamp": "2026-03-08T17:46:12.851629+0100", "flow_id": 1405921388664115, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 34090, "dest_ip": "185.254.126.122", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:46:12.851629+0100", "src_ip": "130.12.180.174", "dest_ip": "185.254.126.122", "src_port": 34090, "dest_port": 23}}'); INSERT INTO alerts VALUES(561,1772988431.939208984,'{"timestamp": "2026-03-08T17:47:11.939209+0100", "flow_id": 2063551309477785, "event_type": "alert", "src_ip": "185.242.3.196", "src_port": 55883, "dest_ip": "185.254.126.122", "dest_port": 4096, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:47:11.939209+0100", "src_ip": "185.242.3.196", "dest_ip": "185.254.126.122", "src_port": 55883, "dest_port": 4096}}'); INSERT INTO alerts VALUES(562,1772988491.464519977,'{"timestamp": "2026-03-08T17:48:11.464520+0100", "flow_id": 869198948798961, "event_type": "alert", "src_ip": "193.163.125.16", "src_port": 40199, "dest_ip": "185.254.126.122", "dest_port": 8019, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:48:11.464520+0100", "src_ip": "193.163.125.16", "dest_ip": "185.254.126.122", "src_port": 40199, "dest_port": 8019}}'); INSERT INTO alerts VALUES(563,1772988502.369503975,'{"timestamp": "2026-03-08T17:48:22.369504+0100", "flow_id": 1868482737008161, "event_type": "alert", "src_ip": "167.94.146.42", "src_port": 28143, "dest_ip": "185.254.126.122", "dest_port": 26935, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:48:22.369504+0100", "src_ip": "167.94.146.42", "dest_ip": "185.254.126.122", "src_port": 28143, "dest_port": 26935}}'); INSERT INTO alerts VALUES(564,1772988571.656270981,'{"timestamp": "2026-03-08T17:49:31.656271+0100", "flow_id": 848338912696795, "event_type": "alert", "src_ip": "167.94.146.74", "src_port": 21645, "dest_ip": "185.254.126.122", "dest_port": 40511, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:49:31.656271+0100", "src_ip": "167.94.146.74", "dest_ip": "185.254.126.122", "src_port": 21645, "dest_port": 40511}}'); INSERT INTO alerts VALUES(565,1772988585.328767061,'{"timestamp": "2026-03-08T17:49:45.328767+0100", "flow_id": 286146540968300, "event_type": "alert", "src_ip": "193.163.125.6", "src_port": 40451, "dest_ip": "185.254.126.122", "dest_port": 873, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:49:45.328767+0100", "src_ip": "193.163.125.6", "dest_ip": "185.254.126.122", "src_port": 40451, "dest_port": 873}}'); INSERT INTO alerts VALUES(566,1772988587.642457009,'{"timestamp": "2026-03-08T17:49:47.642457+0100", "flow_id": 1070482176849571, "event_type": "alert", "src_ip": "167.94.146.34", "src_port": 26885, "dest_ip": "185.254.126.122", "dest_port": 8558, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:49:47.642457+0100", "src_ip": "167.94.146.34", "dest_ip": "185.254.126.122", "src_port": 26885, "dest_port": 8558}}'); INSERT INTO alerts VALUES(567,1772988595.453537941,'{"timestamp": "2026-03-08T17:49:55.453538+0100", "flow_id": 1103510121394297, "event_type": "alert", "src_ip": "205.210.31.196", "src_port": 54086, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:49:55.453538+0100", "src_ip": "205.210.31.196", "dest_ip": "185.254.126.122", "src_port": 54086, "dest_port": 3389}}'); INSERT INTO alerts VALUES(568,1772988627.957986116,'{"timestamp": "2026-03-08T17:50:27.957986+0100", "flow_id": 1018297424414785, "event_type": "alert", "src_ip": "204.76.203.17", "src_port": 47534, "dest_ip": "185.254.126.122", "dest_port": 19133, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 61, "bytes_toclient": 0, "start": "2026-03-08T17:50:27.957986+0100", "src_ip": "204.76.203.17", "dest_ip": "185.254.126.122", "src_port": 47534, "dest_port": 19133}}'); INSERT INTO alerts VALUES(569,1772988627.957986116,'{"timestamp": "2026-03-08T17:50:27.957986+0100", "flow_id": 1018297424414785, "event_type": "alert", "src_ip": "204.76.203.17", "src_port": 47534, "dest_ip": "185.254.126.122", "dest_port": 19133, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 61, "bytes_toclient": 0, "start": "2026-03-08T17:50:27.957986+0100", "src_ip": "204.76.203.17", "dest_ip": "185.254.126.122", "src_port": 47534, "dest_port": 19133}}'); INSERT INTO alerts VALUES(570,1772988676.434536934,'{"timestamp": "2026-03-08T17:51:16.434537+0100", "flow_id": 1303376461237583, "event_type": "alert", "src_ip": "205.210.31.102", "src_port": 50583, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:51:16.434537+0100", "src_ip": "205.210.31.102", "dest_ip": "185.254.126.122", "src_port": 50583, "dest_port": 22}}'); INSERT INTO alerts VALUES(571,1772988684.095103025,'{"timestamp": "2026-03-08T17:51:24.095103+0100", "flow_id": 1252892792042001, "event_type": "alert", "src_ip": "193.163.125.10", "src_port": 51549, "dest_ip": "185.254.126.122", "dest_port": 11102, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:51:24.095103+0100", "src_ip": "193.163.125.10", "dest_ip": "185.254.126.122", "src_port": 51549, "dest_port": 11102}}'); INSERT INTO alerts VALUES(572,1772988771.546667098,'{"timestamp": "2026-03-08T17:52:51.546667+0100", "flow_id": 940544678170436, "event_type": "alert", "src_ip": "193.32.162.196", "src_port": 42354, "dest_ip": "185.254.126.122", "dest_port": 25, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T17:52:51.546667+0100", "src_ip": "193.32.162.196", "dest_ip": "185.254.126.122", "src_port": 42354, "dest_port": 25}}'); INSERT INTO alerts VALUES(573,1772988843.922080039,'{"timestamp": "2026-03-08T17:54:03.922080+0100", "flow_id": 864081400988469, "event_type": "alert", "src_ip": "167.94.138.155", "src_port": 11449, "dest_ip": "185.254.126.122", "dest_port": 1604, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-08T17:54:03.922080+0100", "src_ip": "167.94.138.155", "dest_ip": "185.254.126.122", "src_port": 11449, "dest_port": 1604}}'); INSERT INTO alerts VALUES(574,1772988883.654165029,'{"timestamp": "2026-03-08T17:54:43.654165+0100", "flow_id": 1120769085111801, "event_type": "alert", "src_ip": "167.94.146.75", "src_port": 1645, "dest_ip": "185.254.126.122", "dest_port": 56813, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:54:43.654165+0100", "src_ip": "167.94.146.75", "dest_ip": "185.254.126.122", "src_port": 1645, "dest_port": 56813}}'); INSERT INTO alerts VALUES(575,1772988977.131236077,'{"timestamp": "2026-03-08T17:56:17.131236+0100", "flow_id": 282181606566428, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 44991, "dest_ip": "185.254.126.122", "dest_port": 48526, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:56:17.131236+0100", "src_ip": "167.94.146.45", "dest_ip": "185.254.126.122", "src_port": 44991, "dest_port": 48526}}'); INSERT INTO alerts VALUES(576,1772988983.968255043,'{"timestamp": "2026-03-08T17:56:23.968255+0100", "flow_id": 2188298944658028, "event_type": "alert", "src_ip": "205.210.31.201", "src_port": 50682, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:56:23.968255+0100", "src_ip": "205.210.31.201", "dest_ip": "185.254.126.122", "src_port": 50682, "dest_port": 1433}}'); INSERT INTO alerts VALUES(577,1772988983.968255043,'{"timestamp": "2026-03-08T17:56:23.968255+0100", "flow_id": 2188298944658028, "event_type": "alert", "src_ip": "205.210.31.201", "src_port": 50682, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:56:23.968255+0100", "src_ip": "205.210.31.201", "dest_ip": "185.254.126.122", "src_port": 50682, "dest_port": 1433}}'); INSERT INTO alerts VALUES(578,1772988991.803847075,'{"timestamp": "2026-03-08T17:56:31.803847+0100", "flow_id": 2045124383443051, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 18986, "dest_ip": "185.254.126.122", "dest_port": 32265, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:56:31.803847+0100", "src_ip": "167.94.146.37", "dest_ip": "185.254.126.122", "src_port": 18986, "dest_port": 32265}}'); INSERT INTO alerts VALUES(579,1772989016.04788208,'{"timestamp": "2026-03-08T17:56:56.047882+0100", "flow_id": 205652349794823, "event_type": "alert", "src_ip": "193.163.125.18", "src_port": 44478, "dest_ip": "185.254.126.122", "dest_port": 161, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T17:56:56.047882+0100", "src_ip": "193.163.125.18", "dest_ip": "185.254.126.122", "src_port": 44478, "dest_port": 161}}'); INSERT INTO alerts VALUES(580,1772989101.350774049,'{"timestamp": "2026-03-08T17:58:21.350774+0100", "flow_id": 1506563633969297, "event_type": "alert", "src_ip": "167.94.138.151", "src_port": 7678, "dest_ip": "185.254.126.122", "dest_port": 5984, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:58:21.350774+0100", "src_ip": "167.94.138.151", "dest_ip": "185.254.126.122", "src_port": 7678, "dest_port": 5984}}'); INSERT INTO alerts VALUES(581,1772989136.980010032,'{"timestamp": "2026-03-08T17:58:56.980010+0100", "flow_id": 268462644535775, "event_type": "alert", "src_ip": "167.94.138.132", "src_port": 51667, "dest_ip": "185.254.126.122", "dest_port": 61616, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:58:56.980010+0100", "src_ip": "167.94.138.132", "dest_ip": "185.254.126.122", "src_port": 51667, "dest_port": 61616}}'); INSERT INTO alerts VALUES(582,1772989155.397876024,'{"timestamp": "2026-03-08T17:59:15.397876+0100", "flow_id": 864441343097470, "event_type": "alert", "src_ip": "167.94.146.33", "src_port": 19261, "dest_ip": "185.254.126.122", "dest_port": 38230, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T17:59:15.397876+0100", "src_ip": "167.94.146.33", "dest_ip": "185.254.126.122", "src_port": 19261, "dest_port": 38230}}'); INSERT INTO alerts VALUES(583,1772989285.164907933,'{"timestamp": "2026-03-08T18:01:25.164908+0100", "flow_id": 1552700395247823, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 2082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:01:25.164908+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 2082}}'); INSERT INTO alerts VALUES(584,1772989285.164907933,'{"timestamp": "2026-03-08T18:01:25.164908+0100", "flow_id": 1552700395247823, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 2082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:01:25.164908+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 2082}}'); INSERT INTO alerts VALUES(585,1772989546.363516093,'{"timestamp": "2026-03-08T18:05:46.363516+0100", "flow_id": 716866880513402, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 4432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:05:46.363516+0100", "src_ip": "88.210.63.69", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 4432}}'); INSERT INTO alerts VALUES(586,1772989670.375839949,'{"timestamp": "2026-03-08T18:07:50.375840+0100", "flow_id": 1895696493921892, "event_type": "alert", "src_ip": "193.163.125.31", "src_port": 43741, "dest_ip": "185.254.126.122", "dest_port": 1040, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:07:50.375840+0100", "src_ip": "193.163.125.31", "dest_ip": "185.254.126.122", "src_port": 43741, "dest_port": 1040}}'); INSERT INTO alerts VALUES(587,1772989772.169823885,'{"timestamp": "2026-03-08T18:09:32.169824+0100", "flow_id": 1292339053044915, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 14355, "dest_ip": "185.254.126.122", "dest_port": 44979, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T18:09:32.169824+0100", "src_ip": "167.94.146.32", "dest_ip": "185.254.126.122", "src_port": 14355, "dest_port": 44979}}'); INSERT INTO alerts VALUES(588,1772989858.058634042,'{"timestamp": "2026-03-08T18:10:58.058634+0100", "flow_id": 814781961384633, "event_type": "alert", "src_ip": "87.121.84.67", "src_port": 56579, "dest_ip": "185.254.126.122", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:10:58.058634+0100", "src_ip": "87.121.84.67", "dest_ip": "185.254.126.122", "src_port": 56579, "dest_port": 5900}}'); INSERT INTO alerts VALUES(589,1772990360.712070941,'{"timestamp": "2026-03-08T18:19:20.712071+0100", "flow_id": 243572377181667, "event_type": "alert", "src_ip": "193.163.125.15", "src_port": 51796, "dest_ip": "185.254.126.122", "dest_port": 5375, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:19:20.712071+0100", "src_ip": "193.163.125.15", "dest_ip": "185.254.126.122", "src_port": 51796, "dest_port": 5375}}'); INSERT INTO alerts VALUES(590,1772990370.327887059,'{"timestamp": "2026-03-08T18:19:30.327887+0100", "flow_id": 563843169949282, "event_type": "alert", "src_ip": "167.94.146.47", "src_port": 34615, "dest_ip": "185.254.126.122", "dest_port": 64727, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T18:19:30.327887+0100", "src_ip": "167.94.146.47", "dest_ip": "185.254.126.122", "src_port": 34615, "dest_port": 64727}}'); INSERT INTO alerts VALUES(591,1772990399.321908951,'{"timestamp": "2026-03-08T18:19:59.321909+0100", "flow_id": 2227017267385765, "event_type": "alert", "src_ip": "91.224.92.177", "src_port": 60386, "dest_ip": "185.254.126.122", "dest_port": 4001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:19:59.321909+0100", "src_ip": "91.224.92.177", "dest_ip": "185.254.126.122", "src_port": 60386, "dest_port": 4001}}'); INSERT INTO alerts VALUES(592,1772990432.730726957,'{"timestamp": "2026-03-08T18:20:32.730727+0100", "flow_id": 42224681933447, "event_type": "alert", "src_ip": "77.83.39.250", "src_port": 49640, "dest_ip": "185.254.126.122", "dest_port": 2525, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400008, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 9", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:20:32.730727+0100", "src_ip": "77.83.39.250", "dest_ip": "185.254.126.122", "src_port": 49640, "dest_port": 2525}}'); INSERT INTO alerts VALUES(593,1772990456.85668397,'{"timestamp": "2026-03-08T18:20:56.856684+0100", "flow_id": 20256469289408, "event_type": "alert", "src_ip": "45.135.194.48", "src_port": 51565, "dest_ip": "185.254.126.122", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T18:20:56.856684+0100", "src_ip": "45.135.194.48", "dest_ip": "185.254.126.122", "src_port": 51565, "dest_port": 5555}}'); INSERT INTO alerts VALUES(594,1772990476.761640072,'{"timestamp": "2026-03-08T18:21:16.761640+0100", "flow_id": 1300897097848641, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 40097, "dest_ip": "185.254.126.122", "dest_port": 7854, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:21:16.761640+0100", "src_ip": "79.124.40.82", "dest_ip": "185.254.126.122", "src_port": 40097, "dest_port": 7854}}'); INSERT INTO alerts VALUES(595,1772990670.881150007,'{"timestamp": "2026-03-08T18:24:30.881150+0100", "flow_id": 1814188564892950, "event_type": "alert", "src_ip": "34.228.104.231", "src_port": 53747, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T18:24:30.881150+0100", "src_ip": "34.228.104.231", "dest_ip": "185.254.126.122", "src_port": 53747, "dest_port": 1433}}'); INSERT INTO alerts VALUES(596,1772990712.032851935,'{"timestamp": "2026-03-08T18:25:12.032852+0100", "flow_id": 141099229495170, "event_type": "alert", "src_ip": "34.47.37.0", "src_port": 45432, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:25:12.032852+0100", "src_ip": "34.47.37.0", "dest_ip": "185.254.126.122", "src_port": 45432, "dest_port": 3306}}'); INSERT INTO alerts VALUES(597,1772990753.054701089,'{"timestamp": "2026-03-08T18:25:53.054701+0100", "flow_id": 516415018991036, "event_type": "alert", "src_ip": "88.210.63.192", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 333, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:25:53.054701+0100", "src_ip": "88.210.63.192", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 333}}'); INSERT INTO alerts VALUES(598,1772990812.520292998,'{"timestamp": "2026-03-08T18:26:52.520293+0100", "flow_id": 1390217075319517, "event_type": "alert", "src_ip": "185.242.226.97", "src_port": 33568, "dest_ip": "185.254.126.122", "dest_port": 40956, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-08T18:26:52.520293+0100", "src_ip": "185.242.226.97", "dest_ip": "185.254.126.122", "src_port": 33568, "dest_port": 40956}}'); INSERT INTO alerts VALUES(599,1772990826.128971099,'{"timestamp": "2026-03-08T18:27:06.128971+0100", "flow_id": 835401711401709, "event_type": "alert", "src_ip": "64.89.163.241", "src_port": 44342, "dest_ip": "185.254.126.122", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:27:06.128971+0100", "src_ip": "64.89.163.241", "dest_ip": "185.254.126.122", "src_port": 44342, "dest_port": 3000}}'); INSERT INTO alerts VALUES(600,1772990866.606152057,'{"timestamp": "2026-03-08T18:27:46.606152+0100", "flow_id": 633079924757403, "event_type": "alert", "src_ip": "45.142.154.87", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 3112, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:27:46.606152+0100", "src_ip": "45.142.154.87", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 3112}}'); INSERT INTO alerts VALUES(601,1772990905.015603065,'{"timestamp": "2026-03-08T18:28:25.015603+0100", "flow_id": 348491736364982, "event_type": "alert", "src_ip": "45.142.154.98", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 110, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:28:25.015603+0100", "src_ip": "45.142.154.98", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 110}}'); INSERT INTO alerts VALUES(602,1772990987.424913884,'{"timestamp": "2026-03-08T18:29:47.424914+0100", "flow_id": 980569264352404, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "185.254.126.122", "dest_port": 14317, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:29:47.424914+0100", "src_ip": "79.124.40.110", "dest_ip": "185.254.126.122", "src_port": 52537, "dest_port": 14317}}'); INSERT INTO alerts VALUES(603,1772990997.676218986,'{"timestamp": "2026-03-08T18:29:57.676219+0100", "flow_id": 1496965450195981, "event_type": "alert", "src_ip": "185.217.188.132", "src_port": 43474, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:29:57.676219+0100", "src_ip": "185.217.188.132", "dest_ip": "185.254.126.122", "src_port": 43474, "dest_port": 1433}}'); INSERT INTO alerts VALUES(604,1772991041.674079896,'{"timestamp": "2026-03-08T18:30:41.674080+0100", "flow_id": 361879129694706, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 48937, "dest_ip": "185.254.126.122", "dest_port": 55475, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:30:41.674080+0100", "src_ip": "79.124.62.126", "dest_ip": "185.254.126.122", "src_port": 48937, "dest_port": 55475}}'); INSERT INTO alerts VALUES(605,1772991222.345890046,'{"timestamp": "2026-03-08T18:33:42.345890+0100", "flow_id": 1767063836246742, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 48193, "dest_ip": "185.254.126.122", "dest_port": 61809, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:33:42.345890+0100", "src_ip": "79.124.62.230", "dest_ip": "185.254.126.122", "src_port": 48193, "dest_port": 61809}}'); INSERT INTO alerts VALUES(606,1772991260.052238941,'{"timestamp": "2026-03-08T18:34:20.052239+0100", "flow_id": 1350268476347024, "event_type": "alert", "src_ip": "193.163.125.68", "src_port": 22477, "dest_ip": "185.254.126.122", "dest_port": 3283, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 33, "bytes_toclient": 0, "start": "2026-03-08T18:34:20.052239+0100", "src_ip": "193.163.125.68", "dest_ip": "185.254.126.122", "src_port": 22477, "dest_port": 3283}}'); INSERT INTO alerts VALUES(607,1772991302.818145991,'{"timestamp": "2026-03-08T18:35:02.818146+0100", "flow_id": 1825062651041052, "event_type": "alert", "src_ip": "198.235.24.200", "src_port": 53730, "dest_ip": "185.254.126.122", "dest_port": 21, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:35:02.818146+0100", "src_ip": "198.235.24.200", "dest_ip": "185.254.126.122", "src_port": 53730, "dest_port": 21}}'); INSERT INTO alerts VALUES(608,1772991361.959403038,'{"timestamp": "2026-03-08T18:36:01.959403+0100", "flow_id": 461432146546057, "event_type": "alert", "src_ip": "64.89.163.130", "src_port": 51258, "dest_ip": "185.254.126.122", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:36:01.959403+0100", "src_ip": "64.89.163.130", "dest_ip": "185.254.126.122", "src_port": 51258, "dest_port": 27017}}'); INSERT INTO alerts VALUES(609,1772991365.877649069,'{"timestamp": "2026-03-08T18:36:05.877649+0100", "flow_id": 1517675751971992, "event_type": "alert", "src_ip": "178.20.210.136", "src_port": 49261, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:36:05.877649+0100", "src_ip": "178.20.210.136", "dest_ip": "185.254.126.122", "src_port": 49261, "dest_port": 3389}}'); INSERT INTO alerts VALUES(610,1772991413.312537908,'{"timestamp": "2026-03-08T18:36:53.312538+0100", "flow_id": 1623816137484769, "event_type": "alert", "src_ip": "198.235.24.251", "src_port": 55410, "dest_ip": "185.254.126.122", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:36:53.312538+0100", "src_ip": "198.235.24.251", "dest_ip": "185.254.126.122", "src_port": 55410, "dest_port": 5900}}'); INSERT INTO alerts VALUES(611,1772991572.391997099,'{"timestamp": "2026-03-08T18:39:32.391997+0100", "flow_id": 1402140493948477, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 57202, "dest_ip": "185.254.126.122", "dest_port": 3444, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:39:32.391997+0100", "src_ip": "45.142.193.7", "dest_ip": "185.254.126.122", "src_port": 57202, "dest_port": 3444}}'); INSERT INTO alerts VALUES(612,1772991605.185529947,'{"timestamp": "2026-03-08T18:40:05.185530+0100", "flow_id": 1641273369683391, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 38590, "dest_ip": "185.254.126.122", "dest_port": 8082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:40:05.185530+0100", "src_ip": "87.121.84.57", "dest_ip": "185.254.126.122", "src_port": 38590, "dest_port": 8082}}'); INSERT INTO alerts VALUES(613,1772991607.724984884,'{"timestamp": "2026-03-08T18:40:07.724985+0100", "flow_id": 1987888940711922, "event_type": "alert", "src_ip": "46.151.182.188", "src_port": 51377, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:40:07.724985+0100", "src_ip": "46.151.182.188", "dest_ip": "185.254.126.122", "src_port": 51377, "dest_port": 5432}}'); INSERT INTO alerts VALUES(614,1772991607.724984884,'{"timestamp": "2026-03-08T18:40:07.724985+0100", "flow_id": 1987888940711922, "event_type": "alert", "src_ip": "46.151.182.188", "src_port": 51377, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:40:07.724985+0100", "src_ip": "46.151.182.188", "dest_ip": "185.254.126.122", "src_port": 51377, "dest_port": 5432}}'); INSERT INTO alerts VALUES(615,1772991667.577028037,'{"timestamp": "2026-03-08T18:41:07.577028+0100", "flow_id": 1070945433053036, "event_type": "alert", "src_ip": "193.163.125.26", "src_port": 42793, "dest_ip": "185.254.126.122", "dest_port": 502, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:41:07.577028+0100", "src_ip": "193.163.125.26", "dest_ip": "185.254.126.122", "src_port": 42793, "dest_port": 502}}'); INSERT INTO alerts VALUES(616,1772991749.427248002,'{"timestamp": "2026-03-08T18:42:29.427248+0100", "flow_id": 1553542630394285, "event_type": "alert", "src_ip": "176.65.148.96", "src_port": 40700, "dest_ip": "185.254.126.122", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T18:42:29.427248+0100", "src_ip": "176.65.148.96", "dest_ip": "185.254.126.122", "src_port": 40700, "dest_port": 8332}}'); INSERT INTO alerts VALUES(617,1772991749.427248002,'{"timestamp": "2026-03-08T18:42:29.427248+0100", "flow_id": 1553542630394285, "event_type": "alert", "src_ip": "176.65.148.96", "src_port": 40700, "dest_ip": "185.254.126.122", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T18:42:29.427248+0100", "src_ip": "176.65.148.96", "dest_ip": "185.254.126.122", "src_port": 40700, "dest_port": 8332}}'); INSERT INTO alerts VALUES(618,1772991753.04221201,'{"timestamp": "2026-03-08T18:42:33.042212+0100", "flow_id": 462775993636846, "event_type": "alert", "src_ip": "43.228.157.10", "src_port": 46981, "dest_ip": "185.254.126.122", "dest_port": 12362, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:42:33.042212+0100", "src_ip": "43.228.157.10", "dest_ip": "185.254.126.122", "src_port": 46981, "dest_port": 12362}}'); INSERT INTO alerts VALUES(619,1772991813.737875939,'{"timestamp": "2026-03-08T18:43:33.737876+0100", "flow_id": 1480304181537930, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59739, "dest_ip": "185.254.126.122", "dest_port": 62442, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:43:33.737876+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59739, "dest_port": 62442}}'); INSERT INTO alerts VALUES(620,1772991813.737875939,'{"timestamp": "2026-03-08T18:43:33.737876+0100", "flow_id": 1480304181537930, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59739, "dest_ip": "185.254.126.122", "dest_port": 62442, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:43:33.737876+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59739, "dest_port": 62442}}'); INSERT INTO alerts VALUES(621,1772991831.683962107,'{"timestamp": "2026-03-08T18:43:51.683962+0100", "flow_id": 2093170899216941, "event_type": "alert", "src_ip": "176.65.134.3", "src_port": 51597, "dest_ip": "185.254.126.122", "dest_port": 4153, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:43:51.683962+0100", "src_ip": "176.65.134.3", "dest_ip": "185.254.126.122", "src_port": 51597, "dest_port": 4153}}'); INSERT INTO alerts VALUES(622,1772991877.563297987,'{"timestamp": "2026-03-08T18:44:37.563298+0100", "flow_id": 1574922774227641, "event_type": "alert", "src_ip": "193.163.125.13", "src_port": 39282, "dest_ip": "185.254.126.122", "dest_port": 1023, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:44:37.563298+0100", "src_ip": "193.163.125.13", "dest_ip": "185.254.126.122", "src_port": 39282, "dest_port": 1023}}'); INSERT INTO alerts VALUES(623,1772991994.662230969,'{"timestamp": "2026-03-08T18:46:34.662231+0100", "flow_id": 592461341962835, "event_type": "alert", "src_ip": "167.94.138.149", "src_port": 9278, "dest_ip": "185.254.126.122", "dest_port": 22922, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T18:46:34.662231+0100", "src_ip": "167.94.138.149", "dest_ip": "185.254.126.122", "src_port": 9278, "dest_port": 22922}}'); INSERT INTO alerts VALUES(624,1772992157.6157341,'{"timestamp": "2026-03-08T18:49:17.615734+0100", "flow_id": 1518658058680205, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 40501, "dest_ip": "185.254.126.122", "dest_port": 2375, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:49:17.615734+0100", "src_ip": "193.142.146.230", "dest_ip": "185.254.126.122", "src_port": 40501, "dest_port": 2375}}'); INSERT INTO alerts VALUES(625,1772992196.759884119,'{"timestamp": "2026-03-08T18:49:56.759884+0100", "flow_id": 1293352572890251, "event_type": "alert", "src_ip": "87.121.84.50", "src_port": 42885, "dest_ip": "185.254.126.122", "dest_port": 8820, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:49:56.759884+0100", "src_ip": "87.121.84.50", "dest_ip": "185.254.126.122", "src_port": 42885, "dest_port": 8820}}'); INSERT INTO alerts VALUES(626,1772992262.742244006,'{"timestamp": "2026-03-08T18:51:02.742244+0100", "flow_id": 1780542358765425, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 48935, "dest_ip": "185.254.126.122", "dest_port": 62815, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:51:02.742244+0100", "src_ip": "79.124.62.134", "dest_ip": "185.254.126.122", "src_port": 48935, "dest_port": 62815}}'); INSERT INTO alerts VALUES(627,1772992440.205645084,'{"timestamp": "2026-03-08T18:54:00.205645+0100", "flow_id": 38816982420982, "event_type": "alert", "src_ip": "64.89.163.79", "src_port": 52391, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:54:00.205645+0100", "src_ip": "64.89.163.79", "dest_ip": "185.254.126.122", "src_port": 52391, "dest_port": 3306}}'); INSERT INTO alerts VALUES(628,1772992440.205645084,'{"timestamp": "2026-03-08T18:54:00.205645+0100", "flow_id": 38816982420982, "event_type": "alert", "src_ip": "64.89.163.79", "src_port": 52391, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:54:00.205645+0100", "src_ip": "64.89.163.79", "dest_ip": "185.254.126.122", "src_port": 52391, "dest_port": 3306}}'); INSERT INTO alerts VALUES(629,1772992477.990905047,'{"timestamp": "2026-03-08T18:54:37.990905+0100", "flow_id": 1441158333787227, "event_type": "alert", "src_ip": "79.124.62.178", "src_port": 56406, "dest_ip": "185.254.126.122", "dest_port": 53389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:54:37.990905+0100", "src_ip": "79.124.62.178", "dest_ip": "185.254.126.122", "src_port": 56406, "dest_port": 53389}}'); INSERT INTO alerts VALUES(630,1772992557.609440088,'{"timestamp": "2026-03-08T18:55:57.609440+0100", "flow_id": 1491626047292700, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "185.254.126.122", "dest_port": 22762, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:55:57.609440+0100", "src_ip": "130.12.180.88", "dest_ip": "185.254.126.122", "src_port": 52302, "dest_port": 22762}}'); INSERT INTO alerts VALUES(631,1772992557.609440088,'{"timestamp": "2026-03-08T18:55:57.609440+0100", "flow_id": 1491626047292700, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "185.254.126.122", "dest_port": 22762, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:55:57.609440+0100", "src_ip": "130.12.180.88", "dest_ip": "185.254.126.122", "src_port": 52302, "dest_port": 22762}}'); INSERT INTO alerts VALUES(632,1772992574.254558087,'{"timestamp": "2026-03-08T18:56:14.254558+0100", "flow_id": 1937745374812845, "event_type": "alert", "src_ip": "167.94.138.156", "src_port": 53577, "dest_ip": "185.254.126.122", "dest_port": 18789, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T18:56:14.254558+0100", "src_ip": "167.94.138.156", "dest_ip": "185.254.126.122", "src_port": 53577, "dest_port": 18789}}'); INSERT INTO alerts VALUES(633,1772992655.528456927,'{"timestamp": "2026-03-08T18:57:35.528457+0100", "flow_id": 1988233414251818, "event_type": "alert", "src_ip": "176.65.148.197", "src_port": 45968, "dest_ip": "185.254.126.122", "dest_port": 5005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:57:35.528457+0100", "src_ip": "176.65.148.197", "dest_ip": "185.254.126.122", "src_port": 45968, "dest_port": 5005}}'); INSERT INTO alerts VALUES(634,1772992655.528456927,'{"timestamp": "2026-03-08T18:57:35.528457+0100", "flow_id": 1988233414251818, "event_type": "alert", "src_ip": "176.65.148.197", "src_port": 45968, "dest_ip": "185.254.126.122", "dest_port": 5005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:57:35.528457+0100", "src_ip": "176.65.148.197", "dest_ip": "185.254.126.122", "src_port": 45968, "dest_port": 5005}}'); INSERT INTO alerts VALUES(635,1772992656.080064058,'{"timestamp": "2026-03-08T18:57:36.080064+0100", "flow_id": 62400079135592, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 46876, "dest_ip": "185.254.126.122", "dest_port": 31522, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T18:57:36.080064+0100", "src_ip": "167.94.146.37", "dest_ip": "185.254.126.122", "src_port": 46876, "dest_port": 31522}}'); INSERT INTO alerts VALUES(636,1772992674.612891912,'{"timestamp": "2026-03-08T18:57:54.612892+0100", "flow_id": 662027457684331, "event_type": "alert", "src_ip": "185.156.73.182", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 44431, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:57:54.612892+0100", "src_ip": "185.156.73.182", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 44431}}'); INSERT INTO alerts VALUES(637,1772992715.219897032,'{"timestamp": "2026-03-08T18:58:35.219897+0100", "flow_id": 944451638835348, "event_type": "alert", "src_ip": "162.217.98.180", "src_port": 40014, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 414, "bytes_toclient": 0, "start": "2026-03-08T18:58:35.219897+0100", "src_ip": "162.217.98.180", "dest_ip": "185.254.126.122", "src_port": 40014, "dest_port": 5060}}'); INSERT INTO alerts VALUES(638,1772992732.199340105,'{"timestamp": "2026-03-08T18:58:52.199340+0100", "flow_id": 1137635715162371, "event_type": "alert", "src_ip": "178.20.210.151", "src_port": 50083, "dest_ip": "185.254.126.122", "dest_port": 2181, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T18:58:52.199340+0100", "src_ip": "178.20.210.151", "dest_ip": "185.254.126.122", "src_port": 50083, "dest_port": 2181}}'); INSERT INTO alerts VALUES(639,1772992779.51056099,'{"timestamp": "2026-03-08T18:59:39.510561+0100", "flow_id": 1066946325194420, "event_type": "alert", "src_ip": "176.65.139.45", "src_port": 37643, "dest_ip": "185.254.126.122", "dest_port": 17001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T18:59:39.510561+0100", "src_ip": "176.65.139.45", "dest_ip": "185.254.126.122", "src_port": 37643, "dest_port": 17001}}'); INSERT INTO alerts VALUES(640,1772992815.817234992,'{"timestamp": "2026-03-08T19:00:15.817235+0100", "flow_id": 2102624494857220, "event_type": "alert", "src_ip": "66.132.153.155", "src_port": 10071, "dest_ip": "185.254.126.122", "dest_port": 20000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:00:15.817235+0100", "src_ip": "66.132.153.155", "dest_ip": "185.254.126.122", "src_port": 10071, "dest_port": 20000}}'); INSERT INTO alerts VALUES(641,1772992840.495302915,'{"timestamp": "2026-03-08T19:00:40.495303+0100", "flow_id": 156988831241324, "event_type": "alert", "src_ip": "192.109.200.157", "src_port": 58001, "dest_ip": "185.254.126.122", "dest_port": 34567, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400037, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 38", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:00:40.495303+0100", "src_ip": "192.109.200.157", "dest_ip": "185.254.126.122", "src_port": 58001, "dest_port": 34567}}'); INSERT INTO alerts VALUES(642,1772992841.303529024,'{"timestamp": "2026-03-08T19:00:41.303529+0100", "flow_id": 459225113155168, "event_type": "alert", "src_ip": "45.142.154.99", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 20202, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:00:41.303529+0100", "src_ip": "45.142.154.99", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 20202}}'); INSERT INTO alerts VALUES(643,1772992854.93322897,'{"timestamp": "2026-03-08T19:00:54.933229+0100", "flow_id": 1756389143121918, "event_type": "alert", "src_ip": "176.65.148.243", "src_port": 47397, "dest_ip": "185.254.126.122", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:00:54.933229+0100", "src_ip": "176.65.148.243", "dest_ip": "185.254.126.122", "src_port": 47397, "dest_port": 25565}}'); INSERT INTO alerts VALUES(644,1772992854.93322897,'{"timestamp": "2026-03-08T19:00:54.933229+0100", "flow_id": 1756389143121918, "event_type": "alert", "src_ip": "176.65.148.243", "src_port": 47397, "dest_ip": "185.254.126.122", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:00:54.933229+0100", "src_ip": "176.65.148.243", "dest_ip": "185.254.126.122", "src_port": 47397, "dest_port": 25565}}'); INSERT INTO alerts VALUES(645,1772992984.180638074,'{"timestamp": "2026-03-08T19:03:04.180638+0100", "flow_id": 212885881650058, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 51176, "dest_ip": "185.254.126.122", "dest_port": 18765, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:03:04.180638+0100", "src_ip": "185.242.246.37", "dest_ip": "185.254.126.122", "src_port": 51176, "dest_port": 18765}}'); INSERT INTO alerts VALUES(646,1772992984.180638074,'{"timestamp": "2026-03-08T19:03:04.180638+0100", "flow_id": 212885881650058, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 51176, "dest_ip": "185.254.126.122", "dest_port": 18765, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:03:04.180638+0100", "src_ip": "185.242.246.37", "dest_ip": "185.254.126.122", "src_port": 51176, "dest_port": 18765}}'); INSERT INTO alerts VALUES(647,1772993001.959125041,'{"timestamp": "2026-03-08T19:03:21.959125+0100", "flow_id": 464528879654812, "event_type": "alert", "src_ip": "34.77.87.222", "src_port": 45737, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2001219, "rev": 20, "signature": "ET SCAN Potential SSH Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 88, "bytes_toclient": 0, "start": "2026-03-08T19:03:21.108156+0100", "src_ip": "34.77.87.222", "dest_ip": "185.254.126.122", "src_port": 45737, "dest_port": 22}}'); INSERT INTO alerts VALUES(648,1772993010.253139972,'{"timestamp": "2026-03-08T19:03:30.253140+0100", "flow_id": 805753532462123, "event_type": "alert", "src_ip": "167.94.138.97", "src_port": 31927, "dest_ip": "185.254.126.122", "dest_port": 64235, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:03:30.253140+0100", "src_ip": "167.94.138.97", "dest_ip": "185.254.126.122", "src_port": 31927, "dest_port": 64235}}'); INSERT INTO alerts VALUES(649,1772993015.734673023,'{"timestamp": "2026-03-08T19:03:35.734673+0100", "flow_id": 2029499643965952, "event_type": "alert", "src_ip": "187.107.8.55", "src_port": 48338, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:03:35.734673+0100", "src_ip": "187.107.8.55", "dest_ip": "185.254.126.122", "src_port": 48338, "dest_port": 1433}}'); INSERT INTO alerts VALUES(650,1772993033.478796006,'{"timestamp": "2026-03-08T19:03:53.478796+0100", "flow_id": 367564616512110, "event_type": "alert", "src_ip": "176.65.149.180", "src_port": 54863, "dest_ip": "185.254.126.122", "dest_port": 8265, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:03:53.478796+0100", "src_ip": "176.65.149.180", "dest_ip": "185.254.126.122", "src_port": 54863, "dest_port": 8265}}'); INSERT INTO alerts VALUES(651,1772993037.017303944,'{"timestamp": "2026-03-08T19:03:57.017304+0100", "flow_id": 1481698694925740, "event_type": "alert", "src_ip": "172.94.9.253", "src_port": 58397, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400031, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 32", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:03:57.017304+0100", "src_ip": "172.94.9.253", "dest_ip": "185.254.126.122", "src_port": 58397, "dest_port": 443}}'); INSERT INTO alerts VALUES(652,1772993071.012602091,'{"timestamp": "2026-03-08T19:04:31.012602+0100", "flow_id": 2024451157657611, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 52541, "dest_ip": "185.254.126.122", "dest_port": 3310, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:04:31.012602+0100", "src_ip": "185.242.246.38", "dest_ip": "185.254.126.122", "src_port": 52541, "dest_port": 3310}}'); INSERT INTO alerts VALUES(653,1772993071.012602091,'{"timestamp": "2026-03-08T19:04:31.012602+0100", "flow_id": 2024451157657611, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 52541, "dest_ip": "185.254.126.122", "dest_port": 3310, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:04:31.012602+0100", "src_ip": "185.242.246.38", "dest_ip": "185.254.126.122", "src_port": 52541, "dest_port": 3310}}'); INSERT INTO alerts VALUES(654,1772993177.567368984,'{"timestamp": "2026-03-08T19:06:17.567369+0100", "flow_id": 466508560984802, "event_type": "alert", "src_ip": "167.94.138.129", "src_port": 35423, "dest_ip": "185.254.126.122", "dest_port": 7443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:06:17.567369+0100", "src_ip": "167.94.138.129", "dest_ip": "185.254.126.122", "src_port": 35423, "dest_port": 7443}}'); INSERT INTO alerts VALUES(655,1772993192.259644031,'{"timestamp": "2026-03-08T19:06:32.259644+0100", "flow_id": 270740375727484, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 44332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:06:32.259644+0100", "src_ip": "88.210.63.69", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 44332}}'); INSERT INTO alerts VALUES(656,1772993251.555756092,'{"timestamp": "2026-03-08T19:07:31.555756+0100", "flow_id": 979579725536547, "event_type": "alert", "src_ip": "185.242.226.103", "src_port": 58331, "dest_ip": "185.254.126.122", "dest_port": 5950, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:07:31.555756+0100", "src_ip": "185.242.226.103", "dest_ip": "185.254.126.122", "src_port": 58331, "dest_port": 5950}}'); INSERT INTO alerts VALUES(657,1772993251.802834987,'{"timestamp": "2026-03-08T19:07:31.802835+0100", "flow_id": 914878777351784, "event_type": "alert", "src_ip": "167.94.138.142", "src_port": 6349, "dest_ip": "185.254.126.122", "dest_port": 8880, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:07:31.802835+0100", "src_ip": "167.94.138.142", "dest_ip": "185.254.126.122", "src_port": 6349, "dest_port": 8880}}'); INSERT INTO alerts VALUES(658,1772993390.157857894,'{"timestamp": "2026-03-08T19:09:50.157858+0100", "flow_id": 1803896445987800, "event_type": "alert", "src_ip": "87.121.84.72", "src_port": 50160, "dest_ip": "185.254.126.122", "dest_port": 115, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:09:50.157858+0100", "src_ip": "87.121.84.72", "dest_ip": "185.254.126.122", "src_port": 50160, "dest_port": 115}}'); INSERT INTO alerts VALUES(659,1772993484.473695039,'{"timestamp": "2026-03-08T19:11:24.473695+0100", "flow_id": 1190079917508902, "event_type": "alert", "src_ip": "198.235.24.253", "src_port": 50964, "dest_ip": "185.254.126.122", "dest_port": 3443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:11:24.473695+0100", "src_ip": "198.235.24.253", "dest_ip": "185.254.126.122", "src_port": 50964, "dest_port": 3443}}'); INSERT INTO alerts VALUES(660,1772993511.263313056,'{"timestamp": "2026-03-08T19:11:51.263313+0100", "flow_id": 1975349259186691, "event_type": "alert", "src_ip": "176.65.149.233", "src_port": 39584, "dest_ip": "185.254.126.122", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:11:51.263313+0100", "src_ip": "176.65.149.233", "dest_ip": "185.254.126.122", "src_port": 39584, "dest_port": 8088}}'); INSERT INTO alerts VALUES(661,1772993572.937309026,'{"timestamp": "2026-03-08T19:12:52.937309+0100", "flow_id": 1210962594636731, "event_type": "alert", "src_ip": "193.163.125.28", "src_port": 33040, "dest_ip": "185.254.126.122", "dest_port": 8222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:12:52.937309+0100", "src_ip": "193.163.125.28", "dest_ip": "185.254.126.122", "src_port": 33040, "dest_port": 8222}}'); INSERT INTO alerts VALUES(662,1772993573.770606995,'{"timestamp": "2026-03-08T19:12:53.770607+0100", "flow_id": 1620882596890942, "event_type": "alert", "src_ip": "205.210.31.235", "src_port": 56897, "dest_ip": "185.254.126.122", "dest_port": 4911, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:12:53.770607+0100", "src_ip": "205.210.31.235", "dest_ip": "185.254.126.122", "src_port": 56897, "dest_port": 4911}}'); INSERT INTO alerts VALUES(663,1772993590.459197044,'{"timestamp": "2026-03-08T19:13:10.459197+0100", "flow_id": 1690765299878868, "event_type": "alert", "src_ip": "205.210.31.67", "src_port": 53501, "dest_ip": "185.254.126.122", "dest_port": 9092, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:13:10.459197+0100", "src_ip": "205.210.31.67", "dest_ip": "185.254.126.122", "src_port": 53501, "dest_port": 9092}}'); INSERT INTO alerts VALUES(664,1772993590.520320892,'{"timestamp": "2026-03-08T19:13:10.520321+0100", "flow_id": 1953289825650821, "event_type": "alert", "src_ip": "205.210.31.75", "src_port": 51030, "dest_ip": "185.254.126.122", "dest_port": 54498, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:13:10.520321+0100", "src_ip": "205.210.31.75", "dest_ip": "185.254.126.122", "src_port": 51030, "dest_port": 54498}}'); INSERT INTO alerts VALUES(665,1772993739.925648927,'{"timestamp": "2026-03-08T19:15:39.925649+0100", "flow_id": 879410663066380, "event_type": "alert", "src_ip": "205.210.31.41", "src_port": 52216, "dest_ip": "185.254.126.122", "dest_port": 4100, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:15:39.925649+0100", "src_ip": "205.210.31.41", "dest_ip": "185.254.126.122", "src_port": 52216, "dest_port": 4100}}'); INSERT INTO alerts VALUES(666,1772993743.962327004,'{"timestamp": "2026-03-08T19:15:43.962327+0100", "flow_id": 2162841810119228, "event_type": "alert", "src_ip": "205.210.31.240", "src_port": 55128, "dest_ip": "185.254.126.122", "dest_port": 88, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:15:43.962327+0100", "src_ip": "205.210.31.240", "dest_ip": "185.254.126.122", "src_port": 55128, "dest_port": 88}}'); INSERT INTO alerts VALUES(667,1772993893.291223049,'{"timestamp": "2026-03-08T19:18:13.291223+0100", "flow_id": 1532269859725608, "event_type": "alert", "src_ip": "167.94.146.33", "src_port": 36069, "dest_ip": "185.254.126.122", "dest_port": 29201, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:18:13.291223+0100", "src_ip": "167.94.146.33", "dest_ip": "185.254.126.122", "src_port": 36069, "dest_port": 29201}}'); INSERT INTO alerts VALUES(668,1772994087.752329112,'{"timestamp": "2026-03-08T19:21:27.752329+0100", "flow_id": 2105329769513192, "event_type": "alert", "src_ip": "205.210.31.56", "src_port": 56503, "dest_ip": "185.254.126.122", "dest_port": 2160, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:21:27.752329+0100", "src_ip": "205.210.31.56", "dest_ip": "185.254.126.122", "src_port": 56503, "dest_port": 2160}}'); INSERT INTO alerts VALUES(669,1772994105.818120957,'{"timestamp": "2026-03-08T19:21:45.818121+0100", "flow_id": 417579899736440, "event_type": "alert", "src_ip": "193.163.125.6", "src_port": 58816, "dest_ip": "185.254.126.122", "dest_port": 50000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:21:45.818121+0100", "src_ip": "193.163.125.6", "dest_ip": "185.254.126.122", "src_port": 58816, "dest_port": 50000}}'); INSERT INTO alerts VALUES(670,1772994275.646025897,'{"timestamp": "2026-03-08T19:24:35.646026+0100", "flow_id": 1085814593366943, "event_type": "alert", "src_ip": "147.185.132.106", "src_port": 53576, "dest_ip": "185.254.126.122", "dest_port": 8008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:24:35.646026+0100", "src_ip": "147.185.132.106", "dest_ip": "185.254.126.122", "src_port": 53576, "dest_port": 8008}}'); INSERT INTO alerts VALUES(671,1772994360.368696928,'{"timestamp": "2026-03-08T19:26:00.368697+0100", "flow_id": 176170378285767, "event_type": "alert", "src_ip": "91.196.152.148", "src_port": 47369, "dest_ip": "185.254.126.122", "dest_port": 52951, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:26:00.368697+0100", "src_ip": "91.196.152.148", "dest_ip": "185.254.126.122", "src_port": 47369, "dest_port": 52951}}'); INSERT INTO alerts VALUES(672,1772994471.634162903,'{"timestamp": "2026-03-08T19:27:51.634163+0100", "flow_id": 2160762888928919, "event_type": "alert", "src_ip": "64.89.163.144", "src_port": 54388, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:27:51.634163+0100", "src_ip": "64.89.163.144", "dest_ip": "185.254.126.122", "src_port": 54388, "dest_port": 3306}}'); INSERT INTO alerts VALUES(673,1772994471.634162903,'{"timestamp": "2026-03-08T19:27:51.634163+0100", "flow_id": 2160762888928919, "event_type": "alert", "src_ip": "64.89.163.144", "src_port": 54388, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:27:51.634163+0100", "src_ip": "64.89.163.144", "dest_ip": "185.254.126.122", "src_port": 54388, "dest_port": 3306}}'); INSERT INTO alerts VALUES(674,1772994771.354285956,'{"timestamp": "2026-03-08T19:32:51.354286+0100", "flow_id": 958698993561799, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 44377, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:32:51.354286+0100", "src_ip": "185.156.73.86", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 44377}}'); INSERT INTO alerts VALUES(675,1772994774.528369904,'{"timestamp": "2026-03-08T19:32:54.528370+0100", "flow_id": 1706384384619251, "event_type": "alert", "src_ip": "193.163.125.29", "src_port": 40536, "dest_ip": "185.254.126.122", "dest_port": 61616, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:32:54.528370+0100", "src_ip": "193.163.125.29", "dest_ip": "185.254.126.122", "src_port": 40536, "dest_port": 61616}}'); INSERT INTO alerts VALUES(676,1772994799.353790044,'{"timestamp": "2026-03-08T19:33:19.353790+0100", "flow_id": 2082469998397305, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 40097, "dest_ip": "185.254.126.122", "dest_port": 38080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:33:19.353790+0100", "src_ip": "79.124.40.82", "dest_ip": "185.254.126.122", "src_port": 40097, "dest_port": 38080}}'); INSERT INTO alerts VALUES(677,1772994810.820534945,'{"timestamp": "2026-03-08T19:33:30.820535+0100", "flow_id": 709425288779080, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "185.254.126.122", "dest_port": 11906, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:33:30.820535+0100", "src_ip": "79.124.40.110", "dest_ip": "185.254.126.122", "src_port": 52537, "dest_port": 11906}}'); INSERT INTO alerts VALUES(678,1772994814.746771098,'{"timestamp": "2026-03-08T19:33:34.746771+0100", "flow_id": 1799982736885010, "event_type": "alert", "src_ip": "205.210.31.70", "src_port": 53201, "dest_ip": "185.254.126.122", "dest_port": 636, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:33:34.746771+0100", "src_ip": "205.210.31.70", "dest_ip": "185.254.126.122", "src_port": 53201, "dest_port": 636}}'); INSERT INTO alerts VALUES(679,1772994866.57742405,'{"timestamp": "2026-03-08T19:34:26.577424+0100", "flow_id": 791168492019746, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 58271, "dest_ip": "185.254.126.122", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T19:34:26.577424+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 58271, "dest_port": 8545}}'); INSERT INTO alerts VALUES(680,1772994866.57742405,'{"timestamp": "2026-03-08T19:34:26.577424+0100", "flow_id": 791168492019746, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 58271, "dest_ip": "185.254.126.122", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T19:34:26.577424+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 58271, "dest_port": 8545}}'); INSERT INTO alerts VALUES(681,1772994917.196999074,'{"timestamp": "2026-03-08T19:35:17.196999+0100", "flow_id": 1409055543183191, "event_type": "alert", "src_ip": "205.210.31.206", "src_port": 54350, "dest_ip": "185.254.126.122", "dest_port": 401, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:35:17.196999+0100", "src_ip": "205.210.31.206", "dest_ip": "185.254.126.122", "src_port": 54350, "dest_port": 401}}'); INSERT INTO alerts VALUES(682,1772994920.685939074,'{"timestamp": "2026-03-08T19:35:20.685939+0100", "flow_id": 131338207120446, "event_type": "alert", "src_ip": "167.94.146.78", "src_port": 41271, "dest_ip": "185.254.126.122", "dest_port": 28001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:35:20.685939+0100", "src_ip": "167.94.146.78", "dest_ip": "185.254.126.122", "src_port": 41271, "dest_port": 28001}}'); INSERT INTO alerts VALUES(683,1772994971.196753026,'{"timestamp": "2026-03-08T19:36:11.196753+0100", "flow_id": 845050356380072, "event_type": "alert", "src_ip": "167.94.138.131", "src_port": 31840, "dest_ip": "185.254.126.122", "dest_port": 5000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:36:11.196753+0100", "src_ip": "167.94.138.131", "dest_ip": "185.254.126.122", "src_port": 31840, "dest_port": 5000}}'); INSERT INTO alerts VALUES(684,1772994988.587193013,'{"timestamp": "2026-03-08T19:36:28.587193+0100", "flow_id": 1396078648969088, "event_type": "alert", "src_ip": "198.235.24.99", "src_port": 31163, "dest_ip": "185.254.126.122", "dest_port": 13546, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-08T19:36:28.587193+0100", "src_ip": "198.235.24.99", "dest_ip": "185.254.126.122", "src_port": 31163, "dest_port": 13546}}'); INSERT INTO alerts VALUES(685,1772994989.423645973,'{"timestamp": "2026-03-08T19:36:29.423646+0100", "flow_id": 1538070937673635, "event_type": "alert", "src_ip": "66.132.153.145", "src_port": 64502, "dest_ip": "185.254.126.122", "dest_port": 9601, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:36:29.423646+0100", "src_ip": "66.132.153.145", "dest_ip": "185.254.126.122", "src_port": 64502, "dest_port": 9601}}'); INSERT INTO alerts VALUES(686,1772995008.244560956,'{"timestamp": "2026-03-08T19:36:48.244561+0100", "flow_id": 205959809842690, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 45671, "dest_ip": "185.254.126.122", "dest_port": 4742, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400037, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 38", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T19:36:48.244561+0100", "src_ip": "192.109.200.219", "dest_ip": "185.254.126.122", "src_port": 45671, "dest_port": 4742}}'); INSERT INTO alerts VALUES(687,1772995008.244560956,'{"timestamp": "2026-03-08T19:36:48.244561+0100", "flow_id": 205959809842690, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 45671, "dest_ip": "185.254.126.122", "dest_port": 4742, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500020, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 11", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T19:36:48.244561+0100", "src_ip": "192.109.200.219", "dest_ip": "185.254.126.122", "src_port": 45671, "dest_port": 4742}}'); INSERT INTO alerts VALUES(688,1772995008.335062026,'{"timestamp": "2026-03-08T19:36:48.335062+0100", "flow_id": 31708159319973, "event_type": "alert", "src_ip": "167.94.138.135", "src_port": 28363, "dest_ip": "185.254.126.122", "dest_port": 523, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 48, "bytes_toclient": 0, "start": "2026-03-08T19:36:48.335062+0100", "src_ip": "167.94.138.135", "dest_ip": "185.254.126.122", "src_port": 28363, "dest_port": 523}}'); INSERT INTO alerts VALUES(689,1772995095.39770794,'{"timestamp": "2026-03-08T19:38:15.397708+0100", "flow_id": 1989618200127346, "event_type": "alert", "src_ip": "193.163.125.19", "src_port": 50639, "dest_ip": "185.254.126.122", "dest_port": 1984, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:38:15.397708+0100", "src_ip": "193.163.125.19", "dest_ip": "185.254.126.122", "src_port": 50639, "dest_port": 1984}}'); INSERT INTO alerts VALUES(690,1772995123.563826085,'{"timestamp": "2026-03-08T19:38:43.563826+0100", "flow_id": 1014241138300592, "event_type": "alert", "src_ip": "77.83.39.250", "src_port": 49640, "dest_ip": "185.254.126.122", "dest_port": 465, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400008, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 9", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:38:43.563826+0100", "src_ip": "77.83.39.250", "dest_ip": "185.254.126.122", "src_port": 49640, "dest_port": 465}}'); INSERT INTO alerts VALUES(691,1772995203.852582931,'{"timestamp": "2026-03-08T19:40:03.852583+0100", "flow_id": 847068769045083, "event_type": "alert", "src_ip": "193.163.125.24", "src_port": 35337, "dest_ip": "185.254.126.122", "dest_port": 2187, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:40:03.852583+0100", "src_ip": "193.163.125.24", "dest_ip": "185.254.126.122", "src_port": 35337, "dest_port": 2187}}'); INSERT INTO alerts VALUES(692,1772995262.935532093,'{"timestamp": "2026-03-08T19:41:02.935532+0100", "flow_id": 1766282329281385, "event_type": "alert", "src_ip": "167.94.138.150", "src_port": 7616, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:41:02.935532+0100", "src_ip": "167.94.138.150", "dest_ip": "185.254.126.122", "src_port": 7616, "dest_port": 22}}'); INSERT INTO alerts VALUES(693,1772995266.97458601,'{"timestamp": "2026-03-08T19:41:06.974586+0100", "flow_id": 808117782829884, "event_type": "alert", "src_ip": "43.228.157.17", "src_port": 53005, "dest_ip": "185.254.126.122", "dest_port": 37122, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:41:06.974586+0100", "src_ip": "43.228.157.17", "dest_ip": "185.254.126.122", "src_port": 53005, "dest_port": 37122}}'); INSERT INTO alerts VALUES(694,1772995323.010782958,'{"timestamp": "2026-03-08T19:42:03.010783+0100", "flow_id": 890739487436191, "event_type": "alert", "src_ip": "167.94.138.155", "src_port": 20059, "dest_ip": "185.254.126.122", "dest_port": 11103, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:42:03.010783+0100", "src_ip": "167.94.138.155", "dest_ip": "185.254.126.122", "src_port": 20059, "dest_port": 11103}}'); INSERT INTO alerts VALUES(695,1772995325.548019887,'{"timestamp": "2026-03-08T19:42:05.548020+0100", "flow_id": 1509303387123140, "event_type": "alert", "src_ip": "147.185.132.207", "src_port": 55026, "dest_ip": "185.254.126.122", "dest_port": 4332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:42:05.548020+0100", "src_ip": "147.185.132.207", "dest_ip": "185.254.126.122", "src_port": 55026, "dest_port": 4332}}'); INSERT INTO alerts VALUES(696,1772995338.09719801,'{"timestamp": "2026-03-08T19:42:18.097198+0100", "flow_id": 698938872869123, "event_type": "alert", "src_ip": "167.94.138.153", "src_port": 50251, "dest_ip": "185.254.126.122", "dest_port": 1913, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:42:18.097198+0100", "src_ip": "167.94.138.153", "dest_ip": "185.254.126.122", "src_port": 50251, "dest_port": 1913}}'); INSERT INTO alerts VALUES(697,1772995406.697103977,'{"timestamp": "2026-03-08T19:43:26.697104+0100", "flow_id": 1868143199777937, "event_type": "alert", "src_ip": "130.12.180.52", "src_port": 59044, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:43:26.697104+0100", "src_ip": "130.12.180.52", "dest_ip": "185.254.126.122", "src_port": 59044, "dest_port": 80}}'); INSERT INTO alerts VALUES(698,1772995406.697103977,'{"timestamp": "2026-03-08T19:43:26.697104+0100", "flow_id": 1868143199777937, "event_type": "alert", "src_ip": "130.12.180.52", "src_port": 59044, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:43:26.697104+0100", "src_ip": "130.12.180.52", "dest_ip": "185.254.126.122", "src_port": 59044, "dest_port": 80}}'); INSERT INTO alerts VALUES(699,1772995475.093594075,'{"timestamp": "2026-03-08T19:44:35.093594+0100", "flow_id": 964935316864358, "event_type": "alert", "src_ip": "167.94.146.39", "src_port": 40071, "dest_ip": "185.254.126.122", "dest_port": 54971, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:44:35.093594+0100", "src_ip": "167.94.146.39", "dest_ip": "185.254.126.122", "src_port": 40071, "dest_port": 54971}}'); INSERT INTO alerts VALUES(700,1772995499.184041977,'{"timestamp": "2026-03-08T19:44:59.184042+0100", "flow_id": 1071932738382960, "event_type": "alert", "src_ip": "198.235.24.111", "src_port": 54050, "dest_ip": "185.254.126.122", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:44:59.184042+0100", "src_ip": "198.235.24.111", "dest_ip": "185.254.126.122", "src_port": 54050, "dest_port": 8088}}'); INSERT INTO alerts VALUES(701,1772995537.403551101,'{"timestamp": "2026-03-08T19:45:37.403551+0100", "flow_id": 325864129933598, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 45717, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:45:37.403551+0100", "src_ip": "45.153.34.32", "dest_ip": "185.254.126.122", "src_port": 45717, "dest_port": 3306}}'); INSERT INTO alerts VALUES(702,1772995537.403551101,'{"timestamp": "2026-03-08T19:45:37.403551+0100", "flow_id": 325864129933598, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 45717, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:45:37.403551+0100", "src_ip": "45.153.34.32", "dest_ip": "185.254.126.122", "src_port": 45717, "dest_port": 3306}}'); INSERT INTO alerts VALUES(703,1772995581.1728549,'{"timestamp": "2026-03-08T19:46:21.172855+0100", "flow_id": 1586834760204609, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 53303, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:46:21.172855+0100", "src_ip": "79.124.62.230", "dest_ip": "185.254.126.122", "src_port": 53303, "dest_port": 3389}}'); INSERT INTO alerts VALUES(704,1772995599.176259041,'{"timestamp": "2026-03-08T19:46:39.176259+0100", "flow_id": 2164404857944116, "event_type": "alert", "src_ip": "198.235.24.117", "src_port": 52197, "dest_ip": "185.254.126.122", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 88, "bytes_toclient": 0, "start": "2026-03-08T19:46:39.176259+0100", "src_ip": "198.235.24.117", "dest_ip": "185.254.126.122", "src_port": 52197, "dest_port": 161}}'); INSERT INTO alerts VALUES(705,1772995635.836234092,'{"timestamp": "2026-03-08T19:47:15.836234+0100", "flow_id": 1058326076584971, "event_type": "alert", "src_ip": "147.185.132.15", "src_port": 51576, "dest_ip": "185.254.126.122", "dest_port": 444, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:47:15.836234+0100", "src_ip": "147.185.132.15", "dest_ip": "185.254.126.122", "src_port": 51576, "dest_port": 444}}'); INSERT INTO alerts VALUES(706,1772995684.746699094,'{"timestamp": "2026-03-08T19:48:04.746699+0100", "flow_id": 1236724216616074, "event_type": "alert", "src_ip": "205.210.31.88", "src_port": 50545, "dest_ip": "185.254.126.122", "dest_port": 3388, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:48:04.746699+0100", "src_ip": "205.210.31.88", "dest_ip": "185.254.126.122", "src_port": 50545, "dest_port": 3388}}'); INSERT INTO alerts VALUES(707,1772995697.940557004,'{"timestamp": "2026-03-08T19:48:17.940557+0100", "flow_id": 380487529683113, "event_type": "alert", "src_ip": "205.210.31.82", "src_port": 49586, "dest_ip": "185.254.126.122", "dest_port": 389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:48:17.940557+0100", "src_ip": "205.210.31.82", "dest_ip": "185.254.126.122", "src_port": 49586, "dest_port": 389}}'); INSERT INTO alerts VALUES(708,1772995721.124123097,'{"timestamp": "2026-03-08T19:48:41.124123+0100", "flow_id": 533107533531209, "event_type": "alert", "src_ip": "165.154.33.72", "src_port": 36028, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:48:41.124123+0100", "src_ip": "165.154.33.72", "dest_ip": "185.254.126.122", "src_port": 36028, "dest_port": 3306}}'); INSERT INTO alerts VALUES(709,1772995788.537116051,'{"timestamp": "2026-03-08T19:49:48.537116+0100", "flow_id": 1180998313044787, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 2083, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:49:48.537116+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 2083}}'); INSERT INTO alerts VALUES(710,1772995788.537116051,'{"timestamp": "2026-03-08T19:49:48.537116+0100", "flow_id": 1180998313044787, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 2083, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:49:48.537116+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 2083}}'); INSERT INTO alerts VALUES(711,1772995807.507404088,'{"timestamp": "2026-03-08T19:50:07.507404+0100", "flow_id": 2179285035006735, "event_type": "alert", "src_ip": "167.94.138.152", "src_port": 29178, "dest_ip": "185.254.126.122", "dest_port": 2095, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:50:07.507404+0100", "src_ip": "167.94.138.152", "dest_ip": "185.254.126.122", "src_port": 29178, "dest_port": 2095}}'); INSERT INTO alerts VALUES(712,1772995813.538088084,'{"timestamp": "2026-03-08T19:50:13.538088+0100", "flow_id": 1466648772944491, "event_type": "alert", "src_ip": "193.163.125.12", "src_port": 49262, "dest_ip": "185.254.126.122", "dest_port": 21, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:50:13.538088+0100", "src_ip": "193.163.125.12", "dest_ip": "185.254.126.122", "src_port": 49262, "dest_port": 21}}'); INSERT INTO alerts VALUES(713,1772995874.909337044,'{"timestamp": "2026-03-08T19:51:14.909337+0100", "flow_id": 809351825471204, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 55728, "dest_ip": "185.254.126.122", "dest_port": 10337, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:51:14.909337+0100", "src_ip": "79.124.62.126", "dest_ip": "185.254.126.122", "src_port": 55728, "dest_port": 10337}}'); INSERT INTO alerts VALUES(714,1772995901.068651915,'{"timestamp": "2026-03-08T19:51:41.068652+0100", "flow_id": 1420760451936820, "event_type": "alert", "src_ip": "193.163.125.36", "src_port": 50679, "dest_ip": "185.254.126.122", "dest_port": 2525, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:51:41.068652+0100", "src_ip": "193.163.125.36", "dest_ip": "185.254.126.122", "src_port": 50679, "dest_port": 2525}}'); INSERT INTO alerts VALUES(715,1772995949.170414924,'{"timestamp": "2026-03-08T19:52:29.170415+0100", "flow_id": 1576351805473261, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 34073, "dest_ip": "185.254.126.122", "dest_port": 2376, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:52:29.170415+0100", "src_ip": "193.142.146.230", "dest_ip": "185.254.126.122", "src_port": 34073, "dest_port": 2376}}'); INSERT INTO alerts VALUES(716,1772995952.872150897,'{"timestamp": "2026-03-08T19:52:32.872151+0100", "flow_id": 86686373456639, "event_type": "alert", "src_ip": "167.94.146.46", "src_port": 20287, "dest_ip": "185.254.126.122", "dest_port": 50941, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:52:32.872151+0100", "src_ip": "167.94.146.46", "dest_ip": "185.254.126.122", "src_port": 20287, "dest_port": 50941}}'); INSERT INTO alerts VALUES(717,1772995961.980679035,'{"timestamp": "2026-03-08T19:52:41.980679+0100", "flow_id": 552810111475742, "event_type": "alert", "src_ip": "176.65.134.24", "src_port": 64391, "dest_ip": "185.254.126.122", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 48, "bytes_toclient": 0, "start": "2026-03-08T19:52:41.980679+0100", "src_ip": "176.65.134.24", "dest_ip": "185.254.126.122", "src_port": 64391, "dest_port": 25565}}'); INSERT INTO alerts VALUES(718,1772995962.753876925,'{"timestamp": "2026-03-08T19:52:42.753877+0100", "flow_id": 704602445785734, "event_type": "alert", "src_ip": "172.104.100.117", "src_port": 44894, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T19:52:42.753877+0100", "src_ip": "172.104.100.117", "dest_ip": "185.254.126.122", "src_port": 44894, "dest_port": 5432}}'); INSERT INTO alerts VALUES(719,1772995968.909221888,'{"timestamp": "2026-03-08T19:52:48.909222+0100", "flow_id": 245905361228359, "event_type": "alert", "src_ip": "87.121.84.76", "src_port": 40446, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:52:48.909222+0100", "src_ip": "87.121.84.76", "dest_ip": "185.254.126.122", "src_port": 40446, "dest_port": 80}}'); INSERT INTO alerts VALUES(720,1772995975.278806925,'{"timestamp": "2026-03-08T19:52:55.278807+0100", "flow_id": 2041894030284169, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 54209, "dest_ip": "185.254.126.122", "dest_port": 46340, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:52:55.278807+0100", "src_ip": "79.124.62.134", "dest_ip": "185.254.126.122", "src_port": 54209, "dest_port": 46340}}'); INSERT INTO alerts VALUES(721,1772996102.873090983,'{"timestamp": "2026-03-08T19:55:02.873091+0100", "flow_id": 1779573171549915, "event_type": "alert", "src_ip": "205.210.31.108", "src_port": 50167, "dest_ip": "185.254.126.122", "dest_port": 4786, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:55:02.873091+0100", "src_ip": "205.210.31.108", "dest_ip": "185.254.126.122", "src_port": 50167, "dest_port": 4786}}'); INSERT INTO alerts VALUES(722,1772996137.16129899,'{"timestamp": "2026-03-08T19:55:37.161299+0100", "flow_id": 411299847634752, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 34173, "dest_ip": "185.254.126.122", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:55:37.161299+0100", "src_ip": "87.121.84.57", "dest_ip": "185.254.126.122", "src_port": 34173, "dest_port": 3000}}'); INSERT INTO alerts VALUES(723,1772996142.908061027,'{"timestamp": "2026-03-08T19:55:42.908061+0100", "flow_id": 1929768328941158, "event_type": "alert", "src_ip": "167.94.138.108", "src_port": 14340, "dest_ip": "185.254.126.122", "dest_port": 53408, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T19:55:42.908061+0100", "src_ip": "167.94.138.108", "dest_ip": "185.254.126.122", "src_port": 14340, "dest_port": 53408}}'); INSERT INTO alerts VALUES(724,1772996151.800087928,'{"timestamp": "2026-03-08T19:55:51.800088+0100", "flow_id": 2028978078139666, "event_type": "alert", "src_ip": "193.163.125.13", "src_port": 33726, "dest_ip": "185.254.126.122", "dest_port": 5050, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:55:51.800088+0100", "src_ip": "193.163.125.13", "dest_ip": "185.254.126.122", "src_port": 33726, "dest_port": 5050}}'); INSERT INTO alerts VALUES(725,1772996225.914457083,'{"timestamp": "2026-03-08T19:57:05.914457+0100", "flow_id": 549864885853427, "event_type": "alert", "src_ip": "147.185.132.195", "src_port": 55140, "dest_ip": "185.254.126.122", "dest_port": 10001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:57:05.914457+0100", "src_ip": "147.185.132.195", "dest_ip": "185.254.126.122", "src_port": 55140, "dest_port": 10001}}'); INSERT INTO alerts VALUES(726,1772996229.627072095,'{"timestamp": "2026-03-08T19:57:09.627072+0100", "flow_id": 1567356305734413, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "185.254.126.122", "dest_port": 51344, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:57:09.627072+0100", "src_ip": "130.12.180.88", "dest_ip": "185.254.126.122", "src_port": 52302, "dest_port": 51344}}'); INSERT INTO alerts VALUES(727,1772996229.627072095,'{"timestamp": "2026-03-08T19:57:09.627072+0100", "flow_id": 1567356305734413, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "185.254.126.122", "dest_port": 51344, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:57:09.627072+0100", "src_ip": "130.12.180.88", "dest_ip": "185.254.126.122", "src_port": 52302, "dest_port": 51344}}'); INSERT INTO alerts VALUES(728,1772996254.011209965,'{"timestamp": "2026-03-08T19:57:34.011210+0100", "flow_id": 1736997186493480, "event_type": "alert", "src_ip": "193.163.125.21", "src_port": 59714, "dest_ip": "185.254.126.122", "dest_port": 21288, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:57:34.011210+0100", "src_ip": "193.163.125.21", "dest_ip": "185.254.126.122", "src_port": 59714, "dest_port": 21288}}'); INSERT INTO alerts VALUES(729,1772996269.844784975,'{"timestamp": "2026-03-08T19:57:49.844785+0100", "flow_id": 1658002276107246, "event_type": "alert", "src_ip": "158.94.211.212", "src_port": 49628, "dest_ip": "185.254.126.122", "dest_port": 465, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400027, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 28", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T19:57:49.844785+0100", "src_ip": "158.94.211.212", "dest_ip": "185.254.126.122", "src_port": 49628, "dest_port": 465}}'); INSERT INTO alerts VALUES(730,1772996376.575364112,'{"timestamp": "2026-03-08T19:59:36.575364+0100", "flow_id": 219370311855865, "event_type": "alert", "src_ip": "45.142.154.98", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T19:59:36.575364+0100", "src_ip": "45.142.154.98", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 23}}'); INSERT INTO alerts VALUES(731,1772996405.601342917,'{"timestamp": "2026-03-08T20:00:05.601343+0100", "flow_id": 1456852213209944, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59739, "dest_ip": "185.254.126.122", "dest_port": 39756, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:00:05.601343+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59739, "dest_port": 39756}}'); INSERT INTO alerts VALUES(732,1772996405.601342917,'{"timestamp": "2026-03-08T20:00:05.601343+0100", "flow_id": 1456852213209944, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59739, "dest_ip": "185.254.126.122", "dest_port": 39756, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:00:05.601343+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59739, "dest_port": 39756}}'); INSERT INTO alerts VALUES(733,1772996492.107547998,'{"timestamp": "2026-03-08T20:01:32.107548+0100", "flow_id": 1306341031304806, "event_type": "alert", "src_ip": "205.210.31.193", "src_port": 56933, "dest_ip": "185.254.126.122", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:01:32.107548+0100", "src_ip": "205.210.31.193", "dest_ip": "185.254.126.122", "src_port": 56933, "dest_port": 27017}}'); INSERT INTO alerts VALUES(734,1772996494.720182895,'{"timestamp": "2026-03-08T20:01:34.720183+0100", "flow_id": 1967263239541011, "event_type": "alert", "src_ip": "205.210.31.86", "src_port": 53800, "dest_ip": "185.254.126.122", "dest_port": 8009, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:01:34.720183+0100", "src_ip": "205.210.31.86", "dest_ip": "185.254.126.122", "src_port": 53800, "dest_port": 8009}}'); INSERT INTO alerts VALUES(735,1772996552.119263888,'{"timestamp": "2026-03-08T20:02:32.119264+0100", "flow_id": 230762605347369, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 62467, "dest_ip": "185.254.126.122", "dest_port": 46615, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:02:32.119264+0100", "src_ip": "167.94.146.40", "dest_ip": "185.254.126.122", "src_port": 62467, "dest_port": 46615}}'); INSERT INTO alerts VALUES(736,1772996584.91255498,'{"timestamp": "2026-03-08T20:03:04.912555+0100", "flow_id": 260223470952068, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 12936, "dest_ip": "185.254.126.122", "dest_port": 44082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:03:04.912555+0100", "src_ip": "167.94.146.37", "dest_ip": "185.254.126.122", "src_port": 12936, "dest_port": 44082}}'); INSERT INTO alerts VALUES(737,1772996684.931451083,'{"timestamp": "2026-03-08T20:04:44.931451+0100", "flow_id": 1185803481267274, "event_type": "alert", "src_ip": "205.210.31.97", "src_port": 51048, "dest_ip": "185.254.126.122", "dest_port": 20256, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:04:44.931451+0100", "src_ip": "205.210.31.97", "dest_ip": "185.254.126.122", "src_port": 51048, "dest_port": 20256}}'); INSERT INTO alerts VALUES(738,1772996711.535727025,'{"timestamp": "2026-03-08T20:05:11.535727+0100", "flow_id": 2019457342658171, "event_type": "alert", "src_ip": "91.224.92.177", "src_port": 43038, "dest_ip": "185.254.126.122", "dest_port": 3001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:05:11.535727+0100", "src_ip": "91.224.92.177", "dest_ip": "185.254.126.122", "src_port": 43038, "dest_port": 3001}}'); INSERT INTO alerts VALUES(739,1772996791.75694704,'{"timestamp": "2026-03-08T20:06:31.756947+0100", "flow_id": 2125164259265434, "event_type": "alert", "src_ip": "176.65.134.34", "src_port": 36079, "dest_ip": "185.254.126.122", "dest_port": 41000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:06:31.756947+0100", "src_ip": "176.65.134.34", "dest_ip": "185.254.126.122", "src_port": 36079, "dest_port": 41000}}'); INSERT INTO alerts VALUES(740,1772996845.495244027,'{"timestamp": "2026-03-08T20:07:25.495244+0100", "flow_id": 1564110791608796, "event_type": "alert", "src_ip": "147.185.132.46", "src_port": 49372, "dest_ip": "185.254.126.122", "dest_port": 1028, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:07:25.495244+0100", "src_ip": "147.185.132.46", "dest_ip": "185.254.126.122", "src_port": 49372, "dest_port": 1028}}'); INSERT INTO alerts VALUES(741,1772996864.482892036,'{"timestamp": "2026-03-08T20:07:44.482892+0100", "flow_id": 103683964845137, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 44314, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:07:44.482892+0100", "src_ip": "88.210.63.69", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 44314}}'); INSERT INTO alerts VALUES(742,1772996882.562480926,'{"timestamp": "2026-03-08T20:08:02.562481+0100", "flow_id": 726989966029822, "event_type": "alert", "src_ip": "88.210.63.191", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 13443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:08:02.562481+0100", "src_ip": "88.210.63.191", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 13443}}'); INSERT INTO alerts VALUES(743,1772996885.466512918,'{"timestamp": "2026-03-08T20:08:05.466513+0100", "flow_id": 1440711732022966, "event_type": "alert", "src_ip": "147.185.132.168", "src_port": 53225, "dest_ip": "185.254.126.122", "dest_port": 51007, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:08:05.466513+0100", "src_ip": "147.185.132.168", "dest_ip": "185.254.126.122", "src_port": 53225, "dest_port": 51007}}'); INSERT INTO alerts VALUES(744,1772996972.48891306,'{"timestamp": "2026-03-08T20:09:32.488913+0100", "flow_id": 1255440667007108, "event_type": "alert", "src_ip": "88.210.63.190", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 58443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:09:32.488913+0100", "src_ip": "88.210.63.190", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 58443}}'); INSERT INTO alerts VALUES(745,1772997088.66712308,'{"timestamp": "2026-03-08T20:11:28.667123+0100", "flow_id": 50524781915977, "event_type": "alert", "src_ip": "205.210.31.204", "src_port": 55223, "dest_ip": "185.254.126.122", "dest_port": 50053, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:11:28.667123+0100", "src_ip": "205.210.31.204", "dest_ip": "185.254.126.122", "src_port": 55223, "dest_port": 50053}}'); INSERT INTO alerts VALUES(746,1772997109.152990103,'{"timestamp": "2026-03-08T20:11:49.152990+0100", "flow_id": 1501516185323735, "event_type": "alert", "src_ip": "194.50.16.198", "src_port": 5061, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 429, "bytes_toclient": 0, "start": "2026-03-08T20:11:49.152990+0100", "src_ip": "194.50.16.198", "dest_ip": "185.254.126.122", "src_port": 5061, "dest_port": 5060}}'); INSERT INTO alerts VALUES(747,1772997171.823653936,'{"timestamp": "2026-03-08T20:12:51.823654+0100", "flow_id": 1004293165852902, "event_type": "alert", "src_ip": "167.94.138.138", "src_port": 12598, "dest_ip": "185.254.126.122", "dest_port": 58000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:12:51.823654+0100", "src_ip": "167.94.138.138", "dest_ip": "185.254.126.122", "src_port": 12598, "dest_port": 58000}}'); INSERT INTO alerts VALUES(748,1772997184.848424912,'{"timestamp": "2026-03-08T20:13:04.848425+0100", "flow_id": 266260928340923, "event_type": "alert", "src_ip": "205.210.31.76", "src_port": 51390, "dest_ip": "185.254.126.122", "dest_port": 445, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:13:04.848425+0100", "src_ip": "205.210.31.76", "dest_ip": "185.254.126.122", "src_port": 51390, "dest_port": 445}}'); INSERT INTO alerts VALUES(749,1772997219.801706075,'{"timestamp": "2026-03-08T20:13:39.801706+0100", "flow_id": 910027322538218, "event_type": "alert", "src_ip": "205.210.31.69", "src_port": 53479, "dest_ip": "185.254.126.122", "dest_port": 28080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:13:39.801706+0100", "src_ip": "205.210.31.69", "dest_ip": "185.254.126.122", "src_port": 53479, "dest_port": 28080}}'); INSERT INTO alerts VALUES(750,1772997239.975716114,'{"timestamp": "2026-03-08T20:13:59.975716+0100", "flow_id": 2220346355366617, "event_type": "alert", "src_ip": "205.210.31.108", "src_port": 52969, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:13:59.975716+0100", "src_ip": "205.210.31.108", "dest_ip": "185.254.126.122", "src_port": 52969, "dest_port": 3306}}'); INSERT INTO alerts VALUES(751,1772997248.701220989,'{"timestamp": "2026-03-08T20:14:08.701221+0100", "flow_id": 196972684561080, "event_type": "alert", "src_ip": "66.132.153.150", "src_port": 50119, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:14:08.701221+0100", "src_ip": "66.132.153.150", "dest_ip": "185.254.126.122", "src_port": 50119, "dest_port": 1433}}'); INSERT INTO alerts VALUES(752,1772997248.701220989,'{"timestamp": "2026-03-08T20:14:08.701221+0100", "flow_id": 196972684561080, "event_type": "alert", "src_ip": "66.132.153.150", "src_port": 50119, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:14:08.701221+0100", "src_ip": "66.132.153.150", "dest_ip": "185.254.126.122", "src_port": 50119, "dest_port": 1433}}'); INSERT INTO alerts VALUES(753,1772997286.250861883,'{"timestamp": "2026-03-08T20:14:46.250862+0100", "flow_id": 1921871137269985, "event_type": "alert", "src_ip": "45.156.87.50", "src_port": 42281, "dest_ip": "185.254.126.122", "dest_port": 17000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:14:46.250862+0100", "src_ip": "45.156.87.50", "dest_ip": "185.254.126.122", "src_port": 42281, "dest_port": 17000}}'); INSERT INTO alerts VALUES(754,1772997441.753115893,'{"timestamp": "2026-03-08T20:17:21.753116+0100", "flow_id": 419862370518168, "event_type": "alert", "src_ip": "64.89.161.53", "src_port": 43970, "dest_ip": "185.254.126.122", "dest_port": 10012, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T20:17:21.753116+0100", "src_ip": "64.89.161.53", "dest_ip": "185.254.126.122", "src_port": 43970, "dest_port": 10012}}'); INSERT INTO alerts VALUES(755,1772997502.619277955,'{"timestamp": "2026-03-08T20:18:22.619278+0100", "flow_id": 1815358068138418, "event_type": "alert", "src_ip": "87.121.84.72", "src_port": 50160, "dest_ip": "185.254.126.122", "dest_port": 117, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:18:22.619278+0100", "src_ip": "87.121.84.72", "dest_ip": "185.254.126.122", "src_port": 50160, "dest_port": 117}}'); INSERT INTO alerts VALUES(756,1772997506.929975987,'{"timestamp": "2026-03-08T20:18:26.929976+0100", "flow_id": 616519446360227, "event_type": "alert", "src_ip": "193.163.125.27", "src_port": 51525, "dest_ip": "185.254.126.122", "dest_port": 9108, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:18:26.929976+0100", "src_ip": "193.163.125.27", "dest_ip": "185.254.126.122", "src_port": 51525, "dest_port": 9108}}'); INSERT INTO alerts VALUES(757,1772997553.649799109,'{"timestamp": "2026-03-08T20:19:13.649799+0100", "flow_id": 539067846195583, "event_type": "alert", "src_ip": "205.210.31.250", "src_port": 54737, "dest_ip": "185.254.126.122", "dest_port": 88, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:19:13.649799+0100", "src_ip": "205.210.31.250", "dest_ip": "185.254.126.122", "src_port": 54737, "dest_port": 88}}'); INSERT INTO alerts VALUES(758,1772997653.057126998,'{"timestamp": "2026-03-08T20:20:53.057127+0100", "flow_id": 1652733917379011, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 57020, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:20:53.057127+0100", "src_ip": "45.153.34.32", "dest_ip": "185.254.126.122", "src_port": 57020, "dest_port": 3306}}'); INSERT INTO alerts VALUES(759,1772997668.052010059,'{"timestamp": "2026-03-08T20:21:08.052010+0100", "flow_id": 1349284990079907, "event_type": "alert", "src_ip": "205.210.31.101", "src_port": 56140, "dest_ip": "185.254.126.122", "dest_port": 5906, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:21:08.052010+0100", "src_ip": "205.210.31.101", "dest_ip": "185.254.126.122", "src_port": 56140, "dest_port": 5906}}'); INSERT INTO alerts VALUES(760,1772997875.889720916,'{"timestamp": "2026-03-08T20:24:35.889721+0100", "flow_id": 1006574063480828, "event_type": "alert", "src_ip": "147.185.132.117", "src_port": 49454, "dest_ip": "185.254.126.122", "dest_port": 9000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:24:35.889721+0100", "src_ip": "147.185.132.117", "dest_ip": "185.254.126.122", "src_port": 49454, "dest_port": 9000}}'); INSERT INTO alerts VALUES(761,1772997973.92956996,'{"timestamp": "2026-03-08T20:26:13.929570+0100", "flow_id": 1459199818604061, "event_type": "alert", "src_ip": "64.89.163.148", "src_port": 57806, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:26:13.929570+0100", "src_ip": "64.89.163.148", "dest_ip": "185.254.126.122", "src_port": 57806, "dest_port": 3306}}'); INSERT INTO alerts VALUES(762,1772997973.92956996,'{"timestamp": "2026-03-08T20:26:13.929570+0100", "flow_id": 1459199818604061, "event_type": "alert", "src_ip": "64.89.163.148", "src_port": 57806, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:26:13.929570+0100", "src_ip": "64.89.163.148", "dest_ip": "185.254.126.122", "src_port": 57806, "dest_port": 3306}}'); INSERT INTO alerts VALUES(763,1772997995.695736885,'{"timestamp": "2026-03-08T20:26:35.695737+0100", "flow_id": 1017846658811533, "event_type": "alert", "src_ip": "147.185.132.237", "src_port": 53608, "dest_ip": "185.254.126.122", "dest_port": 4430, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:26:35.695737+0100", "src_ip": "147.185.132.237", "dest_ip": "185.254.126.122", "src_port": 53608, "dest_port": 4430}}'); INSERT INTO alerts VALUES(764,1772998161.8986969,'{"timestamp": "2026-03-08T20:29:21.898697+0100", "flow_id": 482175648961417, "event_type": "alert", "src_ip": "167.94.138.103", "src_port": 39796, "dest_ip": "185.254.126.122", "dest_port": 49104, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:29:21.898697+0100", "src_ip": "167.94.138.103", "dest_ip": "185.254.126.122", "src_port": 39796, "dest_port": 49104}}'); INSERT INTO alerts VALUES(765,1772998218.685156106,'{"timestamp": "2026-03-08T20:30:18.685156+0100", "flow_id": 690926288261454, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 57202, "dest_ip": "185.254.126.122", "dest_port": 3435, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:30:18.685156+0100", "src_ip": "45.142.193.7", "dest_ip": "185.254.126.122", "src_port": 57202, "dest_port": 3435}}'); INSERT INTO alerts VALUES(766,1772998239.273880958,'{"timestamp": "2026-03-08T20:30:39.273881+0100", "flow_id": 2020736748910707, "event_type": "alert", "src_ip": "167.94.146.41", "src_port": 35399, "dest_ip": "185.254.126.122", "dest_port": 30518, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:30:39.273881+0100", "src_ip": "167.94.146.41", "dest_ip": "185.254.126.122", "src_port": 35399, "dest_port": 30518}}'); INSERT INTO alerts VALUES(767,1772998292.600559949,'{"timestamp": "2026-03-08T20:31:32.600560+0100", "flow_id": 1172014882975356, "event_type": "alert", "src_ip": "43.228.157.19", "src_port": 57101, "dest_ip": "185.254.126.122", "dest_port": 12488, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:31:32.600560+0100", "src_ip": "43.228.157.19", "dest_ip": "185.254.126.122", "src_port": 57101, "dest_port": 12488}}'); INSERT INTO alerts VALUES(768,1772998312.940932036,'{"timestamp": "2026-03-08T20:31:52.940932+0100", "flow_id": 100624459371357, "event_type": "alert", "src_ip": "178.20.210.152", "src_port": 53204, "dest_ip": "185.254.126.122", "dest_port": 51922, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:31:52.940932+0100", "src_ip": "178.20.210.152", "dest_ip": "185.254.126.122", "src_port": 53204, "dest_port": 51922}}'); INSERT INTO alerts VALUES(769,1772998329.226285934,'{"timestamp": "2026-03-08T20:32:09.226286+0100", "flow_id": 408943425238904, "event_type": "alert", "src_ip": "87.121.84.88", "src_port": 60000, "dest_ip": "185.254.126.122", "dest_port": 22159, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:32:09.226286+0100", "src_ip": "87.121.84.88", "dest_ip": "185.254.126.122", "src_port": 60000, "dest_port": 22159}}'); INSERT INTO alerts VALUES(770,1772998352.373260022,'{"timestamp": "2026-03-08T20:32:32.373260+0100", "flow_id": 195767163409286, "event_type": "alert", "src_ip": "198.235.24.178", "src_port": 49519, "dest_ip": "185.254.126.122", "dest_port": 10010, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:32:32.373260+0100", "src_ip": "198.235.24.178", "dest_ip": "185.254.126.122", "src_port": 49519, "dest_port": 10010}}'); INSERT INTO alerts VALUES(771,1772998372.656402112,'{"timestamp": "2026-03-08T20:32:52.656402+0100", "flow_id": 1130378710830302, "event_type": "alert", "src_ip": "147.185.132.123", "src_port": 55789, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 408, "bytes_toclient": 0, "start": "2026-03-08T20:32:52.656402+0100", "src_ip": "147.185.132.123", "dest_ip": "185.254.126.122", "src_port": 55789, "dest_port": 5060}}'); INSERT INTO alerts VALUES(772,1772998425.448502063,'{"timestamp": "2026-03-08T20:33:45.448502+0100", "flow_id": 518927471432136, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 40097, "dest_ip": "185.254.126.122", "dest_port": 4521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:33:45.448502+0100", "src_ip": "79.124.40.82", "dest_ip": "185.254.126.122", "src_port": 40097, "dest_port": 4521}}'); INSERT INTO alerts VALUES(773,1772998450.716228009,'{"timestamp": "2026-03-08T20:34:10.716228+0100", "flow_id": 824378539492987, "event_type": "alert", "src_ip": "198.235.24.194", "src_port": 53807, "dest_ip": "185.254.126.122", "dest_port": 2002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:34:10.716228+0100", "src_ip": "198.235.24.194", "dest_ip": "185.254.126.122", "src_port": 53807, "dest_port": 2002}}'); INSERT INTO alerts VALUES(774,1772998459.034542083,'{"timestamp": "2026-03-08T20:34:19.034542+0100", "flow_id": 992784708188846, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 52881, "dest_ip": "185.254.126.122", "dest_port": 2222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:34:19.034542+0100", "src_ip": "185.242.246.36", "dest_ip": "185.254.126.122", "src_port": 52881, "dest_port": 2222}}'); INSERT INTO alerts VALUES(775,1772998459.034542083,'{"timestamp": "2026-03-08T20:34:19.034542+0100", "flow_id": 992784708188846, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 52881, "dest_ip": "185.254.126.122", "dest_port": 2222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:34:19.034542+0100", "src_ip": "185.242.246.36", "dest_ip": "185.254.126.122", "src_port": 52881, "dest_port": 2222}}'); INSERT INTO alerts VALUES(776,1772998472.900187016,'{"timestamp": "2026-03-08T20:34:32.900187+0100", "flow_id": 207102695458352, "event_type": "alert", "src_ip": "45.153.34.187", "src_port": 48115, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:34:32.900187+0100", "src_ip": "45.153.34.187", "dest_ip": "185.254.126.122", "src_port": 48115, "dest_port": 80}}'); INSERT INTO alerts VALUES(777,1772998499.298300981,'{"timestamp": "2026-03-08T20:34:59.298301+0100", "flow_id": 999718308467617, "event_type": "alert", "src_ip": "198.235.24.84", "src_port": 51383, "dest_ip": "185.254.126.122", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-08T20:34:59.298301+0100", "src_ip": "198.235.24.84", "dest_ip": "185.254.126.122", "src_port": 51383, "dest_port": 53}}'); INSERT INTO alerts VALUES(778,1772998499.298300981,'{"timestamp": "2026-03-08T20:34:59.298301+0100", "flow_id": 999718308467617, "event_type": "alert", "src_ip": "198.235.24.84", "src_port": 51383, "dest_ip": "185.254.126.122", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2101616, "rev": 9, "signature": "GPL DNS named version attempt", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_07_26"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-08T20:34:59.298301+0100", "src_ip": "198.235.24.84", "dest_ip": "185.254.126.122", "src_port": 51383, "dest_port": 53}}'); INSERT INTO alerts VALUES(779,1772998533.51175499,'{"timestamp": "2026-03-08T20:35:33.511755+0100", "flow_id": 1635022550195106, "event_type": "alert", "src_ip": "185.242.226.67", "src_port": 58647, "dest_ip": "185.254.126.122", "dest_port": 5094, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-08T20:35:33.511755+0100", "src_ip": "185.242.226.67", "dest_ip": "185.254.126.122", "src_port": 58647, "dest_port": 5094}}'); INSERT INTO alerts VALUES(780,1772998583.889744997,'{"timestamp": "2026-03-08T20:36:23.889745+0100", "flow_id": 2132577887710045, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "185.254.126.122", "dest_port": 14946, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:36:23.889745+0100", "src_ip": "79.124.40.110", "dest_ip": "185.254.126.122", "src_port": 52537, "dest_port": 14946}}'); INSERT INTO alerts VALUES(781,1772998644.377679109,'{"timestamp": "2026-03-08T20:37:24.377679+0100", "flow_id": 1340645385797722, "event_type": "alert", "src_ip": "185.242.226.68", "src_port": 55364, "dest_ip": "185.254.126.122", "dest_port": 7168, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-08T20:37:24.377679+0100", "src_ip": "185.242.226.68", "dest_ip": "185.254.126.122", "src_port": 55364, "dest_port": 7168}}'); INSERT INTO alerts VALUES(782,1772998661.298909903,'{"timestamp": "2026-03-08T20:37:41.298910+0100", "flow_id": 1565284007163642, "event_type": "alert", "src_ip": "193.163.125.10", "src_port": 53293, "dest_ip": "185.254.126.122", "dest_port": 21304, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:37:41.298910+0100", "src_ip": "193.163.125.10", "dest_ip": "185.254.126.122", "src_port": 53293, "dest_port": 21304}}'); INSERT INTO alerts VALUES(783,1772998664.902548074,'{"timestamp": "2026-03-08T20:37:44.902548+0100", "flow_id": 217243518296947, "event_type": "alert", "src_ip": "205.210.31.110", "src_port": 50005, "dest_ip": "185.254.126.122", "dest_port": 5632, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 30, "bytes_toclient": 0, "start": "2026-03-08T20:37:44.902548+0100", "src_ip": "205.210.31.110", "dest_ip": "185.254.126.122", "src_port": 50005, "dest_port": 5632}}'); INSERT INTO alerts VALUES(784,1772998664.902548074,'{"timestamp": "2026-03-08T20:37:44.902548+0100", "flow_id": 217243518296947, "event_type": "alert", "src_ip": "205.210.31.110", "src_port": 50005, "dest_ip": "185.254.126.122", "dest_port": 5632, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2100566, "rev": 5, "signature": "GPL POLICY PCAnywhere server response", "category": "Misc activity", "severity": 3, "metadata": {"created_at": ["2010_09_23"], "signature_severity": ["Unknown"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 30, "bytes_toclient": 0, "start": "2026-03-08T20:37:44.902548+0100", "src_ip": "205.210.31.110", "dest_ip": "185.254.126.122", "src_port": 50005, "dest_port": 5632}}'); INSERT INTO alerts VALUES(785,1772998823.979213954,'{"timestamp": "2026-03-08T20:40:23.979214+0100", "flow_id": 2235368527481141, "event_type": "alert", "src_ip": "147.185.132.201", "src_port": 49739, "dest_ip": "185.254.126.122", "dest_port": 3493, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:40:23.979214+0100", "src_ip": "147.185.132.201", "dest_ip": "185.254.126.122", "src_port": 49739, "dest_port": 3493}}'); INSERT INTO alerts VALUES(786,1772998875.909862042,'{"timestamp": "2026-03-08T20:41:15.909862+0100", "flow_id": 1093080409981966, "event_type": "alert", "src_ip": "176.65.148.29", "src_port": 53344, "dest_ip": "185.254.126.122", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T20:41:15.909862+0100", "src_ip": "176.65.148.29", "dest_ip": "185.254.126.122", "src_port": 53344, "dest_port": 8545}}'); INSERT INTO alerts VALUES(787,1772998875.909862042,'{"timestamp": "2026-03-08T20:41:15.909862+0100", "flow_id": 1093080409981966, "event_type": "alert", "src_ip": "176.65.148.29", "src_port": 53344, "dest_ip": "185.254.126.122", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T20:41:15.909862+0100", "src_ip": "176.65.148.29", "dest_ip": "185.254.126.122", "src_port": 53344, "dest_port": 8545}}'); INSERT INTO alerts VALUES(788,1772998889.200779915,'{"timestamp": "2026-03-08T20:41:29.200780+0100", "flow_id": 299397612773731, "event_type": "alert", "src_ip": "198.235.24.64", "src_port": 52922, "dest_ip": "185.254.126.122", "dest_port": 8085, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:41:29.200780+0100", "src_ip": "198.235.24.64", "dest_ip": "185.254.126.122", "src_port": 52922, "dest_port": 8085}}'); INSERT INTO alerts VALUES(789,1772998909.122773885,'{"timestamp": "2026-03-08T20:41:49.122774+0100", "flow_id": 1653212064884073, "event_type": "alert", "src_ip": "34.118.59.79", "src_port": 45432, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:41:49.122774+0100", "src_ip": "34.118.59.79", "dest_ip": "185.254.126.122", "src_port": 45432, "dest_port": 5432}}'); INSERT INTO alerts VALUES(790,1772998948.155320882,'{"timestamp": "2026-03-08T20:42:28.155321+0100", "flow_id": 1230051439840897, "event_type": "alert", "src_ip": "193.163.125.26", "src_port": 54850, "dest_ip": "185.254.126.122", "dest_port": 4911, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:42:28.155321+0100", "src_ip": "193.163.125.26", "dest_ip": "185.254.126.122", "src_port": 54850, "dest_port": 4911}}'); INSERT INTO alerts VALUES(791,1772998950.109698057,'{"timestamp": "2026-03-08T20:42:30.109698+0100", "flow_id": 1878528422583969, "event_type": "alert", "src_ip": "178.83.200.2", "src_port": 60000, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:42:30.109698+0100", "src_ip": "178.83.200.2", "dest_ip": "185.254.126.122", "src_port": 60000, "dest_port": 1433}}'); INSERT INTO alerts VALUES(792,1772998987.65840602,'{"timestamp": "2026-03-08T20:43:07.658406+0100", "flow_id": 857510773396117, "event_type": "alert", "src_ip": "167.94.146.38", "src_port": 62274, "dest_ip": "185.254.126.122", "dest_port": 1777, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:43:07.658406+0100", "src_ip": "167.94.146.38", "dest_ip": "185.254.126.122", "src_port": 62274, "dest_port": 1777}}'); INSERT INTO alerts VALUES(793,1772999037.644506931,'{"timestamp": "2026-03-08T20:43:57.644507+0100", "flow_id": 1642237451345932, "event_type": "alert", "src_ip": "192.109.200.220", "src_port": 58926, "dest_ip": "185.254.126.122", "dest_port": 672, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400037, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 38", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T20:43:57.644507+0100", "src_ip": "192.109.200.220", "dest_ip": "185.254.126.122", "src_port": 58926, "dest_port": 672}}'); INSERT INTO alerts VALUES(794,1772999120.439189911,'{"timestamp": "2026-03-08T20:45:20.439190+0100", "flow_id": 197457777519473, "event_type": "alert", "src_ip": "147.185.132.18", "src_port": 49523, "dest_ip": "185.254.126.122", "dest_port": 11495, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:45:20.439190+0100", "src_ip": "147.185.132.18", "dest_ip": "185.254.126.122", "src_port": 49523, "dest_port": 11495}}'); INSERT INTO alerts VALUES(795,1772999199.82663989,'{"timestamp": "2026-03-08T20:46:39.826640+0100", "flow_id": 2143018022521479, "event_type": "alert", "src_ip": "205.210.31.99", "src_port": 52762, "dest_ip": "185.254.126.122", "dest_port": 2096, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:46:39.826640+0100", "src_ip": "205.210.31.99", "dest_ip": "185.254.126.122", "src_port": 52762, "dest_port": 2096}}'); INSERT INTO alerts VALUES(796,1772999258.154313087,'{"timestamp": "2026-03-08T20:47:38.154313+0100", "flow_id": 662769522558595, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 45250, "dest_ip": "185.254.126.122", "dest_port": 24093, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:47:38.154313+0100", "src_ip": "167.94.146.32", "dest_ip": "185.254.126.122", "src_port": 45250, "dest_port": 24093}}'); INSERT INTO alerts VALUES(797,1772999280.865138054,'{"timestamp": "2026-03-08T20:48:00.865138+0100", "flow_id": 56568616660709, "event_type": "alert", "src_ip": "147.185.132.79", "src_port": 56440, "dest_ip": "185.254.126.122", "dest_port": 3905, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:48:00.865138+0100", "src_ip": "147.185.132.79", "dest_ip": "185.254.126.122", "src_port": 56440, "dest_port": 3905}}'); INSERT INTO alerts VALUES(798,1772999293.36255002,'{"timestamp": "2026-03-08T20:48:13.362550+0100", "flow_id": 1557142741790571, "event_type": "alert", "src_ip": "185.169.4.141", "src_port": 43176, "dest_ip": "185.254.126.122", "dest_port": 8728, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:48:13.362550+0100", "src_ip": "185.169.4.141", "dest_ip": "185.254.126.122", "src_port": 43176, "dest_port": 8728}}'); INSERT INTO alerts VALUES(799,1772999366.770520925,'{"timestamp": "2026-03-08T20:49:26.770521+0100", "flow_id": 1901990990743208, "event_type": "alert", "src_ip": "51.38.211.50", "src_port": 5283, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 440, "bytes_toclient": 0, "start": "2026-03-08T20:49:26.770521+0100", "src_ip": "51.38.211.50", "dest_ip": "185.254.126.122", "src_port": 5283, "dest_port": 5060}}'); INSERT INTO alerts VALUES(800,1772999366.770520925,'{"timestamp": "2026-03-08T20:49:26.770521+0100", "flow_id": 1901990990743208, "event_type": "alert", "src_ip": "51.38.211.50", "src_port": 5283, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 440, "bytes_toclient": 0, "start": "2026-03-08T20:49:26.770521+0100", "src_ip": "51.38.211.50", "dest_ip": "185.254.126.122", "src_port": 5283, "dest_port": 5060}}'); INSERT INTO alerts VALUES(801,1772999417.436831952,'{"timestamp": "2026-03-08T20:50:17.436832+0100", "flow_id": 468804538075288, "event_type": "alert", "src_ip": "198.235.24.120", "src_port": 51089, "dest_ip": "185.254.126.122", "dest_port": 5000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:50:17.436832+0100", "src_ip": "198.235.24.120", "dest_ip": "185.254.126.122", "src_port": 51089, "dest_port": 5000}}'); INSERT INTO alerts VALUES(802,1772999422.467606067,'{"timestamp": "2026-03-08T20:50:22.467606+0100", "flow_id": 1726877965599514, "event_type": "alert", "src_ip": "198.235.24.214", "src_port": 51013, "dest_ip": "185.254.126.122", "dest_port": 8991, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:50:22.467606+0100", "src_ip": "198.235.24.214", "dest_ip": "185.254.126.122", "src_port": 51013, "dest_port": 8991}}'); INSERT INTO alerts VALUES(803,1772999424.638678073,'{"timestamp": "2026-03-08T20:50:24.638678+0100", "flow_id": 209830056559657, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 59206, "dest_ip": "185.254.126.122", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T20:50:24.638678+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 59206, "dest_port": 8545}}'); INSERT INTO alerts VALUES(804,1772999424.638678073,'{"timestamp": "2026-03-08T20:50:24.638678+0100", "flow_id": 209830056559657, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 59206, "dest_ip": "185.254.126.122", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T20:50:24.638678+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 59206, "dest_port": 8545}}'); INSERT INTO alerts VALUES(805,1772999486.458863973,'{"timestamp": "2026-03-08T20:51:26.458864+0100", "flow_id": 1689331647456650, "event_type": "alert", "src_ip": "185.242.226.124", "src_port": 34905, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T20:51:26.458864+0100", "src_ip": "185.242.226.124", "dest_ip": "185.254.126.122", "src_port": 34905, "dest_port": 443}}'); INSERT INTO alerts VALUES(806,1772999499.279818058,'{"timestamp": "2026-03-08T20:51:39.279818+0100", "flow_id": 920336057831825, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 18128, "dest_ip": "185.254.126.122", "dest_port": 14028, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:51:39.279818+0100", "src_ip": "167.94.146.45", "dest_ip": "185.254.126.122", "src_port": 18128, "dest_port": 14028}}'); INSERT INTO alerts VALUES(807,1772999556.953968049,'{"timestamp": "2026-03-08T20:52:36.953968+0100", "flow_id": 1282514005703951, "event_type": "alert", "src_ip": "91.196.152.60", "src_port": 62901, "dest_ip": "185.254.126.122", "dest_port": 6666, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:52:36.953968+0100", "src_ip": "91.196.152.60", "dest_ip": "185.254.126.122", "src_port": 62901, "dest_port": 6666}}'); INSERT INTO alerts VALUES(808,1772999591.17789507,'{"timestamp": "2026-03-08T20:53:11.177895+0100", "flow_id": 2171430218613973, "event_type": "alert", "src_ip": "193.163.125.16", "src_port": 48175, "dest_ip": "185.254.126.122", "dest_port": 7810, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:53:11.177895+0100", "src_ip": "193.163.125.16", "dest_ip": "185.254.126.122", "src_port": 48175, "dest_port": 7810}}'); INSERT INTO alerts VALUES(809,1772999622.330562114,'{"timestamp": "2026-03-08T20:53:42.330562+0100", "flow_id": 1701228468999249, "event_type": "alert", "src_ip": "193.163.125.24", "src_port": 50127, "dest_ip": "185.254.126.122", "dest_port": 18789, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:53:42.330562+0100", "src_ip": "193.163.125.24", "dest_ip": "185.254.126.122", "src_port": 50127, "dest_port": 18789}}'); INSERT INTO alerts VALUES(810,1772999634.508399963,'{"timestamp": "2026-03-08T20:53:54.508400+0100", "flow_id": 776188488234778, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 58456, "dest_ip": "185.254.126.122", "dest_port": 31127, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:53:54.508400+0100", "src_ip": "79.124.62.230", "dest_ip": "185.254.126.122", "src_port": 58456, "dest_port": 31127}}'); INSERT INTO alerts VALUES(811,1772999684.83396697,'{"timestamp": "2026-03-08T20:54:44.833967+0100", "flow_id": 1330063822549151, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 55728, "dest_ip": "185.254.126.122", "dest_port": 52377, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:54:44.833967+0100", "src_ip": "79.124.62.126", "dest_ip": "185.254.126.122", "src_port": 55728, "dest_port": 52377}}'); INSERT INTO alerts VALUES(812,1772999712.862467051,'{"timestamp": "2026-03-08T20:55:12.862467+0100", "flow_id": 45094831714094, "event_type": "alert", "src_ip": "91.196.152.52", "src_port": 45350, "dest_ip": "185.254.126.122", "dest_port": 6555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:55:12.862467+0100", "src_ip": "91.196.152.52", "dest_ip": "185.254.126.122", "src_port": 45350, "dest_port": 6555}}'); INSERT INTO alerts VALUES(813,1772999713.269915104,'{"timestamp": "2026-03-08T20:55:13.269915+0100", "flow_id": 314853982960998, "event_type": "alert", "src_ip": "167.94.146.39", "src_port": 34354, "dest_ip": "185.254.126.122", "dest_port": 30073, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:55:13.269915+0100", "src_ip": "167.94.146.39", "dest_ip": "185.254.126.122", "src_port": 34354, "dest_port": 30073}}'); INSERT INTO alerts VALUES(814,1772999726.915698052,'{"timestamp": "2026-03-08T20:55:26.915698+0100", "flow_id": 1962568580434563, "event_type": "alert", "src_ip": "205.210.31.246", "src_port": 55646, "dest_ip": "185.254.126.122", "dest_port": 8531, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:55:26.915698+0100", "src_ip": "205.210.31.246", "dest_ip": "185.254.126.122", "src_port": 55646, "dest_port": 8531}}'); INSERT INTO alerts VALUES(815,1772999742.440222978,'{"timestamp": "2026-03-08T20:55:42.440223+0100", "flow_id": 1890745734002408, "event_type": "alert", "src_ip": "167.94.146.46", "src_port": 56888, "dest_ip": "185.254.126.122", "dest_port": 29126, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T20:55:42.440223+0100", "src_ip": "167.94.146.46", "dest_ip": "185.254.126.122", "src_port": 56888, "dest_port": 29126}}'); INSERT INTO alerts VALUES(816,1772999752.614618063,'{"timestamp": "2026-03-08T20:55:52.614618+0100", "flow_id": 106489829896850, "event_type": "alert", "src_ip": "198.235.24.239", "src_port": 52815, "dest_ip": "185.254.126.122", "dest_port": 5557, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:55:52.614618+0100", "src_ip": "198.235.24.239", "dest_ip": "185.254.126.122", "src_port": 52815, "dest_port": 5557}}'); INSERT INTO alerts VALUES(817,1772999761.704051017,'{"timestamp": "2026-03-08T20:56:01.704051+0100", "flow_id": 490603867612433, "event_type": "alert", "src_ip": "45.142.154.10", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 59, "bytes_toclient": 0, "start": "2026-03-08T20:56:01.704051+0100", "src_ip": "45.142.154.10", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 53}}'); INSERT INTO alerts VALUES(818,1772999761.704051017,'{"timestamp": "2026-03-08T20:56:01.704051+0100", "flow_id": 490603867612433, "event_type": "alert", "src_ip": "45.142.154.10", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2101616, "rev": 9, "signature": "GPL DNS named version attempt", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_07_26"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 59, "bytes_toclient": 0, "start": "2026-03-08T20:56:01.704051+0100", "src_ip": "45.142.154.10", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 53}}'); INSERT INTO alerts VALUES(819,1772999774.202770948,'{"timestamp": "2026-03-08T20:56:14.202771+0100", "flow_id": 1715321596757082, "event_type": "alert", "src_ip": "198.235.24.105", "src_port": 55382, "dest_ip": "185.254.126.122", "dest_port": 1250, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:56:14.202771+0100", "src_ip": "198.235.24.105", "dest_ip": "185.254.126.122", "src_port": 55382, "dest_port": 1250}}'); INSERT INTO alerts VALUES(820,1772999839.075119972,'{"timestamp": "2026-03-08T20:57:19.075120+0100", "flow_id": 2011490273020592, "event_type": "alert", "src_ip": "198.235.24.238", "src_port": 53809, "dest_ip": "185.254.126.122", "dest_port": 123, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ntp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-08T20:57:19.075120+0100", "src_ip": "198.235.24.238", "dest_ip": "185.254.126.122", "src_port": 53809, "dest_port": 123}}'); INSERT INTO alerts VALUES(821,1772999871.089874982,'{"timestamp": "2026-03-08T20:57:51.089875+0100", "flow_id": 2074862678654929, "event_type": "alert", "src_ip": "198.235.24.223", "src_port": 53636, "dest_ip": "185.254.126.122", "dest_port": 67, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T20:57:51.089875+0100", "src_ip": "198.235.24.223", "dest_ip": "185.254.126.122", "src_port": 53636, "dest_port": 67}}'); INSERT INTO alerts VALUES(822,1772999902.069303036,'{"timestamp": "2026-03-08T20:58:22.069303+0100", "flow_id": 1705030498171194, "event_type": "alert", "src_ip": "40.124.186.155", "src_port": 43488, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T20:58:22.069303+0100", "src_ip": "40.124.186.155", "dest_ip": "185.254.126.122", "src_port": 43488, "dest_port": 5432}}'); INSERT INTO alerts VALUES(823,1772999984.759182929,'{"timestamp": "2026-03-08T20:59:44.759183+0100", "flow_id": 164442659652049, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "185.254.126.122", "dest_port": 64011, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:59:44.759183+0100", "src_ip": "130.12.180.88", "dest_ip": "185.254.126.122", "src_port": 52302, "dest_port": 64011}}'); INSERT INTO alerts VALUES(824,1772999984.759182929,'{"timestamp": "2026-03-08T20:59:44.759183+0100", "flow_id": 164442659652049, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "185.254.126.122", "dest_port": 64011, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T20:59:44.759183+0100", "src_ip": "130.12.180.88", "dest_ip": "185.254.126.122", "src_port": 52302, "dest_port": 64011}}'); INSERT INTO alerts VALUES(825,1773000048.654906988,'{"timestamp": "2026-03-08T21:00:48.654907+0100", "flow_id": 279531090946643, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 59498, "dest_ip": "185.254.126.122", "dest_port": 19531, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:00:48.654907+0100", "src_ip": "79.124.62.134", "dest_ip": "185.254.126.122", "src_port": 59498, "dest_port": 19531}}'); INSERT INTO alerts VALUES(826,1773000210.430327892,'{"timestamp": "2026-03-08T21:03:30.430328+0100", "flow_id": 722347399142952, "event_type": "alert", "src_ip": "79.124.62.178", "src_port": 59409, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:03:30.430328+0100", "src_ip": "79.124.62.178", "dest_ip": "185.254.126.122", "src_port": 59409, "dest_port": 8080}}'); INSERT INTO alerts VALUES(827,1773000288.252847909,'{"timestamp": "2026-03-08T21:04:48.252848+0100", "flow_id": 241550508015729, "event_type": "alert", "src_ip": "204.76.203.17", "src_port": 47534, "dest_ip": "185.254.126.122", "dest_port": 27015, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 33, "bytes_toclient": 0, "start": "2026-03-08T21:04:48.252848+0100", "src_ip": "204.76.203.17", "dest_ip": "185.254.126.122", "src_port": 47534, "dest_port": 27015}}'); INSERT INTO alerts VALUES(828,1773000288.252847909,'{"timestamp": "2026-03-08T21:04:48.252848+0100", "flow_id": 241550508015729, "event_type": "alert", "src_ip": "204.76.203.17", "src_port": 47534, "dest_ip": "185.254.126.122", "dest_port": 27015, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 33, "bytes_toclient": 0, "start": "2026-03-08T21:04:48.252848+0100", "src_ip": "204.76.203.17", "dest_ip": "185.254.126.122", "src_port": 47534, "dest_port": 27015}}'); INSERT INTO alerts VALUES(829,1773000292.136373997,'{"timestamp": "2026-03-08T21:04:52.136374+0100", "flow_id": 1148675425279345, "event_type": "alert", "src_ip": "205.210.31.215", "src_port": 51337, "dest_ip": "185.254.126.122", "dest_port": 3052, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:04:52.136374+0100", "src_ip": "205.210.31.215", "dest_ip": "185.254.126.122", "src_port": 51337, "dest_port": 3052}}'); INSERT INTO alerts VALUES(830,1773000300.019522905,'{"timestamp": "2026-03-08T21:05:00.019523+0100", "flow_id": 1209752666807396, "event_type": "alert", "src_ip": "167.94.146.35", "src_port": 53508, "dest_ip": "185.254.126.122", "dest_port": 56133, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T21:05:00.019523+0100", "src_ip": "167.94.146.35", "dest_ip": "185.254.126.122", "src_port": 53508, "dest_port": 56133}}'); INSERT INTO alerts VALUES(831,1773000407.651220083,'{"timestamp": "2026-03-08T21:06:47.651220+0100", "flow_id": 2234021054670795, "event_type": "alert", "src_ip": "198.235.24.211", "src_port": 56775, "dest_ip": "185.254.126.122", "dest_port": 17185, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 92, "bytes_toclient": 0, "start": "2026-03-08T21:06:47.651220+0100", "src_ip": "198.235.24.211", "dest_ip": "185.254.126.122", "src_port": 56775, "dest_port": 17185}}'); INSERT INTO alerts VALUES(832,1773000436.150711059,'{"timestamp": "2026-03-08T21:07:16.150711+0100", "flow_id": 1210250103460335, "event_type": "alert", "src_ip": "176.65.139.31", "src_port": 55705, "dest_ip": "185.254.126.122", "dest_port": 389, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ldap", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-08T21:07:16.150711+0100", "src_ip": "176.65.139.31", "dest_ip": "185.254.126.122", "src_port": 55705, "dest_port": 389}}'); INSERT INTO alerts VALUES(833,1773000451.331151962,'{"timestamp": "2026-03-08T21:07:31.331152+0100", "flow_id": 859341020677356, "event_type": "alert", "src_ip": "193.163.125.34", "src_port": 43594, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:07:31.331152+0100", "src_ip": "193.163.125.34", "dest_ip": "185.254.126.122", "src_port": 43594, "dest_port": 5432}}'); INSERT INTO alerts VALUES(834,1773000451.331151962,'{"timestamp": "2026-03-08T21:07:31.331152+0100", "flow_id": 859341020677356, "event_type": "alert", "src_ip": "193.163.125.34", "src_port": 43594, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:07:31.331152+0100", "src_ip": "193.163.125.34", "dest_ip": "185.254.126.122", "src_port": 43594, "dest_port": 5432}}'); INSERT INTO alerts VALUES(835,1773000510.463222026,'{"timestamp": "2026-03-08T21:08:30.463222+0100", "flow_id": 1708052046650129, "event_type": "alert", "src_ip": "205.210.31.95", "src_port": 49623, "dest_ip": "185.254.126.122", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:08:30.463222+0100", "src_ip": "205.210.31.95", "dest_ip": "185.254.126.122", "src_port": 49623, "dest_port": 1521}}'); INSERT INTO alerts VALUES(836,1773000510.463222026,'{"timestamp": "2026-03-08T21:08:30.463222+0100", "flow_id": 1708052046650129, "event_type": "alert", "src_ip": "205.210.31.95", "src_port": 49623, "dest_ip": "185.254.126.122", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:08:30.463222+0100", "src_ip": "205.210.31.95", "dest_ip": "185.254.126.122", "src_port": 49623, "dest_port": 1521}}'); INSERT INTO alerts VALUES(837,1773000520.030508996,'{"timestamp": "2026-03-08T21:08:40.030509+0100", "flow_id": 131036094176599, "event_type": "alert", "src_ip": "205.210.31.94", "src_port": 49466, "dest_ip": "185.254.126.122", "dest_port": 10001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:08:40.030509+0100", "src_ip": "205.210.31.94", "dest_ip": "185.254.126.122", "src_port": 49466, "dest_port": 10001}}'); INSERT INTO alerts VALUES(838,1773000530.197624921,'{"timestamp": "2026-03-08T21:08:50.197625+0100", "flow_id": 567318368786509, "event_type": "alert", "src_ip": "88.210.63.193", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 29443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:08:50.197625+0100", "src_ip": "88.210.63.193", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 29443}}'); INSERT INTO alerts VALUES(839,1773000551.469527007,'{"timestamp": "2026-03-08T21:09:11.469527+0100", "flow_id": 2016604708692043, "event_type": "alert", "src_ip": "51.178.100.208", "src_port": 5180, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 447, "bytes_toclient": 0, "start": "2026-03-08T21:09:11.469527+0100", "src_ip": "51.178.100.208", "dest_ip": "185.254.126.122", "src_port": 5180, "dest_port": 5060}}'); INSERT INTO alerts VALUES(840,1773000551.469527007,'{"timestamp": "2026-03-08T21:09:11.469527+0100", "flow_id": 2016604708692043, "event_type": "alert", "src_ip": "51.178.100.208", "src_port": 5180, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 447, "bytes_toclient": 0, "start": "2026-03-08T21:09:11.469527+0100", "src_ip": "51.178.100.208", "dest_ip": "185.254.126.122", "src_port": 5180, "dest_port": 5060}}'); INSERT INTO alerts VALUES(841,1773000659.263525962,'{"timestamp": "2026-03-08T21:10:59.263526+0100", "flow_id": 850364483492739, "event_type": "alert", "src_ip": "198.235.24.85", "src_port": 51260, "dest_ip": "185.254.126.122", "dest_port": 5001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:10:59.263526+0100", "src_ip": "198.235.24.85", "dest_ip": "185.254.126.122", "src_port": 51260, "dest_port": 5001}}'); INSERT INTO alerts VALUES(842,1773000733.047740936,'{"timestamp": "2026-03-08T21:12:13.047741+0100", "flow_id": 1612423624813312, "event_type": "alert", "src_ip": "185.241.208.163", "src_port": 50251, "dest_ip": "185.254.126.122", "dest_port": 3390, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:12:13.047741+0100", "src_ip": "185.241.208.163", "dest_ip": "185.254.126.122", "src_port": 50251, "dest_port": 3390}}'); INSERT INTO alerts VALUES(843,1773000818.565634966,'{"timestamp": "2026-03-08T21:13:38.565635+0100", "flow_id": 740534096271342, "event_type": "alert", "src_ip": "147.185.132.51", "src_port": 53118, "dest_ip": "185.254.126.122", "dest_port": 12546, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-08T21:13:38.565635+0100", "src_ip": "147.185.132.51", "dest_ip": "185.254.126.122", "src_port": 53118, "dest_port": 12546}}'); INSERT INTO alerts VALUES(844,1773000887.417045116,'{"timestamp": "2026-03-08T21:14:47.417045+0100", "flow_id": 2072670395668856, "event_type": "alert", "src_ip": "198.235.24.104", "src_port": 50014, "dest_ip": "185.254.126.122", "dest_port": 2484, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:14:47.417045+0100", "src_ip": "198.235.24.104", "dest_ip": "185.254.126.122", "src_port": 50014, "dest_port": 2484}}'); INSERT INTO alerts VALUES(845,1773000899.952703953,'{"timestamp": "2026-03-08T21:14:59.952704+0100", "flow_id": 995611890817458, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 44376, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:14:59.952704+0100", "src_ip": "185.156.73.86", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 44376}}'); INSERT INTO alerts VALUES(846,1773000961.56694889,'{"timestamp": "2026-03-08T21:16:01.566949+0100", "flow_id": 464706509701053, "event_type": "alert", "src_ip": "167.94.138.109", "src_port": 36863, "dest_ip": "185.254.126.122", "dest_port": 57359, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T21:16:01.566949+0100", "src_ip": "167.94.138.109", "dest_ip": "185.254.126.122", "src_port": 36863, "dest_port": 57359}}'); INSERT INTO alerts VALUES(847,1773001012.592196941,'{"timestamp": "2026-03-08T21:16:52.592197+0100", "flow_id": 1136093980051970, "event_type": "alert", "src_ip": "198.235.24.246", "src_port": 55500, "dest_ip": "185.254.126.122", "dest_port": 8081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:16:52.592197+0100", "src_ip": "198.235.24.246", "dest_ip": "185.254.126.122", "src_port": 55500, "dest_port": 8081}}'); INSERT INTO alerts VALUES(848,1773001077.250709056,'{"timestamp": "2026-03-08T21:17:57.250709+0100", "flow_id": 1639740682245257, "event_type": "alert", "src_ip": "94.72.96.152", "src_port": 11983, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 437, "bytes_toclient": 0, "start": "2026-03-08T21:17:57.250709+0100", "src_ip": "94.72.96.152", "dest_ip": "185.254.126.122", "src_port": 11983, "dest_port": 5060}}'); INSERT INTO alerts VALUES(849,1773001077.250709056,'{"timestamp": "2026-03-08T21:17:57.250709+0100", "flow_id": 1639740682245257, "event_type": "alert", "src_ip": "94.72.96.152", "src_port": 11983, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 437, "bytes_toclient": 0, "start": "2026-03-08T21:17:57.250709+0100", "src_ip": "94.72.96.152", "dest_ip": "185.254.126.122", "src_port": 11983, "dest_port": 5060}}'); INSERT INTO alerts VALUES(850,1773001184.985579968,'{"timestamp": "2026-03-08T21:19:44.985580+0100", "flow_id": 10911952019887, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 2086, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:19:44.985580+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 2086}}'); INSERT INTO alerts VALUES(851,1773001184.985579968,'{"timestamp": "2026-03-08T21:19:44.985580+0100", "flow_id": 10911952019887, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 2086, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:19:44.985580+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 2086}}'); INSERT INTO alerts VALUES(852,1773001291.323080062,'{"timestamp": "2026-03-08T21:21:31.323080+0100", "flow_id": 1106144257797465, "event_type": "alert", "src_ip": "43.228.157.12", "src_port": 55402, "dest_ip": "185.254.126.122", "dest_port": 14822, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:21:31.323080+0100", "src_ip": "43.228.157.12", "dest_ip": "185.254.126.122", "src_port": 55402, "dest_port": 14822}}'); INSERT INTO alerts VALUES(853,1773001348.816839934,'{"timestamp": "2026-03-08T21:22:28.816840+0100", "flow_id": 1256502467926210, "event_type": "alert", "src_ip": "205.210.31.212", "src_port": 53789, "dest_ip": "185.254.126.122", "dest_port": 47001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:22:28.816840+0100", "src_ip": "205.210.31.212", "dest_ip": "185.254.126.122", "src_port": 53789, "dest_port": 47001}}'); INSERT INTO alerts VALUES(854,1773001444.17395711,'{"timestamp": "2026-03-08T21:24:04.173957+0100", "flow_id": 1310090952136629, "event_type": "alert", "src_ip": "185.242.226.33", "src_port": 44012, "dest_ip": "185.254.126.122", "dest_port": 587, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:24:04.173957+0100", "src_ip": "185.242.226.33", "dest_ip": "185.254.126.122", "src_port": 44012, "dest_port": 587}}'); INSERT INTO alerts VALUES(855,1773001463.76890397,'{"timestamp": "2026-03-08T21:24:23.768904+0100", "flow_id": 2176518673500987, "event_type": "alert", "src_ip": "147.185.132.40", "src_port": 53383, "dest_ip": "185.254.126.122", "dest_port": 5910, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:24:23.768904+0100", "src_ip": "147.185.132.40", "dest_ip": "185.254.126.122", "src_port": 53383, "dest_port": 5910}}'); INSERT INTO alerts VALUES(856,1773001498.4885149,'{"timestamp": "2026-03-08T21:24:58.488515+0100", "flow_id": 690783171567425, "event_type": "alert", "src_ip": "205.210.31.205", "src_port": 54094, "dest_ip": "185.254.126.122", "dest_port": 4506, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:24:58.488515+0100", "src_ip": "205.210.31.205", "dest_ip": "185.254.126.122", "src_port": 54094, "dest_port": 4506}}'); INSERT INTO alerts VALUES(857,1773001521.439667941,'{"timestamp": "2026-03-08T21:25:21.439668+0100", "flow_id": 480988356978230, "event_type": "alert", "src_ip": "64.89.163.82", "src_port": 41365, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:25:21.439668+0100", "src_ip": "64.89.163.82", "dest_ip": "185.254.126.122", "src_port": 41365, "dest_port": 5432}}'); INSERT INTO alerts VALUES(858,1773001521.439667941,'{"timestamp": "2026-03-08T21:25:21.439668+0100", "flow_id": 480988356978230, "event_type": "alert", "src_ip": "64.89.163.82", "src_port": 41365, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:25:21.439668+0100", "src_ip": "64.89.163.82", "dest_ip": "185.254.126.122", "src_port": 41365, "dest_port": 5432}}'); INSERT INTO alerts VALUES(859,1773001638.697171927,'{"timestamp": "2026-03-08T21:27:18.697172+0100", "flow_id": 1868435239802095, "event_type": "alert", "src_ip": "77.83.39.82", "src_port": 53386, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400008, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 9", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:27:18.697172+0100", "src_ip": "77.83.39.82", "dest_ip": "185.254.126.122", "src_port": 53386, "dest_port": 443}}'); INSERT INTO alerts VALUES(860,1773001676.775269032,'{"timestamp": "2026-03-08T21:27:56.775269+0100", "flow_id": 1359431671633563, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 58427, "dest_ip": "185.254.126.122", "dest_port": 12222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:27:56.775269+0100", "src_ip": "185.242.246.37", "dest_ip": "185.254.126.122", "src_port": 58427, "dest_port": 12222}}'); INSERT INTO alerts VALUES(861,1773001676.775269032,'{"timestamp": "2026-03-08T21:27:56.775269+0100", "flow_id": 1359431671633563, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 58427, "dest_ip": "185.254.126.122", "dest_port": 12222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:27:56.775269+0100", "src_ip": "185.242.246.37", "dest_ip": "185.254.126.122", "src_port": 58427, "dest_port": 12222}}'); INSERT INTO alerts VALUES(862,1773001740.444745063,'{"timestamp": "2026-03-08T21:29:00.444745+0100", "flow_id": 1347219033896759, "event_type": "alert", "src_ip": "45.142.154.99", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 9527, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:29:00.444745+0100", "src_ip": "45.142.154.99", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 9527}}'); INSERT INTO alerts VALUES(863,1773001828.102076054,'{"timestamp": "2026-03-08T21:30:28.102076+0100", "flow_id": 1282840970977878, "event_type": "alert", "src_ip": "167.94.146.33", "src_port": 41524, "dest_ip": "185.254.126.122", "dest_port": 43917, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T21:30:28.102076+0100", "src_ip": "167.94.146.33", "dest_ip": "185.254.126.122", "src_port": 41524, "dest_port": 43917}}'); INSERT INTO alerts VALUES(864,1773001875.949368953,'{"timestamp": "2026-03-08T21:31:15.949369+0100", "flow_id": 981286050465993, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 40549, "dest_ip": "185.254.126.122", "dest_port": 8082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:31:15.949369+0100", "src_ip": "185.242.246.38", "dest_ip": "185.254.126.122", "src_port": 40549, "dest_port": 8082}}'); INSERT INTO alerts VALUES(865,1773001875.949368953,'{"timestamp": "2026-03-08T21:31:15.949369+0100", "flow_id": 981286050465993, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 40549, "dest_ip": "185.254.126.122", "dest_port": 8082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:31:15.949369+0100", "src_ip": "185.242.246.38", "dest_ip": "185.254.126.122", "src_port": 40549, "dest_port": 8082}}'); INSERT INTO alerts VALUES(866,1773001878.015322923,'{"timestamp": "2026-03-08T21:31:18.015323+0100", "flow_id": 1754663350630532, "event_type": "alert", "src_ip": "87.121.84.72", "src_port": 50160, "dest_ip": "185.254.126.122", "dest_port": 119, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:31:18.015323+0100", "src_ip": "87.121.84.72", "dest_ip": "185.254.126.122", "src_port": 50160, "dest_port": 119}}'); INSERT INTO alerts VALUES(867,1773001879.805489064,'{"timestamp": "2026-03-08T21:31:19.805489+0100", "flow_id": 2052175000548871, "event_type": "alert", "src_ip": "167.94.138.193", "src_port": 24378, "dest_ip": "185.254.126.122", "dest_port": 8765, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T21:31:19.805489+0100", "src_ip": "167.94.138.193", "dest_ip": "185.254.126.122", "src_port": 24378, "dest_port": 8765}}'); INSERT INTO alerts VALUES(868,1773001925.547630072,'{"timestamp": "2026-03-08T21:32:05.547630+0100", "flow_id": 1507629578471698, "event_type": "alert", "src_ip": "147.185.132.210", "src_port": 57097, "dest_ip": "185.254.126.122", "dest_port": 40000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:32:05.547630+0100", "src_ip": "147.185.132.210", "dest_ip": "185.254.126.122", "src_port": 57097, "dest_port": 40000}}'); INSERT INTO alerts VALUES(869,1773001949.119525909,'{"timestamp": "2026-03-08T21:32:29.119526+0100", "flow_id": 1639260725615254, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 57202, "dest_ip": "185.254.126.122", "dest_port": 3462, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:32:29.119526+0100", "src_ip": "45.142.193.7", "dest_ip": "185.254.126.122", "src_port": 57202, "dest_port": 3462}}'); INSERT INTO alerts VALUES(870,1773002001.338432073,'{"timestamp": "2026-03-08T21:33:21.338432+0100", "flow_id": 327654744980200, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 58962, "dest_ip": "185.254.126.122", "dest_port": 9001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:33:21.338432+0100", "src_ip": "87.121.84.57", "dest_ip": "185.254.126.122", "src_port": 58962, "dest_port": 9001}}'); INSERT INTO alerts VALUES(871,1773002032.238178969,'{"timestamp": "2026-03-08T21:33:52.238179+0100", "flow_id": 178546516764162, "event_type": "alert", "src_ip": "205.210.31.203", "src_port": 56442, "dest_ip": "185.254.126.122", "dest_port": 2483, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:33:52.238179+0100", "src_ip": "205.210.31.203", "dest_ip": "185.254.126.122", "src_port": 56442, "dest_port": 2483}}'); INSERT INTO alerts VALUES(872,1773002122.575618983,'{"timestamp": "2026-03-08T21:35:22.575619+0100", "flow_id": 783418372770835, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 40097, "dest_ip": "185.254.126.122", "dest_port": 1010, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:35:22.575619+0100", "src_ip": "79.124.40.82", "dest_ip": "185.254.126.122", "src_port": 40097, "dest_port": 1010}}'); INSERT INTO alerts VALUES(873,1773002166.836678029,'{"timestamp": "2026-03-08T21:36:06.836678+0100", "flow_id": 1904655302515882, "event_type": "alert", "src_ip": "205.210.31.253", "src_port": 52454, "dest_ip": "185.254.126.122", "dest_port": 50070, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:36:06.836678+0100", "src_ip": "205.210.31.253", "dest_ip": "185.254.126.122", "src_port": 52454, "dest_port": 50070}}'); INSERT INTO alerts VALUES(874,1773002190.292949915,'{"timestamp": "2026-03-08T21:36:30.292950+0100", "flow_id": 1821164562903442, "event_type": "alert", "src_ip": "193.163.125.22", "src_port": 55884, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:36:30.292950+0100", "src_ip": "193.163.125.22", "dest_ip": "185.254.126.122", "src_port": 55884, "dest_port": 80}}'); INSERT INTO alerts VALUES(875,1773002254.208161115,'{"timestamp": "2026-03-08T21:37:34.208161+0100", "flow_id": 1738470543208034, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "185.254.126.122", "dest_port": 11789, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:37:34.208161+0100", "src_ip": "79.124.40.110", "dest_ip": "185.254.126.122", "src_port": 52537, "dest_port": 11789}}'); INSERT INTO alerts VALUES(876,1773002392.600368976,'{"timestamp": "2026-03-08T21:39:52.600369+0100", "flow_id": 45293110465325, "event_type": "alert", "src_ip": "198.235.24.89", "src_port": 49368, "dest_ip": "185.254.126.122", "dest_port": 8333, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:39:52.600369+0100", "src_ip": "198.235.24.89", "dest_ip": "185.254.126.122", "src_port": 49368, "dest_port": 8333}}'); INSERT INTO alerts VALUES(877,1773002394.567814112,'{"timestamp": "2026-03-08T21:39:54.567814+0100", "flow_id": 749893004004277, "event_type": "alert", "src_ip": "185.242.226.104", "src_port": 49832, "dest_ip": "185.254.126.122", "dest_port": 41528, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:39:54.567814+0100", "src_ip": "185.242.226.104", "dest_ip": "185.254.126.122", "src_port": 49832, "dest_port": 41528}}'); INSERT INTO alerts VALUES(878,1773002402.101422072,'{"timestamp": "2026-03-08T21:40:02.101422+0100", "flow_id": 717082715551080, "event_type": "alert", "src_ip": "144.126.233.152", "src_port": 61006, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:40:02.101422+0100", "src_ip": "144.126.233.152", "dest_ip": "185.254.126.122", "src_port": 61006, "dest_port": 3306}}'); INSERT INTO alerts VALUES(879,1773002411.549103975,'{"timestamp": "2026-03-08T21:40:11.549104+0100", "flow_id": 951011467812325, "event_type": "alert", "src_ip": "185.156.73.182", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 501, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:40:11.549104+0100", "src_ip": "185.156.73.182", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 501}}'); INSERT INTO alerts VALUES(880,1773002415.857724906,'{"timestamp": "2026-03-08T21:40:15.857725+0100", "flow_id": 1995051867670584, "event_type": "alert", "src_ip": "176.65.134.20", "src_port": 36682, "dest_ip": "185.254.126.122", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:40:15.857725+0100", "src_ip": "176.65.134.20", "dest_ip": "185.254.126.122", "src_port": 36682, "dest_port": 443}}'); INSERT INTO alerts VALUES(881,1773002460.147497893,'{"timestamp": "2026-03-08T21:41:00.147498+0100", "flow_id": 1196452250925535, "event_type": "alert", "src_ip": "193.163.125.19", "src_port": 50032, "dest_ip": "185.254.126.122", "dest_port": 20303, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:41:00.147498+0100", "src_ip": "193.163.125.19", "dest_ip": "185.254.126.122", "src_port": 50032, "dest_port": 20303}}'); INSERT INTO alerts VALUES(882,1773002518.835189104,'{"timestamp": "2026-03-08T21:41:58.835189+0100", "flow_id": 1898262885654006, "event_type": "alert", "src_ip": "205.210.31.202", "src_port": 52947, "dest_ip": "185.254.126.122", "dest_port": 30083, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:41:58.835189+0100", "src_ip": "205.210.31.202", "dest_ip": "185.254.126.122", "src_port": 52947, "dest_port": 30083}}'); INSERT INTO alerts VALUES(883,1773002649.100522041,'{"timestamp": "2026-03-08T21:44:09.100522+0100", "flow_id": 431742319992047, "event_type": "alert", "src_ip": "167.94.146.44", "src_port": 55981, "dest_ip": "185.254.126.122", "dest_port": 52087, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T21:44:09.100522+0100", "src_ip": "167.94.146.44", "dest_ip": "185.254.126.122", "src_port": 55981, "dest_port": 52087}}'); INSERT INTO alerts VALUES(884,1773002667.695337057,'{"timestamp": "2026-03-08T21:44:27.695337+0100", "flow_id": 1016126382441745, "event_type": "alert", "src_ip": "198.235.24.196", "src_port": 50238, "dest_ip": "185.254.126.122", "dest_port": 49502, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:44:27.695337+0100", "src_ip": "198.235.24.196", "dest_ip": "185.254.126.122", "src_port": 50238, "dest_port": 49502}}'); INSERT INTO alerts VALUES(885,1773002755.655056953,'{"timestamp": "2026-03-08T21:45:55.655057+0100", "flow_id": 1124601928877673, "event_type": "alert", "src_ip": "147.185.132.97", "src_port": 52543, "dest_ip": "185.254.126.122", "dest_port": 1443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:45:55.655057+0100", "src_ip": "147.185.132.97", "dest_ip": "185.254.126.122", "src_port": 52543, "dest_port": 1443}}'); INSERT INTO alerts VALUES(886,1773002770.207225085,'{"timestamp": "2026-03-08T21:46:10.207225+0100", "flow_id": 608551145288114, "event_type": "alert", "src_ip": "176.65.148.2", "src_port": 57175, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:46:10.207225+0100", "src_ip": "176.65.148.2", "dest_ip": "185.254.126.122", "src_port": 57175, "dest_port": 8080}}'); INSERT INTO alerts VALUES(887,1773002770.207225085,'{"timestamp": "2026-03-08T21:46:10.207225+0100", "flow_id": 608551145288114, "event_type": "alert", "src_ip": "176.65.148.2", "src_port": 57175, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:46:10.207225+0100", "src_ip": "176.65.148.2", "dest_ip": "185.254.126.122", "src_port": 57175, "dest_port": 8080}}'); INSERT INTO alerts VALUES(888,1773002779.748446942,'{"timestamp": "2026-03-08T21:46:19.748447+0100", "flow_id": 962758160838117, "event_type": "alert", "src_ip": "167.94.138.146", "src_port": 29867, "dest_ip": "185.254.126.122", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-08T21:46:19.748447+0100", "src_ip": "167.94.138.146", "dest_ip": "185.254.126.122", "src_port": 29867, "dest_port": 53}}'); INSERT INTO alerts VALUES(889,1773002848.435897111,'{"timestamp": "2026-03-08T21:47:28.435897+0100", "flow_id": 183314722659302, "event_type": "alert", "src_ip": "167.94.146.77", "src_port": 58726, "dest_ip": "185.254.126.122", "dest_port": 31389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T21:47:28.435897+0100", "src_ip": "167.94.146.77", "dest_ip": "185.254.126.122", "src_port": 58726, "dest_port": 31389}}'); INSERT INTO alerts VALUES(890,1773002850.275755882,'{"timestamp": "2026-03-08T21:47:30.275756+0100", "flow_id": 621414242167446, "event_type": "alert", "src_ip": "64.95.96.69", "src_port": 5186, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 433, "bytes_toclient": 0, "start": "2026-03-08T21:47:30.275756+0100", "src_ip": "64.95.96.69", "dest_ip": "185.254.126.122", "src_port": 5186, "dest_port": 5060}}'); INSERT INTO alerts VALUES(891,1773002850.275755882,'{"timestamp": "2026-03-08T21:47:30.275756+0100", "flow_id": 621414242167446, "event_type": "alert", "src_ip": "64.95.96.69", "src_port": 5186, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 433, "bytes_toclient": 0, "start": "2026-03-08T21:47:30.275756+0100", "src_ip": "64.95.96.69", "dest_ip": "185.254.126.122", "src_port": 5186, "dest_port": 5060}}'); INSERT INTO alerts VALUES(892,1773002891.92916298,'{"timestamp": "2026-03-08T21:48:11.929163+0100", "flow_id": 894500368299770, "event_type": "alert", "src_ip": "87.121.84.35", "src_port": 60001, "dest_ip": "185.254.126.122", "dest_port": 22140, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:48:11.929163+0100", "src_ip": "87.121.84.35", "dest_ip": "185.254.126.122", "src_port": 60001, "dest_port": 22140}}'); INSERT INTO alerts VALUES(893,1773002894.457967996,'{"timestamp": "2026-03-08T21:48:14.457968+0100", "flow_id": 1966961269001379, "event_type": "alert", "src_ip": "91.224.92.177", "src_port": 50351, "dest_ip": "185.254.126.122", "dest_port": 4001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:48:14.457968+0100", "src_ip": "91.224.92.177", "dest_ip": "185.254.126.122", "src_port": 50351, "dest_port": 4001}}'); INSERT INTO alerts VALUES(894,1773002949.910089015,'{"timestamp": "2026-03-08T21:49:09.910089+0100", "flow_id": 1657005950707951, "event_type": "alert", "src_ip": "64.95.96.68", "src_port": 5171, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 433, "bytes_toclient": 0, "start": "2026-03-08T21:49:09.910089+0100", "src_ip": "64.95.96.68", "dest_ip": "185.254.126.122", "src_port": 5171, "dest_port": 5060}}'); INSERT INTO alerts VALUES(895,1773002949.910089015,'{"timestamp": "2026-03-08T21:49:09.910089+0100", "flow_id": 1657005950707951, "event_type": "alert", "src_ip": "64.95.96.68", "src_port": 5171, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 433, "bytes_toclient": 0, "start": "2026-03-08T21:49:09.910089+0100", "src_ip": "64.95.96.68", "dest_ip": "185.254.126.122", "src_port": 5171, "dest_port": 5060}}'); INSERT INTO alerts VALUES(896,1773003019.665338993,'{"timestamp": "2026-03-08T21:50:19.665339+0100", "flow_id": 887287078027950, "event_type": "alert", "src_ip": "198.235.24.125", "src_port": 54968, "dest_ip": "185.254.126.122", "dest_port": 8443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:50:19.665339+0100", "src_ip": "198.235.24.125", "dest_ip": "185.254.126.122", "src_port": 54968, "dest_port": 8443}}'); INSERT INTO alerts VALUES(897,1773003095.670413018,'{"timestamp": "2026-03-08T21:51:35.670413+0100", "flow_id": 2034977853898582, "event_type": "alert", "src_ip": "147.185.132.183", "src_port": 50891, "dest_ip": "185.254.126.122", "dest_port": 4800, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 36, "bytes_toclient": 0, "start": "2026-03-08T21:51:35.670413+0100", "src_ip": "147.185.132.183", "dest_ip": "185.254.126.122", "src_port": 50891, "dest_port": 4800}}'); INSERT INTO alerts VALUES(898,1773003171.093499899,'{"timestamp": "2026-03-08T21:52:51.093500+0100", "flow_id": 964531418258600, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59755, "dest_ip": "185.254.126.122", "dest_port": 55830, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:52:51.093500+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59755, "dest_port": 55830}}'); INSERT INTO alerts VALUES(899,1773003171.093499899,'{"timestamp": "2026-03-08T21:52:51.093500+0100", "flow_id": 964531418258600, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59755, "dest_ip": "185.254.126.122", "dest_port": 55830, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:52:51.093500+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59755, "dest_port": 55830}}'); INSERT INTO alerts VALUES(900,1773003218.66376996,'{"timestamp": "2026-03-08T21:53:38.663770+0100", "flow_id": 599071415151565, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 56443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:53:38.663770+0100", "src_ip": "88.210.63.69", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 56443}}'); INSERT INTO alerts VALUES(901,1773003343.317548036,'{"timestamp": "2026-03-08T21:55:43.317548+0100", "flow_id": 2208286976710779, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54911, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2026888, "rev": 4, "signature": "ET INFO DNS Query for Suspicious .icu Domain", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["Medium"], "created_at": ["2019_02_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_11_21"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29028, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "prreqcroab.icu", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T21:55:43.317548+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54911, "dest_port": 53}}'); INSERT INTO alerts VALUES(902,1773003354.570373059,'{"timestamp": "2026-03-08T21:55:54.570373+0100", "flow_id": 760884338336727, "event_type": "alert", "src_ip": "198.235.24.202", "src_port": 50246, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:55:54.570373+0100", "src_ip": "198.235.24.202", "dest_ip": "185.254.126.122", "src_port": 50246, "dest_port": 8080}}'); INSERT INTO alerts VALUES(903,1773003413.995872975,'{"timestamp": "2026-03-08T21:56:53.995873+0100", "flow_id": 1462495679305558, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 58456, "dest_ip": "185.254.126.122", "dest_port": 64479, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:56:53.995873+0100", "src_ip": "79.124.62.230", "dest_ip": "185.254.126.122", "src_port": 58456, "dest_port": 64479}}'); INSERT INTO alerts VALUES(904,1773003433.254703998,'{"timestamp": "2026-03-08T21:57:13.254704+0100", "flow_id": 530997271350417, "event_type": "alert", "src_ip": "205.210.31.230", "src_port": 51046, "dest_ip": "185.254.126.122", "dest_port": 23956, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:57:13.254704+0100", "src_ip": "205.210.31.230", "dest_ip": "185.254.126.122", "src_port": 51046, "dest_port": 23956}}'); INSERT INTO alerts VALUES(905,1773003484.635397911,'{"timestamp": "2026-03-08T21:58:04.635398+0100", "flow_id": 1321642489412512, "event_type": "alert", "src_ip": "167.94.146.47", "src_port": 18052, "dest_ip": "185.254.126.122", "dest_port": 2338, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T21:58:04.635398+0100", "src_ip": "167.94.146.47", "dest_ip": "185.254.126.122", "src_port": 18052, "dest_port": 2338}}'); INSERT INTO alerts VALUES(906,1773003494.241405963,'{"timestamp": "2026-03-08T21:58:14.241406+0100", "flow_id": 1881258402209316, "event_type": "alert", "src_ip": "89.248.163.200", "src_port": 40616, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T21:58:14.241406+0100", "src_ip": "89.248.163.200", "dest_ip": "185.254.126.122", "src_port": 40616, "dest_port": 5432}}'); INSERT INTO alerts VALUES(907,1773003531.64944005,'{"timestamp": "2026-03-08T21:58:51.649440+0100", "flow_id": 1100475142496223, "event_type": "alert", "src_ip": "64.89.163.244", "src_port": 43520, "dest_ip": "185.254.126.122", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:58:51.649440+0100", "src_ip": "64.89.163.244", "dest_ip": "185.254.126.122", "src_port": 43520, "dest_port": 27017}}'); INSERT INTO alerts VALUES(908,1773003543.653235913,'{"timestamp": "2026-03-08T21:59:03.653236+0100", "flow_id": 2242677341586102, "event_type": "alert", "src_ip": "205.210.31.245", "src_port": 51469, "dest_ip": "185.254.126.122", "dest_port": 50003, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T21:59:03.653236+0100", "src_ip": "205.210.31.245", "dest_ip": "185.254.126.122", "src_port": 51469, "dest_port": 50003}}'); INSERT INTO alerts VALUES(909,1773003670.707717895,'{"timestamp": "2026-03-08T22:01:10.707718+0100", "flow_id": 1913726095547699, "event_type": "alert", "src_ip": "147.185.132.60", "src_port": 53415, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:01:10.707718+0100", "src_ip": "147.185.132.60", "dest_ip": "185.254.126.122", "src_port": 53415, "dest_port": 8080}}'); INSERT INTO alerts VALUES(910,1773003707.49413395,'{"timestamp": "2026-03-08T22:01:47.494134+0100", "flow_id": 996391076238493, "event_type": "alert", "src_ip": "176.65.148.45", "src_port": 59161, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:01:47.494134+0100", "src_ip": "176.65.148.45", "dest_ip": "185.254.126.122", "src_port": 59161, "dest_port": 8080}}'); INSERT INTO alerts VALUES(911,1773003707.49413395,'{"timestamp": "2026-03-08T22:01:47.494134+0100", "flow_id": 996391076238493, "event_type": "alert", "src_ip": "176.65.148.45", "src_port": 59161, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:01:47.494134+0100", "src_ip": "176.65.148.45", "dest_ip": "185.254.126.122", "src_port": 59161, "dest_port": 8080}}'); INSERT INTO alerts VALUES(912,1773003714.757635116,'{"timestamp": "2026-03-08T22:01:54.757635+0100", "flow_id": 720744136707859, "event_type": "alert", "src_ip": "205.210.31.97", "src_port": 52894, "dest_ip": "185.254.126.122", "dest_port": 137, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-08T22:01:54.757635+0100", "src_ip": "205.210.31.97", "dest_ip": "185.254.126.122", "src_port": 52894, "dest_port": 137}}'); INSERT INTO alerts VALUES(913,1773003739.778945923,'{"timestamp": "2026-03-08T22:02:19.778946+0100", "flow_id": 1093749354203016, "event_type": "alert", "src_ip": "195.184.76.156", "src_port": 536, "dest_ip": "185.254.126.122", "dest_port": 5800, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:02:19.778946+0100", "src_ip": "195.184.76.156", "dest_ip": "185.254.126.122", "src_port": 536, "dest_port": 5800}}'); INSERT INTO alerts VALUES(914,1773003787.215955972,'{"timestamp": "2026-03-08T22:03:07.215956+0100", "flow_id": 927527532171640, "event_type": "alert", "src_ip": "198.235.24.37", "src_port": 51694, "dest_ip": "185.254.126.122", "dest_port": 5907, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:03:07.215956+0100", "src_ip": "198.235.24.37", "dest_ip": "185.254.126.122", "src_port": 51694, "dest_port": 5907}}'); INSERT INTO alerts VALUES(915,1773003813.072511912,'{"timestamp": "2026-03-08T22:03:33.072512+0100", "flow_id": 1437340261133197, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 59325, "dest_ip": "185.254.126.122", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T22:03:33.072512+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 59325, "dest_port": 8332}}'); INSERT INTO alerts VALUES(916,1773003813.072511912,'{"timestamp": "2026-03-08T22:03:33.072512+0100", "flow_id": 1437340261133197, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 59325, "dest_ip": "185.254.126.122", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T22:03:33.072512+0100", "src_ip": "204.76.203.56", "dest_ip": "185.254.126.122", "src_port": 59325, "dest_port": 8332}}'); INSERT INTO alerts VALUES(917,1773003826.021477937,'{"timestamp": "2026-03-08T22:03:46.021478+0100", "flow_id": 655198719638203, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "185.254.126.122", "dest_port": 54192, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:03:46.021478+0100", "src_ip": "130.12.180.88", "dest_ip": "185.254.126.122", "src_port": 52302, "dest_port": 54192}}'); INSERT INTO alerts VALUES(918,1773003826.021477937,'{"timestamp": "2026-03-08T22:03:46.021478+0100", "flow_id": 655198719638203, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "185.254.126.122", "dest_port": 54192, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:03:46.021478+0100", "src_ip": "130.12.180.88", "dest_ip": "185.254.126.122", "src_port": 52302, "dest_port": 54192}}'); INSERT INTO alerts VALUES(919,1773003846.940499067,'{"timestamp": "2026-03-08T22:04:06.940499+0100", "flow_id": 1787613101843923, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 59498, "dest_ip": "185.254.126.122", "dest_port": 8412, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:04:06.940499+0100", "src_ip": "79.124.62.134", "dest_ip": "185.254.126.122", "src_port": 59498, "dest_port": 8412}}'); INSERT INTO alerts VALUES(920,1773003858.86244893,'{"timestamp": "2026-03-08T22:04:18.862449+0100", "flow_id": 607968129614838, "event_type": "alert", "src_ip": "205.210.31.217", "src_port": 51971, "dest_ip": "185.254.126.122", "dest_port": 8445, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:04:18.862449+0100", "src_ip": "205.210.31.217", "dest_ip": "185.254.126.122", "src_port": 51971, "dest_port": 8445}}'); INSERT INTO alerts VALUES(921,1773003896.574719906,'{"timestamp": "2026-03-08T22:04:56.574720+0100", "flow_id": 216607671397106, "event_type": "alert", "src_ip": "45.156.87.91", "src_port": 54243, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:04:56.574720+0100", "src_ip": "45.156.87.91", "dest_ip": "185.254.126.122", "src_port": 54243, "dest_port": 8080}}'); INSERT INTO alerts VALUES(922,1773003966.068377971,'{"timestamp": "2026-03-08T22:06:06.068378+0100", "flow_id": 1701056545358585, "event_type": "alert", "src_ip": "167.94.146.38", "src_port": 40742, "dest_ip": "185.254.126.122", "dest_port": 3981, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:06:06.068378+0100", "src_ip": "167.94.146.38", "dest_ip": "185.254.126.122", "src_port": 40742, "dest_port": 3981}}'); INSERT INTO alerts VALUES(923,1773003991.165781021,'{"timestamp": "2026-03-08T22:06:31.165781+0100", "flow_id": 2119402425058856, "event_type": "alert", "src_ip": "66.132.153.158", "src_port": 17279, "dest_ip": "185.254.126.122", "dest_port": 5901, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:06:31.165781+0100", "src_ip": "66.132.153.158", "dest_ip": "185.254.126.122", "src_port": 17279, "dest_port": 5901}}'); INSERT INTO alerts VALUES(924,1773004068.069283009,'{"timestamp": "2026-03-08T22:07:48.069283+0100", "flow_id": 1141993909369896, "event_type": "alert", "src_ip": "205.210.31.102", "src_port": 52554, "dest_ip": "185.254.126.122", "dest_port": 8090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:07:48.069283+0100", "src_ip": "205.210.31.102", "dest_ip": "185.254.126.122", "src_port": 52554, "dest_port": 8090}}'); INSERT INTO alerts VALUES(925,1773004092.562730073,'{"timestamp": "2026-03-08T22:08:12.562730+0100", "flow_id": 1291008270493738, "event_type": "alert", "src_ip": "195.184.76.148", "src_port": 31920, "dest_ip": "185.254.126.122", "dest_port": 541, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:08:12.562730+0100", "src_ip": "195.184.76.148", "dest_ip": "185.254.126.122", "src_port": 31920, "dest_port": 541}}'); INSERT INTO alerts VALUES(926,1773004128.827397109,'{"timestamp": "2026-03-08T22:08:48.827397+0100", "flow_id": 175944015512600, "event_type": "alert", "src_ip": "167.94.146.36", "src_port": 50376, "dest_ip": "185.254.126.122", "dest_port": 20189, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:08:48.827397+0100", "src_ip": "167.94.146.36", "dest_ip": "185.254.126.122", "src_port": 50376, "dest_port": 20189}}'); INSERT INTO alerts VALUES(927,1773004139.94330597,'{"timestamp": "2026-03-08T22:08:59.943306+0100", "flow_id": 955246164285355, "event_type": "alert", "src_ip": "205.210.31.75", "src_port": 52241, "dest_ip": "185.254.126.122", "dest_port": 58000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:08:59.943306+0100", "src_ip": "205.210.31.75", "dest_ip": "185.254.126.122", "src_port": 52241, "dest_port": 58000}}'); INSERT INTO alerts VALUES(928,1773004316.416183949,'{"timestamp": "2026-03-08T22:11:56.416184+0100", "flow_id": 1224549352463426, "event_type": "alert", "src_ip": "167.94.146.35", "src_port": 36456, "dest_ip": "185.254.126.122", "dest_port": 10465, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:11:56.416184+0100", "src_ip": "167.94.146.35", "dest_ip": "185.254.126.122", "src_port": 36456, "dest_port": 10465}}'); INSERT INTO alerts VALUES(929,1773004332.686954021,'{"timestamp": "2026-03-08T22:12:12.686954+0100", "flow_id": 1261596835044305, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 54954, "dest_ip": "185.254.126.122", "dest_port": 18080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:12:12.686954+0100", "src_ip": "193.142.146.230", "dest_ip": "185.254.126.122", "src_port": 54954, "dest_port": 18080}}'); INSERT INTO alerts VALUES(930,1773004334.369297028,'{"timestamp": "2026-03-08T22:12:14.369297+0100", "flow_id": 1867597445075942, "event_type": "alert", "src_ip": "206.189.202.0", "src_port": 36032, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:12:14.369297+0100", "src_ip": "206.189.202.0", "dest_ip": "185.254.126.122", "src_port": 36032, "dest_port": 1433}}'); INSERT INTO alerts VALUES(931,1773004387.516123057,'{"timestamp": "2026-03-08T22:13:07.516123+0100", "flow_id": 1090832703381184, "event_type": "alert", "src_ip": "198.235.24.105", "src_port": 51022, "dest_ip": "185.254.126.122", "dest_port": 68, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:13:07.516123+0100", "src_ip": "198.235.24.105", "dest_ip": "185.254.126.122", "src_port": 51022, "dest_port": 68}}'); INSERT INTO alerts VALUES(932,1773004456.927016019,'{"timestamp": "2026-03-08T22:14:16.927016+0100", "flow_id": 40857444730707, "event_type": "alert", "src_ip": "205.210.31.213", "src_port": 52546, "dest_ip": "185.254.126.122", "dest_port": 139, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:14:16.927016+0100", "src_ip": "205.210.31.213", "dest_ip": "185.254.126.122", "src_port": 52546, "dest_port": 139}}'); INSERT INTO alerts VALUES(933,1773004506.969816923,'{"timestamp": "2026-03-08T22:15:06.969817+0100", "flow_id": 787633752128804, "event_type": "alert", "src_ip": "176.65.149.234", "src_port": 59053, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:15:06.969817+0100", "src_ip": "176.65.149.234", "dest_ip": "185.254.126.122", "src_port": 59053, "dest_port": 80}}'); INSERT INTO alerts VALUES(934,1773004509.961007118,'{"timestamp": "2026-03-08T22:15:09.961007+0100", "flow_id": 1594222910805924, "event_type": "alert", "src_ip": "176.65.139.12", "src_port": 41926, "dest_ip": "185.254.126.122", "dest_port": 17000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:15:09.961007+0100", "src_ip": "176.65.139.12", "dest_ip": "185.254.126.122", "src_port": 41926, "dest_port": 17000}}'); INSERT INTO alerts VALUES(935,1773004763.560708046,'{"timestamp": "2026-03-08T22:19:23.560708+0100", "flow_id": 1000849792610588, "event_type": "alert", "src_ip": "205.210.31.221", "src_port": 51671, "dest_ip": "185.254.126.122", "dest_port": 20000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:19:23.560708+0100", "src_ip": "205.210.31.221", "dest_ip": "185.254.126.122", "src_port": 51671, "dest_port": 20000}}'); INSERT INTO alerts VALUES(936,1773004780.319046974,'{"timestamp": "2026-03-08T22:19:40.319047+0100", "flow_id": 1370296865767757, "event_type": "alert", "src_ip": "193.163.125.32", "src_port": 49382, "dest_ip": "185.254.126.122", "dest_port": 20247, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:19:40.319047+0100", "src_ip": "193.163.125.32", "dest_ip": "185.254.126.122", "src_port": 49382, "dest_port": 20247}}'); INSERT INTO alerts VALUES(937,1773004800.559807062,'{"timestamp": "2026-03-08T22:20:00.559807+0100", "flow_id": 152556404128371, "event_type": "alert", "src_ip": "45.153.34.187", "src_port": 42764, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:20:00.559807+0100", "src_ip": "45.153.34.187", "dest_ip": "185.254.126.122", "src_port": 42764, "dest_port": 80}}'); INSERT INTO alerts VALUES(938,1773004862.382163047,'{"timestamp": "2026-03-08T22:21:02.382163+0100", "flow_id": 1922854051334850, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 58556, "dest_ip": "185.254.126.122", "dest_port": 24299, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:21:02.382163+0100", "src_ip": "167.94.146.40", "dest_ip": "185.254.126.122", "src_port": 58556, "dest_port": 24299}}'); INSERT INTO alerts VALUES(939,1773004862.523571014,'{"timestamp": "2026-03-08T22:21:02.523571+0100", "flow_id": 1967247949100084, "event_type": "alert", "src_ip": "15.204.54.13", "src_port": 62250, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 445, "bytes_toclient": 0, "start": "2026-03-08T22:21:02.523571+0100", "src_ip": "15.204.54.13", "dest_ip": "185.254.126.122", "src_port": 62250, "dest_port": 5060}}'); INSERT INTO alerts VALUES(940,1773004862.523571014,'{"timestamp": "2026-03-08T22:21:02.523571+0100", "flow_id": 1967247949100084, "event_type": "alert", "src_ip": "15.204.54.13", "src_port": 62250, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 445, "bytes_toclient": 0, "start": "2026-03-08T22:21:02.523571+0100", "src_ip": "15.204.54.13", "dest_ip": "185.254.126.122", "src_port": 62250, "dest_port": 5060}}'); INSERT INTO alerts VALUES(941,1773004958.055551052,'{"timestamp": "2026-03-08T22:22:38.055551+0100", "flow_id": 1927440931164495, "event_type": "alert", "src_ip": "198.235.24.216", "src_port": 55570, "dest_ip": "185.254.126.122", "dest_port": 8015, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:22:38.055551+0100", "src_ip": "198.235.24.216", "dest_ip": "185.254.126.122", "src_port": 55570, "dest_port": 8015}}'); INSERT INTO alerts VALUES(942,1773005046.768431901,'{"timestamp": "2026-03-08T22:24:06.768432+0100", "flow_id": 1893017081101774, "event_type": "alert", "src_ip": "167.94.146.68", "src_port": 11611, "dest_ip": "185.254.126.122", "dest_port": 24948, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:24:06.768432+0100", "src_ip": "167.94.146.68", "dest_ip": "185.254.126.122", "src_port": 11611, "dest_port": 24948}}'); INSERT INTO alerts VALUES(943,1773005067.563940049,'{"timestamp": "2026-03-08T22:24:27.563940+0100", "flow_id": 1014730300635945, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 9072, "dest_ip": "185.254.126.122", "dest_port": 50653, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:24:27.563940+0100", "src_ip": "167.94.146.32", "dest_ip": "185.254.126.122", "src_port": 9072, "dest_port": 50653}}'); INSERT INTO alerts VALUES(944,1773005085.546555043,'{"timestamp": "2026-03-08T22:24:45.546555+0100", "flow_id": 1503011768814637, "event_type": "alert", "src_ip": "147.185.132.103", "src_port": 56950, "dest_ip": "185.254.126.122", "dest_port": 5353, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "mdns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 74, "bytes_toclient": 0, "start": "2026-03-08T22:24:45.546555+0100", "src_ip": "147.185.132.103", "dest_ip": "185.254.126.122", "src_port": 56950, "dest_port": 5353}}'); INSERT INTO alerts VALUES(945,1773005141.208935022,'{"timestamp": "2026-03-08T22:25:41.208935+0100", "flow_id": 1460322204544004, "event_type": "alert", "src_ip": "130.12.180.52", "src_port": 59044, "dest_ip": "185.254.126.122", "dest_port": 9090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:25:41.208935+0100", "src_ip": "130.12.180.52", "dest_ip": "185.254.126.122", "src_port": 59044, "dest_port": 9090}}'); INSERT INTO alerts VALUES(946,1773005141.208935022,'{"timestamp": "2026-03-08T22:25:41.208935+0100", "flow_id": 1460322204544004, "event_type": "alert", "src_ip": "130.12.180.52", "src_port": 59044, "dest_ip": "185.254.126.122", "dest_port": 9090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:25:41.208935+0100", "src_ip": "130.12.180.52", "dest_ip": "185.254.126.122", "src_port": 59044, "dest_port": 9090}}'); INSERT INTO alerts VALUES(947,1773005151.189318896,'{"timestamp": "2026-03-08T22:25:51.189319+0100", "flow_id": 2220497972334334, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 51186, "dest_ip": "185.254.126.122", "dest_port": 10602, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:25:51.189319+0100", "src_ip": "167.94.146.37", "dest_ip": "185.254.126.122", "src_port": 51186, "dest_port": 10602}}'); INSERT INTO alerts VALUES(948,1773005214.168171882,'{"timestamp": "2026-03-08T22:26:54.168172+0100", "flow_id": 1848193548369988, "event_type": "alert", "src_ip": "198.235.24.104", "src_port": 55051, "dest_ip": "185.254.126.122", "dest_port": 50067, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:26:54.168172+0100", "src_ip": "198.235.24.104", "dest_ip": "185.254.126.122", "src_port": 55051, "dest_port": 50067}}'); INSERT INTO alerts VALUES(949,1773005237.532979966,'{"timestamp": "2026-03-08T22:27:17.532980+0100", "flow_id": 1444708829725067, "event_type": "alert", "src_ip": "147.185.132.204", "src_port": 49881, "dest_ip": "185.254.126.122", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:27:17.532980+0100", "src_ip": "147.185.132.204", "dest_ip": "185.254.126.122", "src_port": 49881, "dest_port": 1521}}'); INSERT INTO alerts VALUES(950,1773005237.532979966,'{"timestamp": "2026-03-08T22:27:17.532980+0100", "flow_id": 1444708829725067, "event_type": "alert", "src_ip": "147.185.132.204", "src_port": 49881, "dest_ip": "185.254.126.122", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:27:17.532980+0100", "src_ip": "147.185.132.204", "dest_ip": "185.254.126.122", "src_port": 49881, "dest_port": 1521}}'); INSERT INTO alerts VALUES(951,1773005309.848690032,'{"timestamp": "2026-03-08T22:28:29.848690+0100", "flow_id": 1674772314498718, "event_type": "alert", "src_ip": "162.217.98.180", "src_port": 53388, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 413, "bytes_toclient": 0, "start": "2026-03-08T22:28:29.848690+0100", "src_ip": "162.217.98.180", "dest_ip": "185.254.126.122", "src_port": 53388, "dest_port": 5060}}'); INSERT INTO alerts VALUES(952,1773005322.676182986,'{"timestamp": "2026-03-08T22:28:42.676183+0100", "flow_id": 652384333363664, "event_type": "alert", "src_ip": "205.210.31.85", "src_port": 54852, "dest_ip": "185.254.126.122", "dest_port": 5903, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:28:42.676183+0100", "src_ip": "205.210.31.85", "dest_ip": "185.254.126.122", "src_port": 54852, "dest_port": 5903}}'); INSERT INTO alerts VALUES(953,1773005347.093836069,'{"timestamp": "2026-03-08T22:29:07.093836+0100", "flow_id": 965973732574379, "event_type": "alert", "src_ip": "45.142.154.87", "src_port": 58914, "dest_ip": "185.254.126.122", "dest_port": 3113, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:29:07.093836+0100", "src_ip": "45.142.154.87", "dest_ip": "185.254.126.122", "src_port": 58914, "dest_port": 3113}}'); INSERT INTO alerts VALUES(954,1773005375.656471968,'{"timestamp": "2026-03-08T22:29:35.656472+0100", "flow_id": 1975104234141603, "event_type": "alert", "src_ip": "147.185.132.94", "src_port": 50703, "dest_ip": "185.254.126.122", "dest_port": 9092, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:29:35.656472+0100", "src_ip": "147.185.132.94", "dest_ip": "185.254.126.122", "src_port": 50703, "dest_port": 9092}}'); INSERT INTO alerts VALUES(955,1773005459.63380909,'{"timestamp": "2026-03-08T22:30:59.633809+0100", "flow_id": 1033339702620230, "event_type": "alert", "src_ip": "205.210.31.38", "src_port": 55141, "dest_ip": "185.254.126.122", "dest_port": 20256, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:30:59.633809+0100", "src_ip": "205.210.31.38", "dest_ip": "185.254.126.122", "src_port": 55141, "dest_port": 20256}}'); INSERT INTO alerts VALUES(956,1773005535.462975979,'{"timestamp": "2026-03-08T22:32:15.462976+0100", "flow_id": 1988470755654220, "event_type": "alert", "src_ip": "168.76.20.229", "src_port": 47003, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400029, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 30", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:32:15.462976+0100", "src_ip": "168.76.20.229", "dest_ip": "185.254.126.122", "src_port": 47003, "dest_port": 80}}'); INSERT INTO alerts VALUES(957,1773005558.591506958,'{"timestamp": "2026-03-08T22:32:38.591507+0100", "flow_id": 1696081106780776, "event_type": "alert", "src_ip": "43.228.157.22", "src_port": 50904, "dest_ip": "185.254.126.122", "dest_port": 5435, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:32:38.591507+0100", "src_ip": "43.228.157.22", "dest_ip": "185.254.126.122", "src_port": 50904, "dest_port": 5435}}'); INSERT INTO alerts VALUES(958,1773005576.116995096,'{"timestamp": "2026-03-08T22:32:56.116995+0100", "flow_id": 221015079425583, "event_type": "alert", "src_ip": "176.65.139.31", "src_port": 22383, "dest_ip": "185.254.126.122", "dest_port": 389, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ldap", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-08T22:32:56.116995+0100", "src_ip": "176.65.139.31", "dest_ip": "185.254.126.122", "src_port": 22383, "dest_port": 389}}'); INSERT INTO alerts VALUES(959,1773005579.224474906,'{"timestamp": "2026-03-08T22:32:59.224475+0100", "flow_id": 964114706272224, "event_type": "alert", "src_ip": "198.235.24.80", "src_port": 56188, "dest_ip": "185.254.126.122", "dest_port": 389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:32:59.224475+0100", "src_ip": "198.235.24.80", "dest_ip": "185.254.126.122", "src_port": 56188, "dest_port": 389}}'); INSERT INTO alerts VALUES(960,1773005655.642452956,'{"timestamp": "2026-03-08T22:34:15.642453+0100", "flow_id": 2196367603824396, "event_type": "alert", "src_ip": "198.235.24.246", "src_port": 51106, "dest_ip": "185.254.126.122", "dest_port": 118, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:34:15.642453+0100", "src_ip": "198.235.24.246", "dest_ip": "185.254.126.122", "src_port": 51106, "dest_port": 118}}'); INSERT INTO alerts VALUES(961,1773005759.887775898,'{"timestamp": "2026-03-08T22:35:59.887776+0100", "flow_id": 2124119937136867, "event_type": "alert", "src_ip": "198.235.24.71", "src_port": 55699, "dest_ip": "185.254.126.122", "dest_port": 8159, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:35:59.887776+0100", "src_ip": "198.235.24.71", "dest_ip": "185.254.126.122", "src_port": 55699, "dest_port": 8159}}'); INSERT INTO alerts VALUES(962,1773005779.488178968,'{"timestamp": "2026-03-08T22:36:19.488179+0100", "flow_id": 970813762028675, "event_type": "alert", "src_ip": "193.163.125.9", "src_port": 41794, "dest_ip": "185.254.126.122", "dest_port": 61613, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:36:19.488179+0100", "src_ip": "193.163.125.9", "dest_ip": "185.254.126.122", "src_port": 41794, "dest_port": 61613}}'); INSERT INTO alerts VALUES(963,1773005834.597946882,'{"timestamp": "2026-03-08T22:37:14.597947+0100", "flow_id": 597841607736634, "event_type": "alert", "src_ip": "167.94.146.46", "src_port": 52453, "dest_ip": "185.254.126.122", "dest_port": 215, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:37:14.597947+0100", "src_ip": "167.94.146.46", "dest_ip": "185.254.126.122", "src_port": 52453, "dest_port": 215}}'); INSERT INTO alerts VALUES(964,1773005851.02057004,'{"timestamp": "2026-03-08T22:37:31.020570+0100", "flow_id": 932774492822416, "event_type": "alert", "src_ip": "176.65.148.95", "src_port": 38954, "dest_ip": "185.254.126.122", "dest_port": 12700, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:37:31.020570+0100", "src_ip": "176.65.148.95", "dest_ip": "185.254.126.122", "src_port": 38954, "dest_port": 12700}}'); INSERT INTO alerts VALUES(965,1773005851.02057004,'{"timestamp": "2026-03-08T22:37:31.020570+0100", "flow_id": 932774492822416, "event_type": "alert", "src_ip": "176.65.148.95", "src_port": 38954, "dest_ip": "185.254.126.122", "dest_port": 12700, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:37:31.020570+0100", "src_ip": "176.65.148.95", "dest_ip": "185.254.126.122", "src_port": 38954, "dest_port": 12700}}'); INSERT INTO alerts VALUES(966,1773005865.86975193,'{"timestamp": "2026-03-08T22:37:45.869752+0100", "flow_id": 357857695677273, "event_type": "alert", "src_ip": "198.235.24.198", "src_port": 49347, "dest_ip": "185.254.126.122", "dest_port": 8443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:37:45.869752+0100", "src_ip": "198.235.24.198", "dest_ip": "185.254.126.122", "src_port": 49347, "dest_port": 8443}}'); INSERT INTO alerts VALUES(967,1773005866.835855008,'{"timestamp": "2026-03-08T22:37:46.835855+0100", "flow_id": 775223713562937, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "185.254.126.122", "dest_port": 10892, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:37:46.835855+0100", "src_ip": "79.124.40.110", "dest_ip": "185.254.126.122", "src_port": 52537, "dest_port": 10892}}'); INSERT INTO alerts VALUES(968,1773005867.642081023,'{"timestamp": "2026-03-08T22:37:47.642081+0100", "flow_id": 1068868330600968, "event_type": "alert", "src_ip": "8.209.82.97", "src_port": 39549, "dest_ip": "185.254.126.122", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 79, "bytes_toclient": 0, "start": "2026-03-08T22:37:47.642081+0100", "src_ip": "8.209.82.97", "dest_ip": "185.254.126.122", "src_port": 39549, "dest_port": 161}}'); INSERT INTO alerts VALUES(969,1773005974.962225915,'{"timestamp": "2026-03-08T22:39:34.962226+0100", "flow_id": 1880929483397348, "event_type": "alert", "src_ip": "88.210.63.190", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 44307, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:39:34.962226+0100", "src_ip": "88.210.63.190", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 44307}}'); INSERT INTO alerts VALUES(970,1773006003.36602211,'{"timestamp": "2026-03-08T22:40:03.366022+0100", "flow_id": 1009103800541375, "event_type": "alert", "src_ip": "45.194.92.9", "src_port": 55662, "dest_ip": "185.254.126.122", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:40:03.366022+0100", "src_ip": "45.194.92.9", "dest_ip": "185.254.126.122", "src_port": 55662, "dest_port": 8080}}'); INSERT INTO alerts VALUES(971,1773006074.415446997,'{"timestamp": "2026-03-08T22:41:14.415447+0100", "flow_id": 658433772511370, "event_type": "alert", "src_ip": "205.210.31.48", "src_port": 54835, "dest_ip": "185.254.126.122", "dest_port": 1900, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 125, "bytes_toclient": 0, "start": "2026-03-08T22:41:14.415447+0100", "src_ip": "205.210.31.48", "dest_ip": "185.254.126.122", "src_port": 54835, "dest_port": 1900}}'); INSERT INTO alerts VALUES(972,1773006084.07716608,'{"timestamp": "2026-03-08T22:41:24.077166+0100", "flow_id": 1175854580280873, "event_type": "alert", "src_ip": "167.94.138.159", "src_port": 18430, "dest_ip": "185.254.126.122", "dest_port": 11000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:41:24.077166+0100", "src_ip": "167.94.138.159", "dest_ip": "185.254.126.122", "src_port": 18430, "dest_port": 11000}}'); INSERT INTO alerts VALUES(973,1773006102.158776045,'{"timestamp": "2026-03-08T22:41:42.158776+0100", "flow_id": 1807841530734786, "event_type": "alert", "src_ip": "77.83.39.250", "src_port": 43514, "dest_ip": "185.254.126.122", "dest_port": 25, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400008, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 9", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:41:42.158776+0100", "src_ip": "77.83.39.250", "dest_ip": "185.254.126.122", "src_port": 43514, "dest_port": 25}}'); INSERT INTO alerts VALUES(974,1773006214.37113309,'{"timestamp": "2026-03-08T22:43:34.371133+0100", "flow_id": 1875479840358065, "event_type": "alert", "src_ip": "178.20.210.151", "src_port": 58715, "dest_ip": "185.254.126.122", "dest_port": 50000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:43:34.371133+0100", "src_ip": "178.20.210.151", "dest_ip": "185.254.126.122", "src_port": 58715, "dest_port": 50000}}'); INSERT INTO alerts VALUES(975,1773006248.218940019,'{"timestamp": "2026-03-08T22:44:08.218940+0100", "flow_id": 95915914579368, "event_type": "alert", "src_ip": "176.65.139.38", "src_port": 50000, "dest_ip": "185.254.126.122", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:44:08.218940+0100", "src_ip": "176.65.139.38", "dest_ip": "185.254.126.122", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(976,1773006272.672164916,'{"timestamp": "2026-03-08T22:44:32.672165+0100", "flow_id": 72178729270393, "event_type": "alert", "src_ip": "198.235.24.109", "src_port": 51766, "dest_ip": "185.254.126.122", "dest_port": 5902, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:44:32.672165+0100", "src_ip": "198.235.24.109", "dest_ip": "185.254.126.122", "src_port": 51766, "dest_port": 5902}}'); INSERT INTO alerts VALUES(977,1773006448.488415957,'{"timestamp": "2026-03-08T22:47:28.488416+0100", "flow_id": 127408496651007, "event_type": "alert", "src_ip": "205.210.31.180", "src_port": 55255, "dest_ip": "185.254.126.122", "dest_port": 30005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:47:28.488416+0100", "src_ip": "205.210.31.180", "dest_ip": "185.254.126.122", "src_port": 55255, "dest_port": 30005}}'); INSERT INTO alerts VALUES(978,1773006450.41199398,'{"timestamp": "2026-03-08T22:47:30.411994+0100", "flow_id": 643602801248779, "event_type": "alert", "src_ip": "66.132.153.148", "src_port": 32863, "dest_ip": "185.254.126.122", "dest_port": 4443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:47:30.411994+0100", "src_ip": "66.132.153.148", "dest_ip": "185.254.126.122", "src_port": 32863, "dest_port": 4443}}'); INSERT INTO alerts VALUES(979,1773006541.978003025,'{"timestamp": "2026-03-08T22:49:01.978003+0100", "flow_id": 1667216581223212, "event_type": "alert", "src_ip": "176.65.148.2", "src_port": 57175, "dest_ip": "185.254.126.122", "dest_port": 3128, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:49:01.978003+0100", "src_ip": "176.65.148.2", "dest_ip": "185.254.126.122", "src_port": 57175, "dest_port": 3128}}'); INSERT INTO alerts VALUES(980,1773006541.978003025,'{"timestamp": "2026-03-08T22:49:01.978003+0100", "flow_id": 1667216581223212, "event_type": "alert", "src_ip": "176.65.148.2", "src_port": 57175, "dest_ip": "185.254.126.122", "dest_port": 3128, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:49:01.978003+0100", "src_ip": "176.65.148.2", "dest_ip": "185.254.126.122", "src_port": 57175, "dest_port": 3128}}'); INSERT INTO alerts VALUES(981,1773006559.697271108,'{"timestamp": "2026-03-08T22:49:19.697271+0100", "flow_id": 2150332670657688, "event_type": "alert", "src_ip": "205.210.31.82", "src_port": 54644, "dest_ip": "185.254.126.122", "dest_port": 3909, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:49:19.697271+0100", "src_ip": "205.210.31.82", "dest_ip": "185.254.126.122", "src_port": 54644, "dest_port": 3909}}'); INSERT INTO alerts VALUES(982,1773006560.496612072,'{"timestamp": "2026-03-08T22:49:20.496612+0100", "flow_id": 162608837861294, "event_type": "alert", "src_ip": "77.83.39.233", "src_port": 40794, "dest_ip": "185.254.126.122", "dest_port": 25, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400008, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 9", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:49:20.496612+0100", "src_ip": "77.83.39.233", "dest_ip": "185.254.126.122", "src_port": 40794, "dest_port": 25}}'); INSERT INTO alerts VALUES(983,1773006567.756881952,'{"timestamp": "2026-03-08T22:49:27.756882+0100", "flow_id": 2124884500178621, "event_type": "alert", "src_ip": "198.235.24.224", "src_port": 56201, "dest_ip": "185.254.126.122", "dest_port": 10250, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:49:27.756882+0100", "src_ip": "198.235.24.224", "dest_ip": "185.254.126.122", "src_port": 56201, "dest_port": 10250}}'); INSERT INTO alerts VALUES(984,1773006590.041455984,'{"timestamp": "2026-03-08T22:49:50.041456+0100", "flow_id": 1866903205975869, "event_type": "alert", "src_ip": "91.196.152.156", "src_port": 20452, "dest_ip": "185.254.126.122", "dest_port": 5800, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:49:50.041456+0100", "src_ip": "91.196.152.156", "dest_ip": "185.254.126.122", "src_port": 20452, "dest_port": 5800}}'); INSERT INTO alerts VALUES(985,1773006658.13653493,'{"timestamp": "2026-03-08T22:50:58.136535+0100", "flow_id": 586415178363643, "event_type": "alert", "src_ip": "205.210.31.89", "src_port": 49450, "dest_ip": "185.254.126.122", "dest_port": 5984, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:50:58.136535+0100", "src_ip": "205.210.31.89", "dest_ip": "185.254.126.122", "src_port": 49450, "dest_port": 5984}}'); INSERT INTO alerts VALUES(986,1773006799.929915904,'{"timestamp": "2026-03-08T22:53:19.929916+0100", "flow_id": 2023634237539429, "event_type": "alert", "src_ip": "178.20.210.152", "src_port": 44770, "dest_ip": "185.254.126.122", "dest_port": 10001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:53:19.929916+0100", "src_ip": "178.20.210.152", "dest_ip": "185.254.126.122", "src_port": 44770, "dest_port": 10001}}'); INSERT INTO alerts VALUES(987,1773006950.182563067,'{"timestamp": "2026-03-08T22:55:50.182563+0100", "flow_id": 1910004626691522, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59739, "dest_ip": "185.254.126.122", "dest_port": 17715, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:55:50.182563+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59739, "dest_port": 17715}}'); INSERT INTO alerts VALUES(988,1773006950.182563067,'{"timestamp": "2026-03-08T22:55:50.182563+0100", "flow_id": 1910004626691522, "event_type": "alert", "src_ip": "176.65.148.70", "src_port": 59739, "dest_ip": "185.254.126.122", "dest_port": 17715, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:55:50.182563+0100", "src_ip": "176.65.148.70", "dest_ip": "185.254.126.122", "src_port": 59739, "dest_port": 17715}}'); INSERT INTO alerts VALUES(989,1773006969.549063921,'{"timestamp": "2026-03-08T22:56:09.549064+0100", "flow_id": 387890892059640, "event_type": "alert", "src_ip": "198.235.24.74", "src_port": 55465, "dest_ip": "185.254.126.122", "dest_port": 2082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:56:09.549064+0100", "src_ip": "198.235.24.74", "dest_ip": "185.254.126.122", "src_port": 55465, "dest_port": 2082}}'); INSERT INTO alerts VALUES(990,1773007001.187442065,'{"timestamp": "2026-03-08T22:56:41.187442+0100", "flow_id": 523583130133735, "event_type": "alert", "src_ip": "198.235.24.212", "src_port": 56102, "dest_ip": "185.254.126.122", "dest_port": 5986, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:56:41.187442+0100", "src_ip": "198.235.24.212", "dest_ip": "185.254.126.122", "src_port": 56102, "dest_port": 5986}}'); INSERT INTO alerts VALUES(991,1773007025.649735928,'{"timestamp": "2026-03-08T22:57:05.649736+0100", "flow_id": 538795719014722, "event_type": "alert", "src_ip": "198.235.24.233", "src_port": 50869, "dest_ip": "185.254.126.122", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:57:05.649736+0100", "src_ip": "198.235.24.233", "dest_ip": "185.254.126.122", "src_port": 50869, "dest_port": 8888}}'); INSERT INTO alerts VALUES(992,1773007042.145338059,'{"timestamp": "2026-03-08T22:57:22.145338+0100", "flow_id": 624223805462588, "event_type": "alert", "src_ip": "176.65.134.34", "src_port": 35845, "dest_ip": "185.254.126.122", "dest_port": 4145, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T22:57:22.145338+0100", "src_ip": "176.65.134.34", "dest_ip": "185.254.126.122", "src_port": 35845, "dest_port": 4145}}'); INSERT INTO alerts VALUES(993,1773007045.877125978,'{"timestamp": "2026-03-08T22:57:25.877126+0100", "flow_id": 1515429378245217, "event_type": "alert", "src_ip": "45.135.194.48", "src_port": 38384, "dest_ip": "185.254.126.122", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T22:57:25.877126+0100", "src_ip": "45.135.194.48", "dest_ip": "185.254.126.122", "src_port": 38384, "dest_port": 5555}}'); INSERT INTO alerts VALUES(994,1773007088.297359943,'{"timestamp": "2026-03-08T22:58:08.297360+0100", "flow_id": 151255325445854, "event_type": "alert", "src_ip": "66.132.153.149", "src_port": 20542, "dest_ip": "185.254.126.122", "dest_port": 18100, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T22:58:08.297360+0100", "src_ip": "66.132.153.149", "dest_ip": "185.254.126.122", "src_port": 20542, "dest_port": 18100}}'); INSERT INTO alerts VALUES(995,1773007152.528796912,'{"timestamp": "2026-03-08T22:59:12.528797+0100", "flow_id": 19367454842372, "event_type": "alert", "src_ip": "198.235.24.166", "src_port": 55132, "dest_ip": "185.254.126.122", "dest_port": 943, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T22:59:12.528797+0100", "src_ip": "198.235.24.166", "dest_ip": "185.254.126.122", "src_port": 55132, "dest_port": 943}}'); INSERT INTO alerts VALUES(996,1773007256.16567707,'{"timestamp": "2026-03-08T23:00:56.165677+0100", "flow_id": 148629511585006, "event_type": "alert", "src_ip": "167.94.138.149", "src_port": 49694, "dest_ip": "185.254.126.122", "dest_port": 17185, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 92, "bytes_toclient": 0, "start": "2026-03-08T23:00:56.165677+0100", "src_ip": "167.94.138.149", "dest_ip": "185.254.126.122", "src_port": 49694, "dest_port": 17185}}'); INSERT INTO alerts VALUES(997,1773007272.42474103,'{"timestamp": "2026-03-08T23:01:12.424741+0100", "flow_id": 135400558444945, "event_type": "alert", "src_ip": "198.235.24.59", "src_port": 52332, "dest_ip": "185.254.126.122", "dest_port": 5222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:01:12.424741+0100", "src_ip": "198.235.24.59", "dest_ip": "185.254.126.122", "src_port": 52332, "dest_port": 5222}}'); INSERT INTO alerts VALUES(998,1773007278.296785117,'{"timestamp": "2026-03-08T23:01:18.296785+0100", "flow_id": 1837633754397747, "event_type": "alert", "src_ip": "167.94.146.43", "src_port": 4981, "dest_ip": "185.254.126.122", "dest_port": 38655, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:01:18.296785+0100", "src_ip": "167.94.146.43", "dest_ip": "185.254.126.122", "src_port": 4981, "dest_port": 38655}}'); INSERT INTO alerts VALUES(999,1773007400.497848034,'{"timestamp": "2026-03-08T23:03:20.497848+0100", "flow_id": 167916124534343, "event_type": "alert", "src_ip": "147.185.132.10", "src_port": 50851, "dest_ip": "185.254.126.122", "dest_port": 7080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:03:20.497848+0100", "src_ip": "147.185.132.10", "dest_ip": "185.254.126.122", "src_port": 50851, "dest_port": 7080}}'); INSERT INTO alerts VALUES(1000,1773007435.780380964,'{"timestamp": "2026-03-08T23:03:55.780381+0100", "flow_id": 1099911529154131, "event_type": "alert", "src_ip": "123.138.18.10", "src_port": 2507, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:03:55.780381+0100", "src_ip": "123.138.18.10", "dest_ip": "185.254.126.122", "src_port": 2507, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1001,1773007468.133311033,'{"timestamp": "2026-03-08T23:04:28.133311+0100", "flow_id": 1135517416723607, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "185.254.126.122", "dest_port": 2501, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:04:28.133311+0100", "src_ip": "130.12.180.88", "dest_ip": "185.254.126.122", "src_port": 52302, "dest_port": 2501}}'); INSERT INTO alerts VALUES(1002,1773007468.133311033,'{"timestamp": "2026-03-08T23:04:28.133311+0100", "flow_id": 1135517416723607, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "185.254.126.122", "dest_port": 2501, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:04:28.133311+0100", "src_ip": "130.12.180.88", "dest_ip": "185.254.126.122", "src_port": 52302, "dest_port": 2501}}'); INSERT INTO alerts VALUES(1003,1773007485.969960928,'{"timestamp": "2026-03-08T23:04:45.969961+0100", "flow_id": 1632677438404557, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 44778, "dest_ip": "185.254.126.122", "dest_port": 32043, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:04:45.969961+0100", "src_ip": "79.124.62.134", "dest_ip": "185.254.126.122", "src_port": 44778, "dest_port": 32043}}'); INSERT INTO alerts VALUES(1004,1773007565.840790033,'{"timestamp": "2026-03-08T23:06:05.840790+0100", "flow_id": 1640840855492471, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 42686, "dest_ip": "185.254.126.122", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:06:05.840790+0100", "src_ip": "79.124.62.126", "dest_ip": "185.254.126.122", "src_port": 42686, "dest_port": 3389}}'); INSERT INTO alerts VALUES(1005,1773007608.823282003,'{"timestamp": "2026-03-08T23:06:48.823282+0100", "flow_id": 158269558620232, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 40962, "dest_ip": "185.254.126.122", "dest_port": 222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:06:48.823282+0100", "src_ip": "185.242.246.36", "dest_ip": "185.254.126.122", "src_port": 40962, "dest_port": 222}}'); INSERT INTO alerts VALUES(1006,1773007608.823282003,'{"timestamp": "2026-03-08T23:06:48.823282+0100", "flow_id": 158269558620232, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 40962, "dest_ip": "185.254.126.122", "dest_port": 222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:06:48.823282+0100", "src_ip": "185.242.246.36", "dest_ip": "185.254.126.122", "src_port": 40962, "dest_port": 222}}'); INSERT INTO alerts VALUES(1007,1773007638.119033098,'{"timestamp": "2026-03-08T23:07:18.119033+0100", "flow_id": 1918620332847162, "event_type": "alert", "src_ip": "167.94.146.44", "src_port": 5761, "dest_ip": "185.254.126.122", "dest_port": 1859, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:07:18.119033+0100", "src_ip": "167.94.146.44", "dest_ip": "185.254.126.122", "src_port": 5761, "dest_port": 1859}}'); INSERT INTO alerts VALUES(1008,1773007652.631706,'{"timestamp": "2026-03-08T23:07:32.631706+0100", "flow_id": 1305782721861832, "event_type": "alert", "src_ip": "185.169.4.141", "src_port": 52401, "dest_ip": "185.254.126.122", "dest_port": 8728, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:07:32.631706+0100", "src_ip": "185.169.4.141", "dest_ip": "185.254.126.122", "src_port": 52401, "dest_port": 8728}}'); INSERT INTO alerts VALUES(1009,1773007667.623893022,'{"timestamp": "2026-03-08T23:07:47.623893+0100", "flow_id": 990751887781628, "event_type": "alert", "src_ip": "167.94.138.108", "src_port": 11841, "dest_ip": "185.254.126.122", "dest_port": 43535, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:07:47.623893+0100", "src_ip": "167.94.138.108", "dest_ip": "185.254.126.122", "src_port": 11841, "dest_port": 43535}}'); INSERT INTO alerts VALUES(1010,1773007668.731547118,'{"timestamp": "2026-03-08T23:07:48.731547+0100", "flow_id": 1171649332809952, "event_type": "alert", "src_ip": "66.132.153.152", "src_port": 10239, "dest_ip": "185.254.126.122", "dest_port": 81, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:07:48.731547+0100", "src_ip": "66.132.153.152", "dest_ip": "185.254.126.122", "src_port": 10239, "dest_port": 81}}'); INSERT INTO alerts VALUES(1011,1773007672.244637012,'{"timestamp": "2026-03-08T23:07:52.244637+0100", "flow_id": 206284128917888, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 44338, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:07:52.244637+0100", "src_ip": "88.210.63.69", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 44338}}'); INSERT INTO alerts VALUES(1012,1773007755.090339899,'{"timestamp": "2026-03-08T23:09:15.090340+0100", "flow_id": 950959102861747, "event_type": "alert", "src_ip": "87.121.84.72", "src_port": 50160, "dest_ip": "185.254.126.122", "dest_port": 120, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:09:15.090340+0100", "src_ip": "87.121.84.72", "dest_ip": "185.254.126.122", "src_port": 50160, "dest_port": 120}}'); INSERT INTO alerts VALUES(1013,1773007850.307811022,'{"timestamp": "2026-03-08T23:10:50.307811+0100", "flow_id": 759090315938144, "event_type": "alert", "src_ip": "185.242.3.195", "src_port": 44950, "dest_ip": "185.254.126.122", "dest_port": 3022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:10:50.307811+0100", "src_ip": "185.242.3.195", "dest_ip": "185.254.126.122", "src_port": 44950, "dest_port": 3022}}'); INSERT INTO alerts VALUES(1014,1773007893.099240065,'{"timestamp": "2026-03-08T23:11:33.099240+0100", "flow_id": 1552133946942565, "event_type": "alert", "src_ip": "176.65.149.180", "src_port": 47312, "dest_ip": "185.254.126.122", "dest_port": 8265, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:11:33.099240+0100", "src_ip": "176.65.149.180", "dest_ip": "185.254.126.122", "src_port": 47312, "dest_port": 8265}}'); INSERT INTO alerts VALUES(1015,1773007900.456829072,'{"timestamp": "2026-03-08T23:11:40.456829+0100", "flow_id": 1399118694843582, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 47746, "dest_ip": "185.254.126.122", "dest_port": 9619, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:11:40.456829+0100", "src_ip": "79.124.62.230", "dest_ip": "185.254.126.122", "src_port": 47746, "dest_port": 9619}}'); INSERT INTO alerts VALUES(1016,1773007946.533660889,'{"timestamp": "2026-03-08T23:12:26.533661+0100", "flow_id": 603209701124661, "event_type": "alert", "src_ip": "185.242.3.240", "src_port": 52569, "dest_ip": "185.254.126.122", "dest_port": 22164, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:12:26.533661+0100", "src_ip": "185.242.3.240", "dest_ip": "185.254.126.122", "src_port": 52569, "dest_port": 22164}}'); INSERT INTO alerts VALUES(1017,1773007954.066137076,'{"timestamp": "2026-03-08T23:12:34.066137+0100", "flow_id": 565532573064462, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 2087, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:12:34.066137+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 2087}}'); INSERT INTO alerts VALUES(1018,1773007954.066137076,'{"timestamp": "2026-03-08T23:12:34.066137+0100", "flow_id": 565532573064462, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "185.254.126.122", "dest_port": 2087, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:12:34.066137+0100", "src_ip": "204.76.203.215", "dest_ip": "185.254.126.122", "src_port": 40000, "dest_port": 2087}}'); INSERT INTO alerts VALUES(1019,1773008012.577930928,'{"timestamp": "2026-03-08T23:13:32.577931+0100", "flow_id": 1356298682409412, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 1398, "dest_ip": "185.254.126.122", "dest_port": 27248, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:13:32.577931+0100", "src_ip": "167.94.146.45", "dest_ip": "185.254.126.122", "src_port": 1398, "dest_port": 27248}}'); INSERT INTO alerts VALUES(1020,1773008148.714977025,'{"timestamp": "2026-03-08T23:15:48.714977+0100", "flow_id": 1381956529226361, "event_type": "alert", "src_ip": "193.163.125.38", "src_port": 20297, "dest_ip": "185.254.126.122", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-08T23:15:48.714977+0100", "src_ip": "193.163.125.38", "dest_ip": "185.254.126.122", "src_port": 20297, "dest_port": 161}}'); INSERT INTO alerts VALUES(1021,1773008148.714977025,'{"timestamp": "2026-03-08T23:15:48.714977+0100", "flow_id": 1381956529226361, "event_type": "alert", "src_ip": "193.163.125.38", "src_port": 20297, "dest_ip": "185.254.126.122", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-08T23:15:48.714977+0100", "src_ip": "193.163.125.38", "dest_ip": "185.254.126.122", "src_port": 20297, "dest_port": 161}}'); INSERT INTO alerts VALUES(1022,1773008151.71491003,'{"timestamp": "2026-03-08T23:15:51.714910+0100", "flow_id": 2226094404711335, "event_type": "alert", "src_ip": "193.163.125.73", "src_port": 21806, "dest_ip": "185.254.126.122", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 92, "bytes_toclient": 0, "start": "2026-03-08T23:15:51.714910+0100", "src_ip": "193.163.125.73", "dest_ip": "185.254.126.122", "src_port": 21806, "dest_port": 161}}'); INSERT INTO alerts VALUES(1023,1773008175.558007002,'{"timestamp": "2026-03-08T23:16:15.558007+0100", "flow_id": 2115150490571469, "event_type": "alert", "src_ip": "101.36.126.70", "src_port": 45858, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2500000, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:16:15.558007+0100", "src_ip": "101.36.126.70", "dest_ip": "185.254.126.122", "src_port": 45858, "dest_port": 80}}'); INSERT INTO alerts VALUES(1024,1773008260.708029031,'{"timestamp": "2026-03-08T23:17:40.708029+0100", "flow_id": 1352114151442066, "event_type": "alert", "src_ip": "81.29.142.50", "src_port": 60437, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:17:40.708029+0100", "src_ip": "81.29.142.50", "dest_ip": "185.254.126.122", "src_port": 60437, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1025,1773008263.896826029,'{"timestamp": "2026-03-08T23:17:43.896826+0100", "flow_id": 2162991355494921, "event_type": "alert", "src_ip": "176.65.149.45", "src_port": 40501, "dest_ip": "185.254.126.122", "dest_port": 8081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:17:43.896826+0100", "src_ip": "176.65.149.45", "dest_ip": "185.254.126.122", "src_port": 40501, "dest_port": 8081}}'); INSERT INTO alerts VALUES(1026,1773008403.116923094,'{"timestamp": "2026-03-08T23:20:03.116923+0100", "flow_id": 1065134527206892, "event_type": "alert", "src_ip": "205.210.31.44", "src_port": 54224, "dest_ip": "185.254.126.122", "dest_port": 1723, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:20:03.116923+0100", "src_ip": "205.210.31.44", "dest_ip": "185.254.126.122", "src_port": 54224, "dest_port": 1723}}'); INSERT INTO alerts VALUES(1027,1773008404.344031095,'{"timestamp": "2026-03-08T23:20:04.344031+0100", "flow_id": 1196130275524313, "event_type": "alert", "src_ip": "198.235.24.226", "src_port": 56014, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:20:04.344031+0100", "src_ip": "198.235.24.226", "dest_ip": "185.254.126.122", "src_port": 56014, "dest_port": 22}}'); INSERT INTO alerts VALUES(1028,1773008427.530482054,'{"timestamp": "2026-03-08T23:20:27.530482+0100", "flow_id": 871030494122938, "event_type": "alert", "src_ip": "193.163.125.30", "src_port": 49874, "dest_ip": "185.254.126.122", "dest_port": 7170, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:20:27.530482+0100", "src_ip": "193.163.125.30", "dest_ip": "185.254.126.122", "src_port": 49874, "dest_port": 7170}}'); INSERT INTO alerts VALUES(1029,1773008547.398509026,'{"timestamp": "2026-03-08T23:22:27.398509+0100", "flow_id": 867160804260829, "event_type": "alert", "src_ip": "198.235.24.207", "src_port": 53726, "dest_ip": "185.254.126.122", "dest_port": 3390, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:22:27.398509+0100", "src_ip": "198.235.24.207", "dest_ip": "185.254.126.122", "src_port": 53726, "dest_port": 3390}}'); INSERT INTO alerts VALUES(1030,1773008586.644730092,'{"timestamp": "2026-03-08T23:23:06.644730+0100", "flow_id": 798769600475803, "event_type": "alert", "src_ip": "193.163.125.24", "src_port": 47483, "dest_ip": "185.254.126.122", "dest_port": 8008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:23:06.644730+0100", "src_ip": "193.163.125.24", "dest_ip": "185.254.126.122", "src_port": 47483, "dest_port": 8008}}'); INSERT INTO alerts VALUES(1031,1773008599.603624106,'{"timestamp": "2026-03-08T23:23:19.603624+0100", "flow_id": 2029597880359255, "event_type": "alert", "src_ip": "205.210.31.54", "src_port": 49204, "dest_ip": "185.254.126.122", "dest_port": 1234, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:23:19.603624+0100", "src_ip": "205.210.31.54", "dest_ip": "185.254.126.122", "src_port": 49204, "dest_port": 1234}}'); INSERT INTO alerts VALUES(1032,1773008657.291300059,'{"timestamp": "2026-03-08T23:24:17.291300+0100", "flow_id": 406699166918733, "event_type": "alert", "src_ip": "176.65.134.3", "src_port": 51597, "dest_ip": "185.254.126.122", "dest_port": 5678, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:24:17.291300+0100", "src_ip": "176.65.134.3", "dest_ip": "185.254.126.122", "src_port": 51597, "dest_port": 5678}}'); INSERT INTO alerts VALUES(1033,1773008684.289740085,'{"timestamp": "2026-03-08T23:24:44.289740+0100", "flow_id": 1244425306806344, "event_type": "alert", "src_ip": "66.132.153.158", "src_port": 46959, "dest_ip": "185.254.126.122", "dest_port": 26257, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:24:44.289740+0100", "src_ip": "66.132.153.158", "dest_ip": "185.254.126.122", "src_port": 46959, "dest_port": 26257}}'); INSERT INTO alerts VALUES(1034,1773008724.937180043,'{"timestamp": "2026-03-08T23:25:24.937180+0100", "flow_id": 1210409805118424, "event_type": "alert", "src_ip": "176.65.148.29", "src_port": 59244, "dest_ip": "185.254.126.122", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T23:25:24.937180+0100", "src_ip": "176.65.148.29", "dest_ip": "185.254.126.122", "src_port": 59244, "dest_port": 8332}}'); INSERT INTO alerts VALUES(1035,1773008724.937180043,'{"timestamp": "2026-03-08T23:25:24.937180+0100", "flow_id": 1210409805118424, "event_type": "alert", "src_ip": "176.65.148.29", "src_port": 59244, "dest_ip": "185.254.126.122", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-08T23:25:24.937180+0100", "src_ip": "176.65.148.29", "dest_ip": "185.254.126.122", "src_port": 59244, "dest_port": 8332}}'); INSERT INTO alerts VALUES(1036,1773008790.673275947,'{"timestamp": "2026-03-08T23:26:30.673276+0100", "flow_id": 1765800471635846, "event_type": "alert", "src_ip": "147.185.132.42", "src_port": 56271, "dest_ip": "185.254.126.122", "dest_port": 23856, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:26:30.673276+0100", "src_ip": "147.185.132.42", "dest_ip": "185.254.126.122", "src_port": 56271, "dest_port": 23856}}'); INSERT INTO alerts VALUES(1037,1773008813.947158098,'{"timestamp": "2026-03-08T23:26:53.947158+0100", "flow_id": 1534740811047494, "event_type": "alert", "src_ip": "91.196.152.44", "src_port": 58241, "dest_ip": "185.254.126.122", "dest_port": 5672, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:26:53.947158+0100", "src_ip": "91.196.152.44", "dest_ip": "185.254.126.122", "src_port": 58241, "dest_port": 5672}}'); INSERT INTO alerts VALUES(1038,1773008814.390336036,'{"timestamp": "2026-03-08T23:26:54.390336+0100", "flow_id": 1957958172008631, "event_type": "alert", "src_ip": "198.235.24.47", "src_port": 55121, "dest_ip": "185.254.126.122", "dest_port": 9443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:26:54.390336+0100", "src_ip": "198.235.24.47", "dest_ip": "185.254.126.122", "src_port": 55121, "dest_port": 9443}}'); INSERT INTO alerts VALUES(1039,1773008836.426525116,'{"timestamp": "2026-03-08T23:27:16.426525+0100", "flow_id": 1268962680561209, "event_type": "alert", "src_ip": "91.224.92.177", "src_port": 55412, "dest_ip": "185.254.126.122", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:27:16.426525+0100", "src_ip": "91.224.92.177", "dest_ip": "185.254.126.122", "src_port": 55412, "dest_port": 3000}}'); INSERT INTO alerts VALUES(1040,1773008877.08996296,'{"timestamp": "2026-03-08T23:27:57.089963+0100", "flow_id": 1512292082407718, "event_type": "alert", "src_ip": "167.94.146.72", "src_port": 29019, "dest_ip": "185.254.126.122", "dest_port": 15337, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:27:57.089963+0100", "src_ip": "167.94.146.72", "dest_ip": "185.254.126.122", "src_port": 29019, "dest_port": 15337}}'); INSERT INTO alerts VALUES(1041,1773008920.970282077,'{"timestamp": "2026-03-08T23:28:40.970282+0100", "flow_id": 226682945776540, "event_type": "alert", "src_ip": "198.235.24.223", "src_port": 51198, "dest_ip": "185.254.126.122", "dest_port": 6379, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:28:40.970282+0100", "src_ip": "198.235.24.223", "dest_ip": "185.254.126.122", "src_port": 51198, "dest_port": 6379}}'); INSERT INTO alerts VALUES(1042,1773008928.766427993,'{"timestamp": "2026-03-08T23:28:48.766428+0100", "flow_id": 195560999723911, "event_type": "alert", "src_ip": "89.190.159.181", "src_port": 56662, "dest_ip": "185.254.126.122", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 438, "bytes_toclient": 0, "start": "2026-03-08T23:28:48.766428+0100", "src_ip": "89.190.159.181", "dest_ip": "185.254.126.122", "src_port": 56662, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1043,1773008938.936964036,'{"timestamp": "2026-03-08T23:28:58.936964+0100", "flow_id": 646533049175145, "event_type": "alert", "src_ip": "167.94.146.42", "src_port": 59834, "dest_ip": "185.254.126.122", "dest_port": 39060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:28:58.936964+0100", "src_ip": "167.94.146.42", "dest_ip": "185.254.126.122", "src_port": 59834, "dest_port": 39060}}'); INSERT INTO alerts VALUES(1044,1773008960.13319993,'{"timestamp": "2026-03-08T23:29:20.133200+0100", "flow_id": 9140317461633, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "185.254.126.122", "dest_port": 64430, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:29:20.133200+0100", "src_ip": "185.156.73.86", "dest_ip": "185.254.126.122", "src_port": 55676, "dest_port": 64430}}'); INSERT INTO alerts VALUES(1045,1773008969.330980063,'{"timestamp": "2026-03-08T23:29:29.330980+0100", "flow_id": 295651778718485, "event_type": "alert", "src_ip": "45.156.87.127", "src_port": 50020, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:29:29.330980+0100", "src_ip": "45.156.87.127", "dest_ip": "185.254.126.122", "src_port": 50020, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1046,1773008969.330980063,'{"timestamp": "2026-03-08T23:29:29.330980+0100", "flow_id": 295651778718485, "event_type": "alert", "src_ip": "45.156.87.127", "src_port": 50020, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-08T23:29:29.330980+0100", "src_ip": "45.156.87.127", "dest_ip": "185.254.126.122", "src_port": 50020, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1047,1773008988.084927082,'{"timestamp": "2026-03-08T23:29:48.084927+0100", "flow_id": 1209186976401195, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 53540, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.084927+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 53540, "dest_port": 5432}}'); INSERT INTO alerts VALUES(1048,1773008988.208538056,'{"timestamp": "2026-03-08T23:29:48.208538+0100", "flow_id": 1177140330716117, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 52578, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.208538+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 52578, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1049,1773008988.389370918,'{"timestamp": "2026-03-08T23:29:48.389371+0100", "flow_id": 1390864605715648, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 59792, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.389371+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 59792, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1050,1773008988.608673095,'{"timestamp": "2026-03-08T23:29:48.608673+0100", "flow_id": 1206856937159214, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 47090, "dest_ip": "185.254.126.122", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.608673+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 47090, "dest_port": 1521}}'); INSERT INTO alerts VALUES(1051,1773008989.13250804,'{"timestamp": "2026-03-08T23:29:49.132508+0100", "flow_id": 1209186976401195, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 53540, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 120, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.084927+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 53540, "dest_port": 5432}}'); INSERT INTO alerts VALUES(1052,1773008989.25961709,'{"timestamp": "2026-03-08T23:29:49.259617+0100", "flow_id": 1177140330716117, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 52578, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 120, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.208538+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 52578, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1053,1773008989.450006962,'{"timestamp": "2026-03-08T23:29:49.450007+0100", "flow_id": 1390864605715648, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 59792, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 120, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.389371+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 59792, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1054,1773008989.639754056,'{"timestamp": "2026-03-08T23:29:49.639754+0100", "flow_id": 1206856937159214, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 47090, "dest_ip": "185.254.126.122", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 120, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.608673+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 47090, "dest_port": 1521}}'); INSERT INTO alerts VALUES(1055,1773008990.150948048,'{"timestamp": "2026-03-08T23:29:50.150948+0100", "flow_id": 1209186976401195, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 53540, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 3, "pkts_toclient": 0, "bytes_toserver": 180, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.084927+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 53540, "dest_port": 5432}}'); INSERT INTO alerts VALUES(1056,1773008990.278878928,'{"timestamp": "2026-03-08T23:29:50.278879+0100", "flow_id": 1177140330716117, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 52578, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 3, "pkts_toclient": 0, "bytes_toserver": 180, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.208538+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 52578, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1057,1773008990.469614029,'{"timestamp": "2026-03-08T23:29:50.469614+0100", "flow_id": 1390864605715648, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 59792, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 3, "pkts_toclient": 0, "bytes_toserver": 180, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.389371+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 59792, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1058,1773008990.669899941,'{"timestamp": "2026-03-08T23:29:50.669900+0100", "flow_id": 1206856937159214, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 47090, "dest_ip": "185.254.126.122", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 3, "pkts_toclient": 0, "bytes_toserver": 180, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.608673+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 47090, "dest_port": 1521}}'); INSERT INTO alerts VALUES(1059,1773008991.181341887,'{"timestamp": "2026-03-08T23:29:51.181342+0100", "flow_id": 1209186976401195, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 53540, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 0, "bytes_toserver": 240, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.084927+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 53540, "dest_port": 5432}}'); INSERT INTO alerts VALUES(1060,1773008991.304955005,'{"timestamp": "2026-03-08T23:29:51.304955+0100", "flow_id": 1177140330716117, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 52578, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 0, "bytes_toserver": 240, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.208538+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 52578, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1061,1773008991.49834299,'{"timestamp": "2026-03-08T23:29:51.498343+0100", "flow_id": 1390864605715648, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 59792, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 0, "bytes_toserver": 240, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.389371+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 59792, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1062,1773008991.687694073,'{"timestamp": "2026-03-08T23:29:51.687694+0100", "flow_id": 1206856937159214, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 47090, "dest_ip": "185.254.126.122", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 0, "bytes_toserver": 240, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.608673+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 47090, "dest_port": 1521}}'); INSERT INTO alerts VALUES(1063,1773008992.20309496,'{"timestamp": "2026-03-08T23:29:52.203095+0100", "flow_id": 1209186976401195, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 53540, "dest_ip": "185.254.126.122", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 5, "pkts_toclient": 0, "bytes_toserver": 300, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.084927+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 53540, "dest_port": 5432}}'); INSERT INTO alerts VALUES(1064,1773008992.326447963,'{"timestamp": "2026-03-08T23:29:52.326448+0100", "flow_id": 1177140330716117, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 52578, "dest_ip": "185.254.126.122", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 5, "pkts_toclient": 0, "bytes_toserver": 300, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.208538+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 52578, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1065,1773008992.51782608,'{"timestamp": "2026-03-08T23:29:52.517826+0100", "flow_id": 1390864605715648, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 59792, "dest_ip": "185.254.126.122", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 5, "pkts_toclient": 0, "bytes_toserver": 300, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.389371+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 59792, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1066,1773008992.586827994,'{"timestamp": "2026-03-08T23:29:52.586828+0100", "flow_id": 1286960044297037, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 37812, "dest_ip": "185.254.126.122", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2001219, "rev": 20, "signature": "ET SCAN Potential SSH Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 5, "pkts_toclient": 0, "bytes_toserver": 300, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.496251+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 37812, "dest_port": 22}}'); INSERT INTO alerts VALUES(1067,1773008992.712091922,'{"timestamp": "2026-03-08T23:29:52.712092+0100", "flow_id": 1206856937159214, "event_type": "alert", "src_ip": "18.219.193.156", "src_port": 47090, "dest_ip": "185.254.126.122", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 5, "pkts_toclient": 0, "bytes_toserver": 300, "bytes_toclient": 0, "start": "2026-03-08T23:29:48.608673+0100", "src_ip": "18.219.193.156", "dest_ip": "185.254.126.122", "src_port": 47090, "dest_port": 1521}}'); INSERT INTO alerts VALUES(1068,1773009010.874358892,'{"timestamp": "2026-03-08T23:30:10.874359+0100", "flow_id": 659119446273088, "event_type": "alert", "src_ip": "167.94.146.36", "src_port": 24610, "dest_ip": "185.254.126.122", "dest_port": 6031, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-08T23:30:10.874359+0100", "src_ip": "167.94.146.36", "dest_ip": "185.254.126.122", "src_port": 24610, "dest_port": 6031}}'); INSERT INTO alerts VALUES(1069,1773009015.935105085,'{"timestamp": "2026-03-08T23:30:15.935105+0100", "flow_id": 2045923514154971, "event_type": "alert", "src_ip": "172.94.9.253", "src_port": 48507, "dest_ip": "185.254.126.122", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400031, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 32", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-08T23:30:15.935105+0100", "src_ip": "172.94.9.253", "dest_ip": "185.254.126.122", "src_port": 48507, "dest_port": 80}}'); INSERT INTO alerts VALUES(1070,1773036222.630697011,'{"timestamp": "2026-03-09T07:03:42.630697+0100", "flow_id": 1864399548359244, "event_type": "alert", "src_ip": "91.196.152.76", "src_port": 46195, "dest_ip": "134.19.55.199", "dest_port": 20201, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:03:42.630697+0100", "src_ip": "91.196.152.76", "dest_ip": "134.19.55.199", "src_port": 46195, "dest_port": 20201}}'); INSERT INTO alerts VALUES(1071,1773036223.388921023,'{"timestamp": "2026-03-09T07:03:43.388921+0100", "flow_id": 2233356069924742, "event_type": "alert", "src_ip": "71.6.232.27", "src_port": 56585, "dest_ip": "134.19.55.199", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T07:03:43.388921+0100", "src_ip": "71.6.232.27", "dest_ip": "134.19.55.199", "src_port": 56585, "dest_port": 161}}'); INSERT INTO alerts VALUES(1072,1773036307.346844912,'{"timestamp": "2026-03-09T07:05:07.346845+0100", "flow_id": 926739967536712, "event_type": "alert", "src_ip": "167.94.138.148", "src_port": 58955, "dest_ip": "134.19.55.199", "dest_port": 5632, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 30, "bytes_toclient": 0, "start": "2026-03-09T07:05:07.346845+0100", "src_ip": "167.94.138.148", "dest_ip": "134.19.55.199", "src_port": 58955, "dest_port": 5632}}'); INSERT INTO alerts VALUES(1073,1773036334.179909944,'{"timestamp": "2026-03-09T07:05:34.179910+0100", "flow_id": 1898609246114519, "event_type": "alert", "src_ip": "64.62.156.50", "src_port": 45630, "dest_ip": "134.19.55.199", "dest_port": 135, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:05:34.179910+0100", "src_ip": "64.62.156.50", "dest_ip": "134.19.55.199", "src_port": 45630, "dest_port": 135}}'); INSERT INTO alerts VALUES(1074,1773036361.536153079,'{"timestamp": "2026-03-09T07:06:01.536153+0100", "flow_id": 332434959313741, "event_type": "alert", "src_ip": "110.164.64.243", "src_port": 49721, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:06:01.536153+0100", "src_ip": "110.164.64.243", "dest_ip": "134.19.55.199", "src_port": 49721, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1075,1773036417.043167115,'{"timestamp": "2026-03-09T07:06:57.043167+0100", "flow_id": 466878087777628, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 56303, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:06:57.043167+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 56303, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1076,1773036417.043167115,'{"timestamp": "2026-03-09T07:06:57.043167+0100", "flow_id": 466878087777628, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 56303, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:06:57.043167+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 56303, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1077,1773036426.656002045,'{"timestamp": "2026-03-09T07:07:06.656002+0100", "flow_id": 565711099458443, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 55735, "dest_ip": "134.19.55.199", "dest_port": 24307, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:07:06.656002+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 55735, "dest_port": 24307}}'); INSERT INTO alerts VALUES(1078,1773036433.240202904,'{"timestamp": "2026-03-09T07:07:13.240203+0100", "flow_id": 468715134312210, "event_type": "alert", "src_ip": "147.185.132.132", "src_port": 54197, "dest_ip": "134.19.55.199", "dest_port": 4025, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:07:13.240203+0100", "src_ip": "147.185.132.132", "dest_ip": "134.19.55.199", "src_port": 54197, "dest_port": 4025}}'); INSERT INTO alerts VALUES(1079,1773036444.523850918,'{"timestamp": "2026-03-09T07:07:24.523851+0100", "flow_id": 1405498147213937, "event_type": "alert", "src_ip": "193.163.125.189", "src_port": 40966, "dest_ip": "134.19.55.199", "dest_port": 8071, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:07:24.523851+0100", "src_ip": "193.163.125.189", "dest_ip": "134.19.55.199", "src_port": 40966, "dest_port": 8071}}'); INSERT INTO alerts VALUES(1080,1773036487.675314904,'{"timestamp": "2026-03-09T07:08:07.675315+0100", "flow_id": 2056032378815202, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 26733, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:08:07.675315+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 26733}}'); INSERT INTO alerts VALUES(1081,1773036487.675314904,'{"timestamp": "2026-03-09T07:08:07.675315+0100", "flow_id": 2056032378815202, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 26733, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:08:07.675315+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 26733}}'); INSERT INTO alerts VALUES(1082,1773036539.145500899,'{"timestamp": "2026-03-09T07:08:59.145501+0100", "flow_id": 906401068050482, "event_type": "alert", "src_ip": "64.62.156.121", "src_port": 48701, "dest_ip": "134.19.55.199", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:08:59.145501+0100", "src_ip": "64.62.156.121", "dest_ip": "134.19.55.199", "src_port": 48701, "dest_port": 1521}}'); INSERT INTO alerts VALUES(1083,1773036539.145500899,'{"timestamp": "2026-03-09T07:08:59.145501+0100", "flow_id": 906401068050482, "event_type": "alert", "src_ip": "64.62.156.121", "src_port": 48701, "dest_ip": "134.19.55.199", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:08:59.145501+0100", "src_ip": "64.62.156.121", "dest_ip": "134.19.55.199", "src_port": 48701, "dest_port": 1521}}'); INSERT INTO alerts VALUES(1084,1773036558.602718115,'{"timestamp": "2026-03-09T07:09:18.602718+0100", "flow_id": 1744231798195582, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 35443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:09:18.602718+0100", "src_ip": "185.156.73.86", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 35443}}'); INSERT INTO alerts VALUES(1085,1773036571.692570924,'{"timestamp": "2026-03-09T07:09:31.692571+0100", "flow_id": 1004246884715008, "event_type": "alert", "src_ip": "79.124.62.178", "src_port": 54267, "dest_ip": "134.19.55.199", "dest_port": 3390, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:09:31.692571+0100", "src_ip": "79.124.62.178", "dest_ip": "134.19.55.199", "src_port": 54267, "dest_port": 3390}}'); INSERT INTO alerts VALUES(1086,1773036572.85676694,'{"timestamp": "2026-03-09T07:09:32.856767+0100", "flow_id": 1146512866055788, "event_type": "alert", "src_ip": "195.184.76.69", "src_port": 21085, "dest_ip": "134.19.55.199", "dest_port": 5554, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:09:32.856767+0100", "src_ip": "195.184.76.69", "dest_ip": "134.19.55.199", "src_port": 21085, "dest_port": 5554}}'); INSERT INTO alerts VALUES(1087,1773036642.015852929,'{"timestamp": "2026-03-09T07:10:42.015853+0100", "flow_id": 631039851771365, "event_type": "alert", "src_ip": "64.62.197.142", "src_port": 45464, "dest_ip": "134.19.55.199", "dest_port": 8030, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:10:42.015853+0100", "src_ip": "64.62.197.142", "dest_ip": "134.19.55.199", "src_port": 45464, "dest_port": 8030}}'); INSERT INTO alerts VALUES(1088,1773036654.165035009,'{"timestamp": "2026-03-09T07:10:54.165035+0100", "flow_id": 1834722376447144, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 55075, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:10:54.165035+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 55075, "dest_port": 3389}}'); INSERT INTO alerts VALUES(1089,1773036655.518362998,'{"timestamp": "2026-03-09T07:10:55.518363+0100", "flow_id": 2226355668886042, "event_type": "alert", "src_ip": "198.143.149.250", "src_port": 8293, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-09T07:10:55.518363+0100", "src_ip": "198.143.149.250", "dest_ip": "134.19.55.199", "src_port": 8293, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1090,1773036655.518362998,'{"timestamp": "2026-03-09T07:10:55.518363+0100", "flow_id": 2226355668886042, "event_type": "alert", "src_ip": "198.143.149.250", "src_port": 8293, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-09T07:10:55.518363+0100", "src_ip": "198.143.149.250", "dest_ip": "134.19.55.199", "src_port": 8293, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1091,1773036678.6809659,'{"timestamp": "2026-03-09T07:11:18.680966+0100", "flow_id": 1798829051173826, "event_type": "alert", "src_ip": "176.65.139.12", "src_port": 33891, "dest_ip": "134.19.55.199", "dest_port": 17000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:11:18.680966+0100", "src_ip": "176.65.139.12", "dest_ip": "134.19.55.199", "src_port": 33891, "dest_port": 17000}}'); INSERT INTO alerts VALUES(1092,1773036701.282941103,'{"timestamp": "2026-03-09T07:11:41.282941+0100", "flow_id": 1496699402049241, "event_type": "alert", "src_ip": "205.210.31.242", "src_port": 52572, "dest_ip": "134.19.55.199", "dest_port": 49501, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:11:41.282941+0100", "src_ip": "205.210.31.242", "dest_ip": "134.19.55.199", "src_port": 52572, "dest_port": 49501}}'); INSERT INTO alerts VALUES(1093,1773036710.173868894,'{"timestamp": "2026-03-09T07:11:50.173869+0100", "flow_id": 1872664483370769, "event_type": "alert", "src_ip": "198.235.24.164", "src_port": 51303, "dest_ip": "134.19.55.199", "dest_port": 11553, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:11:50.173869+0100", "src_ip": "198.235.24.164", "dest_ip": "134.19.55.199", "src_port": 51303, "dest_port": 11553}}'); INSERT INTO alerts VALUES(1094,1773036768.521800994,'{"timestamp": "2026-03-09T07:12:48.521801+0100", "flow_id": 270796948941255, "event_type": "alert", "src_ip": "205.210.31.78", "src_port": 55032, "dest_ip": "134.19.55.199", "dest_port": 88, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:12:48.521801+0100", "src_ip": "205.210.31.78", "dest_ip": "134.19.55.199", "src_port": 55032, "dest_port": 88}}'); INSERT INTO alerts VALUES(1095,1773036775.513375043,'{"timestamp": "2026-03-09T07:12:55.513375+0100", "flow_id": 2204932821066979, "event_type": "alert", "src_ip": "193.163.125.208", "src_port": 34506, "dest_ip": "134.19.55.199", "dest_port": 1801, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:12:55.513375+0100", "src_ip": "193.163.125.208", "dest_ip": "134.19.55.199", "src_port": 34506, "dest_port": 1801}}'); INSERT INTO alerts VALUES(1096,1773036806.581167936,'{"timestamp": "2026-03-09T07:13:26.581168+0100", "flow_id": 1933150958757855, "event_type": "alert", "src_ip": "88.210.63.193", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 34436, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:13:26.581168+0100", "src_ip": "88.210.63.193", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 34436}}'); INSERT INTO alerts VALUES(1097,1773036817.976715087,'{"timestamp": "2026-03-09T07:13:37.976715+0100", "flow_id": 535785201820391, "event_type": "alert", "src_ip": "147.185.132.45", "src_port": 49189, "dest_ip": "134.19.55.199", "dest_port": 20257, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:13:37.976715+0100", "src_ip": "147.185.132.45", "dest_ip": "134.19.55.199", "src_port": 49189, "dest_port": 20257}}'); INSERT INTO alerts VALUES(1098,1773036831.507014037,'{"timestamp": "2026-03-09T07:13:51.507014+0100", "flow_id": 2177609840320995, "event_type": "alert", "src_ip": "91.196.152.221", "src_port": 11730, "dest_ip": "134.19.55.199", "dest_port": 2001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:13:51.507014+0100", "src_ip": "91.196.152.221", "dest_ip": "134.19.55.199", "src_port": 11730, "dest_port": 2001}}'); INSERT INTO alerts VALUES(1099,1773036835.931251049,'{"timestamp": "2026-03-09T07:13:55.931251+0100", "flow_id": 903468456789260, "event_type": "alert", "src_ip": "65.49.1.235", "src_port": 49657, "dest_ip": "134.19.55.199", "dest_port": 4080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:13:55.931251+0100", "src_ip": "65.49.1.235", "dest_ip": "134.19.55.199", "src_port": 49657, "dest_port": 4080}}'); INSERT INTO alerts VALUES(1100,1773036836.377820968,'{"timestamp": "2026-03-09T07:13:56.377821+0100", "flow_id": 1341257660350416, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 2443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:13:56.377821+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 2443}}'); INSERT INTO alerts VALUES(1101,1773036836.377820968,'{"timestamp": "2026-03-09T07:13:56.377821+0100", "flow_id": 1341257660350416, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 2443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:13:56.377821+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 2443}}'); INSERT INTO alerts VALUES(1102,1773036840.432856082,'{"timestamp": "2026-03-09T07:14:00.432856+0100", "flow_id": 170253426849800, "event_type": "alert", "src_ip": "193.163.125.188", "src_port": 52542, "dest_ip": "134.19.55.199", "dest_port": 639, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:14:00.432856+0100", "src_ip": "193.163.125.188", "dest_ip": "134.19.55.199", "src_port": 52542, "dest_port": 639}}'); INSERT INTO alerts VALUES(1103,1773036846.405678034,'{"timestamp": "2026-03-09T07:14:06.405678+0100", "flow_id": 1742377302742764, "event_type": "alert", "src_ip": "91.196.152.179", "src_port": 63260, "dest_ip": "134.19.55.199", "dest_port": 17185, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:14:06.405678+0100", "src_ip": "91.196.152.179", "dest_ip": "134.19.55.199", "src_port": 63260, "dest_port": 17185}}'); INSERT INTO alerts VALUES(1104,1773036852.510215997,'{"timestamp": "2026-03-09T07:14:12.510216+0100", "flow_id": 1346939275379302, "event_type": "alert", "src_ip": "176.65.149.235", "src_port": 56989, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:14:12.510216+0100", "src_ip": "176.65.149.235", "dest_ip": "134.19.55.199", "src_port": 56989, "dest_port": 80}}'); INSERT INTO alerts VALUES(1105,1773036865.728931903,'{"timestamp": "2026-03-09T07:14:25.728932+0100", "flow_id": 315992069815886, "event_type": "alert", "src_ip": "167.94.146.46", "src_port": 55122, "dest_ip": "134.19.55.199", "dest_port": 22088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:14:25.728932+0100", "src_ip": "167.94.146.46", "dest_ip": "134.19.55.199", "src_port": 55122, "dest_port": 22088}}'); INSERT INTO alerts VALUES(1106,1773036934.831127882,'{"timestamp": "2026-03-09T07:15:34.831128+0100", "flow_id": 1880818602500973, "event_type": "alert", "src_ip": "64.62.197.44", "src_port": 53079, "dest_ip": "134.19.55.199", "dest_port": 4081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:15:34.831128+0100", "src_ip": "64.62.197.44", "dest_ip": "134.19.55.199", "src_port": 53079, "dest_port": 4081}}'); INSERT INTO alerts VALUES(1107,1773036971.879071951,'{"timestamp": "2026-03-09T07:16:11.879072+0100", "flow_id": 960836732469142, "event_type": "alert", "src_ip": "64.62.156.171", "src_port": 58115, "dest_ip": "134.19.55.199", "dest_port": 4433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:16:11.879072+0100", "src_ip": "64.62.156.171", "dest_ip": "134.19.55.199", "src_port": 58115, "dest_port": 4433}}'); INSERT INTO alerts VALUES(1108,1773037072.143234969,'{"timestamp": "2026-03-09T07:17:52.143235+0100", "flow_id": 52242569581887, "event_type": "alert", "src_ip": "205.210.31.109", "src_port": 51213, "dest_ip": "134.19.55.199", "dest_port": 5050, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:17:52.143235+0100", "src_ip": "205.210.31.109", "dest_ip": "134.19.55.199", "src_port": 51213, "dest_port": 5050}}'); INSERT INTO alerts VALUES(1109,1773037105.048199893,'{"timestamp": "2026-03-09T07:18:25.048200+0100", "flow_id": 488496338814767, "event_type": "alert", "src_ip": "198.235.24.192", "src_port": 54611, "dest_ip": "134.19.55.199", "dest_port": 20123, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:18:25.048200+0100", "src_ip": "198.235.24.192", "dest_ip": "134.19.55.199", "src_port": 54611, "dest_port": 20123}}'); INSERT INTO alerts VALUES(1110,1773037128.305166959,'{"timestamp": "2026-03-09T07:18:48.305167+0100", "flow_id": 184783163142464, "event_type": "alert", "src_ip": "147.185.132.189", "src_port": 57054, "dest_ip": "134.19.55.199", "dest_port": 5938, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:18:48.305167+0100", "src_ip": "147.185.132.189", "dest_ip": "134.19.55.199", "src_port": 57054, "dest_port": 5938}}'); INSERT INTO alerts VALUES(1111,1773037191.911829949,'{"timestamp": "2026-03-09T07:19:51.911830+0100", "flow_id": 2227434056404440, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 54370, "dest_ip": "134.19.55.199", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T07:19:51.911830+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 54370, "dest_port": 8332}}'); INSERT INTO alerts VALUES(1112,1773037191.911829949,'{"timestamp": "2026-03-09T07:19:51.911830+0100", "flow_id": 2227434056404440, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 54370, "dest_ip": "134.19.55.199", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T07:19:51.911830+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 54370, "dest_port": 8332}}'); INSERT INTO alerts VALUES(1113,1773037210.874326945,'{"timestamp": "2026-03-09T07:20:10.874327+0100", "flow_id": 658982090918552, "event_type": "alert", "src_ip": "193.163.125.182", "src_port": 46123, "dest_ip": "134.19.55.199", "dest_port": 862, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:20:10.874327+0100", "src_ip": "193.163.125.182", "dest_ip": "134.19.55.199", "src_port": 46123, "dest_port": 862}}'); INSERT INTO alerts VALUES(1114,1773037215.023777009,'{"timestamp": "2026-03-09T07:20:15.023777+0100", "flow_id": 2072450339309093, "event_type": "alert", "src_ip": "198.235.24.166", "src_port": 52979, "dest_ip": "134.19.55.199", "dest_port": 2085, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:20:15.023777+0100", "src_ip": "198.235.24.166", "dest_ip": "134.19.55.199", "src_port": 52979, "dest_port": 2085}}'); INSERT INTO alerts VALUES(1115,1773037224.330451966,'{"timestamp": "2026-03-09T07:20:24.330452+0100", "flow_id": 11908871786235, "event_type": "alert", "src_ip": "65.49.1.148", "src_port": 41655, "dest_ip": "134.19.55.199", "dest_port": 9100, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:20:24.330452+0100", "src_ip": "65.49.1.148", "dest_ip": "134.19.55.199", "src_port": 41655, "dest_port": 9100}}'); INSERT INTO alerts VALUES(1116,1773037228.503587008,'{"timestamp": "2026-03-09T07:20:28.503587+0100", "flow_id": 1318467846362255, "event_type": "alert", "src_ip": "185.242.226.33", "src_port": 46748, "dest_ip": "134.19.55.199", "dest_port": 993, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:20:28.503587+0100", "src_ip": "185.242.226.33", "dest_ip": "134.19.55.199", "src_port": 46748, "dest_port": 993}}'); INSERT INTO alerts VALUES(1117,1773037229.412448883,'{"timestamp": "2026-03-09T07:20:29.412449+0100", "flow_id": 1489983416852095, "event_type": "alert", "src_ip": "195.184.76.135", "src_port": 13493, "dest_ip": "134.19.55.199", "dest_port": 6391, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:20:29.412449+0100", "src_ip": "195.184.76.135", "dest_ip": "134.19.55.199", "src_port": 13493, "dest_port": 6391}}'); INSERT INTO alerts VALUES(1118,1773037280.758011103,'{"timestamp": "2026-03-09T07:21:20.758011+0100", "flow_id": 159411743153044, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 9443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:21:20.758011+0100", "src_ip": "88.210.63.69", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 9443}}'); INSERT INTO alerts VALUES(1119,1773037389.756347895,'{"timestamp": "2026-03-09T07:23:09.756348+0100", "flow_id": 1559644351378612, "event_type": "alert", "src_ip": "176.65.149.215", "src_port": 55797, "dest_ip": "134.19.55.199", "dest_port": 999, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:23:09.756348+0100", "src_ip": "176.65.149.215", "dest_ip": "134.19.55.199", "src_port": 55797, "dest_port": 999}}'); INSERT INTO alerts VALUES(1120,1773037426.401751041,'{"timestamp": "2026-03-09T07:23:46.401751+0100", "flow_id": 599609555371684, "event_type": "alert", "src_ip": "64.62.197.42", "src_port": 50996, "dest_ip": "134.19.55.199", "dest_port": 12443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:23:46.401751+0100", "src_ip": "64.62.197.42", "dest_ip": "134.19.55.199", "src_port": 50996, "dest_port": 12443}}'); INSERT INTO alerts VALUES(1121,1773037497.125540019,'{"timestamp": "2026-03-09T07:24:57.125540+0100", "flow_id": 539193010418688, "event_type": "alert", "src_ip": "167.94.146.74", "src_port": 32516, "dest_ip": "134.19.55.199", "dest_port": 1312, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:24:57.125540+0100", "src_ip": "167.94.146.74", "dest_ip": "134.19.55.199", "src_port": 32516, "dest_port": 1312}}'); INSERT INTO alerts VALUES(1122,1773037508.849476099,'{"timestamp": "2026-03-09T07:25:08.849476+0100", "flow_id": 1396672499514606, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 32875, "dest_ip": "134.19.55.199", "dest_port": 8090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:25:08.849476+0100", "src_ip": "193.142.146.230", "dest_ip": "134.19.55.199", "src_port": 32875, "dest_port": 8090}}'); INSERT INTO alerts VALUES(1123,1773037568.381007909,'{"timestamp": "2026-03-09T07:26:08.381008+0100", "flow_id": 229043547912942, "event_type": "alert", "src_ip": "147.185.132.111", "src_port": 52731, "dest_ip": "134.19.55.199", "dest_port": 53631, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:26:08.381008+0100", "src_ip": "147.185.132.111", "dest_ip": "134.19.55.199", "src_port": 52731, "dest_port": 53631}}'); INSERT INTO alerts VALUES(1124,1773037593.754159927,'{"timestamp": "2026-03-09T07:26:33.754160+0100", "flow_id": 424343609985226, "event_type": "alert", "src_ip": "45.153.34.187", "src_port": 51418, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:26:33.754160+0100", "src_ip": "45.153.34.187", "dest_ip": "134.19.55.199", "src_port": 51418, "dest_port": 80}}'); INSERT INTO alerts VALUES(1125,1773037599.657485962,'{"timestamp": "2026-03-09T07:26:39.657486+0100", "flow_id": 1979457046482774, "event_type": "alert", "src_ip": "193.163.125.200", "src_port": 52479, "dest_ip": "134.19.55.199", "dest_port": 40443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:26:39.657486+0100", "src_ip": "193.163.125.200", "dest_ip": "134.19.55.199", "src_port": 52479, "dest_port": 40443}}'); INSERT INTO alerts VALUES(1126,1773037623.105071068,'{"timestamp": "2026-03-09T07:27:03.105071+0100", "flow_id": 2140128547663460, "event_type": "alert", "src_ip": "185.242.226.11", "src_port": 45608, "dest_ip": "134.19.55.199", "dest_port": 12273, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:27:03.105071+0100", "src_ip": "185.242.226.11", "dest_ip": "134.19.55.199", "src_port": 45608, "dest_port": 12273}}'); INSERT INTO alerts VALUES(1127,1773037636.306423902,'{"timestamp": "2026-03-09T07:27:16.306424+0100", "flow_id": 1316081515628142, "event_type": "alert", "src_ip": "64.62.197.13", "src_port": 55029, "dest_ip": "134.19.55.199", "dest_port": 65422, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:27:16.306424+0100", "src_ip": "64.62.197.13", "dest_ip": "134.19.55.199", "src_port": 55029, "dest_port": 65422}}'); INSERT INTO alerts VALUES(1128,1773037662.900444984,'{"timestamp": "2026-03-09T07:27:42.900445+0100", "flow_id": 1897058757220439, "event_type": "alert", "src_ip": "147.185.132.198", "src_port": 51757, "dest_ip": "134.19.55.199", "dest_port": 12345, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:27:42.900445+0100", "src_ip": "147.185.132.198", "dest_ip": "134.19.55.199", "src_port": 51757, "dest_port": 12345}}'); INSERT INTO alerts VALUES(1129,1773037663.125292062,'{"timestamp": "2026-03-09T07:27:43.125292+0100", "flow_id": 2226977984043981, "event_type": "alert", "src_ip": "64.62.156.40", "src_port": 17534, "dest_ip": "134.19.55.199", "dest_port": 111, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-09T07:27:43.125292+0100", "src_ip": "64.62.156.40", "dest_ip": "134.19.55.199", "src_port": 17534, "dest_port": 111}}'); INSERT INTO alerts VALUES(1130,1773037692.580343962,'{"timestamp": "2026-03-09T07:28:12.580344+0100", "flow_id": 1366662357601750, "event_type": "alert", "src_ip": "167.94.138.126", "src_port": 37782, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:28:12.580344+0100", "src_ip": "167.94.138.126", "dest_ip": "134.19.55.199", "src_port": 37782, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1131,1773037755.422679901,'{"timestamp": "2026-03-09T07:29:15.422680+0100", "flow_id": 970973916652120, "event_type": "alert", "src_ip": "65.49.1.173", "src_port": 45288, "dest_ip": "134.19.55.199", "dest_port": 403, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:29:15.422680+0100", "src_ip": "65.49.1.173", "dest_ip": "134.19.55.199", "src_port": 45288, "dest_port": 403}}'); INSERT INTO alerts VALUES(1132,1773037784.274667024,'{"timestamp": "2026-03-09T07:29:44.274667+0100", "flow_id": 53787155878268, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 55735, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:29:44.274667+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 55735, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1133,1773037857.600313901,'{"timestamp": "2026-03-09T07:30:57.600314+0100", "flow_id": 326529509398779, "event_type": "alert", "src_ip": "167.94.138.152", "src_port": 45404, "dest_ip": "134.19.55.199", "dest_port": 9599, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:30:57.600314+0100", "src_ip": "167.94.138.152", "dest_ip": "134.19.55.199", "src_port": 45404, "dest_port": 9599}}'); INSERT INTO alerts VALUES(1134,1773037884.322928905,'{"timestamp": "2026-03-09T07:31:24.322929+0100", "flow_id": 1386972079626544, "event_type": "alert", "src_ip": "198.235.24.126", "src_port": 55051, "dest_ip": "134.19.55.199", "dest_port": 50070, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:31:24.322929+0100", "src_ip": "198.235.24.126", "dest_ip": "134.19.55.199", "src_port": 55051, "dest_port": 50070}}'); INSERT INTO alerts VALUES(1135,1773037895.872467041,'{"timestamp": "2026-03-09T07:31:35.872467+0100", "flow_id": 2058371373641532, "event_type": "alert", "src_ip": "64.62.197.148", "src_port": 35593, "dest_ip": "134.19.55.199", "dest_port": 17689, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:31:35.872467+0100", "src_ip": "64.62.197.148", "dest_ip": "134.19.55.199", "src_port": 35593, "dest_port": 17689}}'); INSERT INTO alerts VALUES(1136,1773037904.635621071,'{"timestamp": "2026-03-09T07:31:44.635621+0100", "flow_id": 196698608526861, "event_type": "alert", "src_ip": "64.62.156.170", "src_port": 39290, "dest_ip": "134.19.55.199", "dest_port": 7000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:31:44.635621+0100", "src_ip": "64.62.156.170", "dest_ip": "134.19.55.199", "src_port": 39290, "dest_port": 7000}}'); INSERT INTO alerts VALUES(1137,1773037916.86955309,'{"timestamp": "2026-03-09T07:31:56.869553+0100", "flow_id": 1201431114793723, "event_type": "alert", "src_ip": "198.235.24.97", "src_port": 55296, "dest_ip": "134.19.55.199", "dest_port": 30006, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:31:56.869553+0100", "src_ip": "198.235.24.97", "dest_ip": "134.19.55.199", "src_port": 55296, "dest_port": 30006}}'); INSERT INTO alerts VALUES(1138,1773037935.792548894,'{"timestamp": "2026-03-09T07:32:15.792549+0100", "flow_id": 1996600988449712, "event_type": "alert", "src_ip": "195.184.76.39", "src_port": 9532, "dest_ip": "134.19.55.199", "dest_port": 5706, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:32:15.792549+0100", "src_ip": "195.184.76.39", "dest_ip": "134.19.55.199", "src_port": 9532, "dest_port": 5706}}'); INSERT INTO alerts VALUES(1139,1773037978.217227936,'{"timestamp": "2026-03-09T07:32:58.217228+0100", "flow_id": 651512312469309, "event_type": "alert", "src_ip": "147.185.132.246", "src_port": 51865, "dest_ip": "134.19.55.199", "dest_port": 8880, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:32:58.217228+0100", "src_ip": "147.185.132.246", "dest_ip": "134.19.55.199", "src_port": 51865, "dest_port": 8880}}'); INSERT INTO alerts VALUES(1140,1773037991.198327064,'{"timestamp": "2026-03-09T07:33:11.198327+0100", "flow_id": 1977709732866325, "event_type": "alert", "src_ip": "195.184.76.181", "src_port": 62029, "dest_ip": "134.19.55.199", "dest_port": 5112, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:33:11.198327+0100", "src_ip": "195.184.76.181", "dest_ip": "134.19.55.199", "src_port": 62029, "dest_port": 5112}}'); INSERT INTO alerts VALUES(1141,1773038024.402508975,'{"timestamp": "2026-03-09T07:33:44.402509+0100", "flow_id": 39914968032187, "event_type": "alert", "src_ip": "167.94.138.136", "src_port": 22304, "dest_ip": "134.19.55.199", "dest_port": 2222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:33:44.402509+0100", "src_ip": "167.94.138.136", "dest_ip": "134.19.55.199", "src_port": 22304, "dest_port": 2222}}'); INSERT INTO alerts VALUES(1142,1773038039.796852112,'{"timestamp": "2026-03-09T07:33:59.796852+0100", "flow_id": 2015079669174452, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 45049, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:33:59.796852+0100", "src_ip": "130.12.180.174", "dest_ip": "134.19.55.199", "src_port": 45049, "dest_port": 23}}'); INSERT INTO alerts VALUES(1143,1773038039.796852112,'{"timestamp": "2026-03-09T07:33:59.796852+0100", "flow_id": 2015079669174452, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 45049, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:33:59.796852+0100", "src_ip": "130.12.180.174", "dest_ip": "134.19.55.199", "src_port": 45049, "dest_port": 23}}'); INSERT INTO alerts VALUES(1144,1773038057.141865015,'{"timestamp": "2026-03-09T07:34:17.141865+0100", "flow_id": 327834395826841, "event_type": "alert", "src_ip": "193.163.125.205", "src_port": 56883, "dest_ip": "134.19.55.199", "dest_port": 30005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:34:17.141865+0100", "src_ip": "193.163.125.205", "dest_ip": "134.19.55.199", "src_port": 56883, "dest_port": 30005}}'); INSERT INTO alerts VALUES(1145,1773038064.290029049,'{"timestamp": "2026-03-09T07:34:24.290029+0100", "flow_id": 119768838292622, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 5297, "dest_ip": "134.19.55.199", "dest_port": 40972, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:34:24.290029+0100", "src_ip": "167.94.146.40", "dest_ip": "134.19.55.199", "src_port": 5297, "dest_port": 40972}}'); INSERT INTO alerts VALUES(1146,1773038082.114542961,'{"timestamp": "2026-03-09T07:34:42.114543+0100", "flow_id": 773437490663846, "event_type": "alert", "src_ip": "167.94.138.96", "src_port": 18984, "dest_ip": "134.19.55.199", "dest_port": 27310, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:34:42.114543+0100", "src_ip": "167.94.138.96", "dest_ip": "134.19.55.199", "src_port": 18984, "dest_port": 27310}}'); INSERT INTO alerts VALUES(1147,1773038114.509227992,'{"timestamp": "2026-03-09T07:35:14.509228+0100", "flow_id": 779743842334744, "event_type": "alert", "src_ip": "193.163.125.213", "src_port": 44232, "dest_ip": "134.19.55.199", "dest_port": 11554, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:35:14.509228+0100", "src_ip": "193.163.125.213", "dest_ip": "134.19.55.199", "src_port": 44232, "dest_port": 11554}}'); INSERT INTO alerts VALUES(1148,1773038120.544270993,'{"timestamp": "2026-03-09T07:35:20.544271+0100", "flow_id": 85826790145206, "event_type": "alert", "src_ip": "66.132.153.153", "src_port": 49756, "dest_ip": "134.19.55.199", "dest_port": 1967, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-09T07:35:20.544271+0100", "src_ip": "66.132.153.153", "dest_ip": "134.19.55.199", "src_port": 49756, "dest_port": 1967}}'); INSERT INTO alerts VALUES(1149,1773038145.496366978,'{"timestamp": "2026-03-09T07:35:45.496367+0100", "flow_id": 443032098081166, "event_type": "alert", "src_ip": "176.65.149.233", "src_port": 36200, "dest_ip": "134.19.55.199", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:35:45.496367+0100", "src_ip": "176.65.149.233", "dest_ip": "134.19.55.199", "src_port": 36200, "dest_port": 8088}}'); INSERT INTO alerts VALUES(1150,1773038189.212532997,'{"timestamp": "2026-03-09T07:36:29.212533+0100", "flow_id": 1475773874859911, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 57633, "dest_ip": "134.19.55.199", "dest_port": 45102, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:36:29.212533+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 57633, "dest_port": 45102}}'); INSERT INTO alerts VALUES(1151,1773038209.1593709,'{"timestamp": "2026-03-09T07:36:49.159371+0100", "flow_id": 403021398703205, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 29752, "dest_ip": "134.19.55.199", "dest_port": 2726, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:36:49.159371+0100", "src_ip": "167.94.146.37", "dest_ip": "134.19.55.199", "src_port": 29752, "dest_port": 2726}}'); INSERT INTO alerts VALUES(1152,1773038272.597187043,'{"timestamp": "2026-03-09T07:37:52.597187+0100", "flow_id": 31627952361435, "event_type": "alert", "src_ip": "205.210.31.70", "src_port": 52362, "dest_ip": "134.19.55.199", "dest_port": 8883, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:37:52.597187+0100", "src_ip": "205.210.31.70", "dest_ip": "134.19.55.199", "src_port": 52362, "dest_port": 8883}}'); INSERT INTO alerts VALUES(1153,1773038353.565642119,'{"timestamp": "2026-03-09T07:39:13.565642+0100", "flow_id": 459090235937030, "event_type": "alert", "src_ip": "193.163.125.183", "src_port": 59097, "dest_ip": "134.19.55.199", "dest_port": 32080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:39:13.565642+0100", "src_ip": "193.163.125.183", "dest_ip": "134.19.55.199", "src_port": 59097, "dest_port": 32080}}'); INSERT INTO alerts VALUES(1154,1773038360.810590028,'{"timestamp": "2026-03-09T07:39:20.810590+0100", "flow_id": 103759240205580, "event_type": "alert", "src_ip": "65.49.1.223", "src_port": 38175, "dest_ip": "134.19.55.199", "dest_port": 32400, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:39:20.810590+0100", "src_ip": "65.49.1.223", "dest_ip": "134.19.55.199", "src_port": 38175, "dest_port": 32400}}'); INSERT INTO alerts VALUES(1155,1773038441.5640409,'{"timestamp": "2026-03-09T07:40:41.564041+0100", "flow_id": 452215921122882, "event_type": "alert", "src_ip": "193.163.125.185", "src_port": 53635, "dest_ip": "134.19.55.199", "dest_port": 20210, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:40:41.564041+0100", "src_ip": "193.163.125.185", "dest_ip": "134.19.55.199", "src_port": 53635, "dest_port": 20210}}'); INSERT INTO alerts VALUES(1156,1773038442.914798974,'{"timestamp": "2026-03-09T07:40:42.914799+0100", "flow_id": 832810564325164, "event_type": "alert", "src_ip": "147.185.132.159", "src_port": 51179, "dest_ip": "134.19.55.199", "dest_port": 9091, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:40:42.914799+0100", "src_ip": "147.185.132.159", "dest_ip": "134.19.55.199", "src_port": 51179, "dest_port": 9091}}'); INSERT INTO alerts VALUES(1157,1773038448.446094037,'{"timestamp": "2026-03-09T07:40:48.446094+0100", "flow_id": 227109393256947, "event_type": "alert", "src_ip": "167.94.146.38", "src_port": 29726, "dest_ip": "134.19.55.199", "dest_port": 25563, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:40:48.446094+0100", "src_ip": "167.94.146.38", "dest_ip": "134.19.55.199", "src_port": 29726, "dest_port": 25563}}'); INSERT INTO alerts VALUES(1158,1773038448.859844923,'{"timestamp": "2026-03-09T07:40:48.859845+0100", "flow_id": 33833523309455, "event_type": "alert", "src_ip": "45.156.87.127", "src_port": 45404, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:40:48.859845+0100", "src_ip": "45.156.87.127", "dest_ip": "134.19.55.199", "src_port": 45404, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1159,1773038448.859844923,'{"timestamp": "2026-03-09T07:40:48.859845+0100", "flow_id": 33833523309455, "event_type": "alert", "src_ip": "45.156.87.127", "src_port": 45404, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:40:48.859845+0100", "src_ip": "45.156.87.127", "dest_ip": "134.19.55.199", "src_port": 45404, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1160,1773038458.855185985,'{"timestamp": "2026-03-09T07:40:58.855186+0100", "flow_id": 576771324549822, "event_type": "alert", "src_ip": "176.65.149.219", "src_port": 63527, "dest_ip": "134.19.55.199", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 48, "bytes_toclient": 0, "start": "2026-03-09T07:40:58.855186+0100", "src_ip": "176.65.149.219", "dest_ip": "134.19.55.199", "src_port": 63527, "dest_port": 25565}}'); INSERT INTO alerts VALUES(1161,1773038490.595139027,'{"timestamp": "2026-03-09T07:41:30.595139+0100", "flow_id": 585779263511931, "event_type": "alert", "src_ip": "176.65.139.38", "src_port": 50000, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:41:30.595139+0100", "src_ip": "176.65.139.38", "dest_ip": "134.19.55.199", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(1162,1773038531.0009861,'{"timestamp": "2026-03-09T07:42:11.000986+0100", "flow_id": 848663201682109, "event_type": "alert", "src_ip": "195.184.76.119", "src_port": 3603, "dest_ip": "134.19.55.199", "dest_port": 51001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:42:11.000986+0100", "src_ip": "195.184.76.119", "dest_ip": "134.19.55.199", "src_port": 3603, "dest_port": 51001}}'); INSERT INTO alerts VALUES(1163,1773038531.001373052,'{"timestamp": "2026-03-09T07:42:11.001373+0100", "flow_id": 850326174828447, "event_type": "alert", "src_ip": "176.65.139.41", "src_port": 50000, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:42:11.001373+0100", "src_ip": "176.65.139.41", "dest_ip": "134.19.55.199", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(1164,1773038577.00467205,'{"timestamp": "2026-03-09T07:42:57.004672+0100", "flow_id": 301544515763882, "event_type": "alert", "src_ip": "193.163.125.186", "src_port": 35713, "dest_ip": "134.19.55.199", "dest_port": 104, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:42:57.004672+0100", "src_ip": "193.163.125.186", "dest_ip": "134.19.55.199", "src_port": 35713, "dest_port": 104}}'); INSERT INTO alerts VALUES(1165,1773038685.535547019,'{"timestamp": "2026-03-09T07:44:45.535547+0100", "flow_id": 1455734575230644, "event_type": "alert", "src_ip": "64.62.156.12", "src_port": 54084, "dest_ip": "134.19.55.199", "dest_port": 6025, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:44:45.535547+0100", "src_ip": "64.62.156.12", "dest_ip": "134.19.55.199", "src_port": 54084, "dest_port": 6025}}'); INSERT INTO alerts VALUES(1166,1773038687.252326965,'{"timestamp": "2026-03-09T07:44:47.252327+0100", "flow_id": 2209640290980487, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 40097, "dest_ip": "134.19.55.199", "dest_port": 9898, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:44:47.252327+0100", "src_ip": "79.124.40.82", "dest_ip": "134.19.55.199", "src_port": 40097, "dest_port": 9898}}'); INSERT INTO alerts VALUES(1167,1773038824.880064965,'{"timestamp": "2026-03-09T07:47:04.880065+0100", "flow_id": 120677573821171, "event_type": "alert", "src_ip": "198.235.24.48", "src_port": 28654, "dest_ip": "134.19.55.199", "dest_port": 12446, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T07:47:04.880065+0100", "src_ip": "198.235.24.48", "dest_ip": "134.19.55.199", "src_port": 28654, "dest_port": 12446}}'); INSERT INTO alerts VALUES(1168,1773038920.662538051,'{"timestamp": "2026-03-09T07:48:40.662538+0100", "flow_id": 30831442376261, "event_type": "alert", "src_ip": "167.94.138.135", "src_port": 36546, "dest_ip": "134.19.55.199", "dest_port": 3784, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T07:48:40.662538+0100", "src_ip": "167.94.138.135", "dest_ip": "134.19.55.199", "src_port": 36546, "dest_port": 3784}}'); INSERT INTO alerts VALUES(1169,1773038933.941262007,'{"timestamp": "2026-03-09T07:48:53.941262+0100", "flow_id": 1509415026953604, "event_type": "alert", "src_ip": "45.153.34.158", "src_port": 52198, "dest_ip": "134.19.55.199", "dest_port": 50555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T07:48:53.941262+0100", "src_ip": "45.153.34.158", "dest_ip": "134.19.55.199", "src_port": 52198, "dest_port": 50555}}'); INSERT INTO alerts VALUES(1170,1773038935.271953106,'{"timestamp": "2026-03-09T07:48:55.271953+0100", "flow_id": 2012455255066568, "event_type": "alert", "src_ip": "91.196.152.125", "src_port": 6575, "dest_ip": "134.19.55.199", "dest_port": 199, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:48:55.271953+0100", "src_ip": "91.196.152.125", "dest_ip": "134.19.55.199", "src_port": 6575, "dest_port": 199}}'); INSERT INTO alerts VALUES(1171,1773038936.326112031,'{"timestamp": "2026-03-09T07:48:56.326112+0100", "flow_id": 274741625216137, "event_type": "alert", "src_ip": "65.49.1.83", "src_port": 42170, "dest_ip": "134.19.55.199", "dest_port": 23856, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:48:56.326112+0100", "src_ip": "65.49.1.83", "dest_ip": "134.19.55.199", "src_port": 42170, "dest_port": 23856}}'); INSERT INTO alerts VALUES(1172,1773038956.561126947,'{"timestamp": "2026-03-09T07:49:16.561127+0100", "flow_id": 1284124290224199, "event_type": "alert", "src_ip": "185.196.8.218", "src_port": 46444, "dest_ip": "134.19.55.199", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:49:16.561127+0100", "src_ip": "185.196.8.218", "dest_ip": "134.19.55.199", "src_port": 46444, "dest_port": 5900}}'); INSERT INTO alerts VALUES(1173,1773038981.722251892,'{"timestamp": "2026-03-09T07:49:41.722252+0100", "flow_id": 1413199055336273, "event_type": "alert", "src_ip": "167.94.138.145", "src_port": 52059, "dest_ip": "134.19.55.199", "dest_port": 6007, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:49:41.722252+0100", "src_ip": "167.94.138.145", "dest_ip": "134.19.55.199", "src_port": 52059, "dest_port": 6007}}'); INSERT INTO alerts VALUES(1174,1773039016.064615011,'{"timestamp": "2026-03-09T07:50:16.064615+0100", "flow_id": 277522222656247, "event_type": "alert", "src_ip": "205.210.31.252", "src_port": 54903, "dest_ip": "134.19.55.199", "dest_port": 427, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:50:16.064615+0100", "src_ip": "205.210.31.252", "dest_ip": "134.19.55.199", "src_port": 54903, "dest_port": 427}}'); INSERT INTO alerts VALUES(1175,1773039029.418628931,'{"timestamp": "2026-03-09T07:50:29.418629+0100", "flow_id": 1516524827598597, "event_type": "alert", "src_ip": "64.62.156.195", "src_port": 59974, "dest_ip": "134.19.55.199", "dest_port": 24156, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:50:29.418629+0100", "src_ip": "64.62.156.195", "dest_ip": "134.19.55.199", "src_port": 59974, "dest_port": 24156}}'); INSERT INTO alerts VALUES(1176,1773039032.323159933,'{"timestamp": "2026-03-09T07:50:32.323160+0100", "flow_id": 262062278779289, "event_type": "alert", "src_ip": "205.210.31.43", "src_port": 55103, "dest_ip": "134.19.55.199", "dest_port": 60000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:50:32.323160+0100", "src_ip": "205.210.31.43", "dest_ip": "134.19.55.199", "src_port": 55103, "dest_port": 60000}}'); INSERT INTO alerts VALUES(1177,1773039072.49159789,'{"timestamp": "2026-03-09T07:51:12.491598+0100", "flow_id": 141075161410690, "event_type": "alert", "src_ip": "178.20.210.151", "src_port": 52907, "dest_ip": "134.19.55.199", "dest_port": 6000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:51:12.491598+0100", "src_ip": "178.20.210.151", "dest_ip": "134.19.55.199", "src_port": 52907, "dest_port": 6000}}'); INSERT INTO alerts VALUES(1178,1773039127.646756887,'{"timestamp": "2026-03-09T07:52:07.646757+0100", "flow_id": 2214853923193606, "event_type": "alert", "src_ip": "198.235.24.45", "src_port": 50944, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:52:07.646757+0100", "src_ip": "198.235.24.45", "dest_ip": "134.19.55.199", "src_port": 50944, "dest_port": 23}}'); INSERT INTO alerts VALUES(1179,1773039178.921053887,'{"timestamp": "2026-03-09T07:52:58.921054+0100", "flow_id": 578199549243222, "event_type": "alert", "src_ip": "167.94.138.106", "src_port": 43434, "dest_ip": "134.19.55.199", "dest_port": 2131, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:52:58.921054+0100", "src_ip": "167.94.138.106", "dest_ip": "134.19.55.199", "src_port": 43434, "dest_port": 2131}}'); INSERT INTO alerts VALUES(1180,1773039227.552604914,'{"timestamp": "2026-03-09T07:53:47.552605+0100", "flow_id": 966049589504534, "event_type": "alert", "src_ip": "167.94.146.34", "src_port": 12431, "dest_ip": "134.19.55.199", "dest_port": 49795, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:53:47.552605+0100", "src_ip": "167.94.146.34", "dest_ip": "134.19.55.199", "src_port": 12431, "dest_port": 49795}}'); INSERT INTO alerts VALUES(1181,1773039275.171320915,'{"timestamp": "2026-03-09T07:54:35.171321+0100", "flow_id": 1017295798559502, "event_type": "alert", "src_ip": "167.94.146.41", "src_port": 64212, "dest_ip": "134.19.55.199", "dest_port": 62134, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:54:35.171321+0100", "src_ip": "167.94.146.41", "dest_ip": "134.19.55.199", "src_port": 64212, "dest_port": 62134}}'); INSERT INTO alerts VALUES(1182,1773039293.737180948,'{"timestamp": "2026-03-09T07:54:53.737181+0100", "flow_id": 1477322368741951, "event_type": "alert", "src_ip": "185.242.226.81", "src_port": 33579, "dest_ip": "134.19.55.199", "dest_port": 40798, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:54:53.737181+0100", "src_ip": "185.242.226.81", "dest_ip": "134.19.55.199", "src_port": 33579, "dest_port": 40798}}'); INSERT INTO alerts VALUES(1183,1773039335.652039052,'{"timestamp": "2026-03-09T07:55:35.652039+0100", "flow_id": 2237537046609436, "event_type": "alert", "src_ip": "193.163.125.210", "src_port": 56706, "dest_ip": "134.19.55.199", "dest_port": 1080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:55:35.652039+0100", "src_ip": "193.163.125.210", "dest_ip": "134.19.55.199", "src_port": 56706, "dest_port": 1080}}'); INSERT INTO alerts VALUES(1184,1773039374.802691936,'{"timestamp": "2026-03-09T07:56:14.802692+0100", "flow_id": 1758687838509561, "event_type": "alert", "src_ip": "167.172.140.78", "src_port": 50017, "dest_ip": "134.19.55.199", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:56:14.802692+0100", "src_ip": "167.172.140.78", "dest_ip": "134.19.55.199", "src_port": 50017, "dest_port": 1521}}'); INSERT INTO alerts VALUES(1185,1773039398.799643993,'{"timestamp": "2026-03-09T07:56:38.799644+0100", "flow_id": 1745597576971865, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 41686, "dest_ip": "134.19.55.199", "dest_port": 38278, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:56:38.799644+0100", "src_ip": "167.94.146.32", "dest_ip": "134.19.55.199", "src_port": 41686, "dest_port": 38278}}'); INSERT INTO alerts VALUES(1186,1773039406.671096086,'{"timestamp": "2026-03-09T07:56:46.671096+0100", "flow_id": 1756436827273456, "event_type": "alert", "src_ip": "91.224.92.177", "src_port": 47996, "dest_ip": "134.19.55.199", "dest_port": 3001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:56:46.671096+0100", "src_ip": "91.224.92.177", "dest_ip": "134.19.55.199", "src_port": 47996, "dest_port": 3001}}'); INSERT INTO alerts VALUES(1187,1773039407.807941913,'{"timestamp": "2026-03-09T07:56:47.807942+0100", "flow_id": 2062711237077920, "event_type": "alert", "src_ip": "167.94.146.39", "src_port": 28710, "dest_ip": "134.19.55.199", "dest_port": 56830, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:56:47.807942+0100", "src_ip": "167.94.146.39", "dest_ip": "134.19.55.199", "src_port": 28710, "dest_port": 56830}}'); INSERT INTO alerts VALUES(1188,1773039477.700181962,'{"timestamp": "2026-03-09T07:57:57.700182+0100", "flow_id": 1599884781228052, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 52818, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:57:57.700182+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.55.199", "src_port": 52818, "dest_port": 22}}'); INSERT INTO alerts VALUES(1189,1773039477.700181962,'{"timestamp": "2026-03-09T07:57:57.700182+0100", "flow_id": 1599884781228052, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 52818, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:57:57.700182+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.55.199", "src_port": 52818, "dest_port": 22}}'); INSERT INTO alerts VALUES(1190,1773039510.844588041,'{"timestamp": "2026-03-09T07:58:30.844588+0100", "flow_id": 1938631062943316, "event_type": "alert", "src_ip": "65.49.1.18", "src_port": 59252, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:58:30.844588+0100", "src_ip": "65.49.1.18", "dest_ip": "134.19.55.199", "src_port": 59252, "dest_port": 80}}'); INSERT INTO alerts VALUES(1191,1773039548.650486947,'{"timestamp": "2026-03-09T07:59:08.650487+0100", "flow_id": 1386448789540171, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 52166, "dest_ip": "134.19.55.199", "dest_port": 1025, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:59:08.650487+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 52166, "dest_port": 1025}}'); INSERT INTO alerts VALUES(1192,1773039548.650486947,'{"timestamp": "2026-03-09T07:59:08.650487+0100", "flow_id": 1386448789540171, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 52166, "dest_ip": "134.19.55.199", "dest_port": 1025, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:59:08.650487+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 52166, "dest_port": 1025}}'); INSERT INTO alerts VALUES(1193,1773039560.249886035,'{"timestamp": "2026-03-09T07:59:20.249886+0100", "flow_id": 228830405815244, "event_type": "alert", "src_ip": "198.235.24.194", "src_port": 56726, "dest_ip": "134.19.55.199", "dest_port": 30005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T07:59:20.249886+0100", "src_ip": "198.235.24.194", "dest_ip": "134.19.55.199", "src_port": 56726, "dest_port": 30005}}'); INSERT INTO alerts VALUES(1194,1773039563.210803985,'{"timestamp": "2026-03-09T07:59:23.210804+0100", "flow_id": 905399552304265, "event_type": "alert", "src_ip": "195.184.76.143", "src_port": 62546, "dest_ip": "134.19.55.199", "dest_port": 5065, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T07:59:23.210804+0100", "src_ip": "195.184.76.143", "dest_ip": "134.19.55.199", "src_port": 62546, "dest_port": 5065}}'); INSERT INTO alerts VALUES(1195,1773039569.058463096,'{"timestamp": "2026-03-09T07:59:29.058463+0100", "flow_id": 532572567501979, "event_type": "alert", "src_ip": "176.65.134.20", "src_port": 46210, "dest_ip": "134.19.55.199", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T07:59:29.058463+0100", "src_ip": "176.65.134.20", "dest_ip": "134.19.55.199", "src_port": 46210, "dest_port": 443}}'); INSERT INTO alerts VALUES(1196,1773039611.761339903,'{"timestamp": "2026-03-09T08:00:11.761340+0100", "flow_id": 1018131723655715, "event_type": "alert", "src_ip": "198.235.24.122", "src_port": 50677, "dest_ip": "134.19.55.199", "dest_port": 54041, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:00:11.761340+0100", "src_ip": "198.235.24.122", "dest_ip": "134.19.55.199", "src_port": 50677, "dest_port": 54041}}'); INSERT INTO alerts VALUES(1197,1773039677.33924508,'{"timestamp": "2026-03-09T08:01:17.339245+0100", "flow_id": 1457046678097690, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 48311, "dest_ip": "134.19.55.199", "dest_port": 30725, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:01:17.339245+0100", "src_ip": "167.94.146.45", "dest_ip": "134.19.55.199", "src_port": 48311, "dest_port": 30725}}'); INSERT INTO alerts VALUES(1198,1773039702.635391951,'{"timestamp": "2026-03-09T08:01:42.635392+0100", "flow_id": 1884563874434118, "event_type": "alert", "src_ip": "195.184.76.161", "src_port": 21137, "dest_ip": "134.19.55.199", "dest_port": 5503, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:01:42.635392+0100", "src_ip": "195.184.76.161", "dest_ip": "134.19.55.199", "src_port": 21137, "dest_port": 5503}}'); INSERT INTO alerts VALUES(1199,1773039722.697057963,'{"timestamp": "2026-03-09T08:02:02.697058+0100", "flow_id": 742045024606951, "event_type": "alert", "src_ip": "147.185.132.52", "src_port": 52132, "dest_ip": "134.19.55.199", "dest_port": 1200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:02:02.697058+0100", "src_ip": "147.185.132.52", "dest_ip": "134.19.55.199", "src_port": 52132, "dest_port": 1200}}'); INSERT INTO alerts VALUES(1200,1773039737.755600929,'{"timestamp": "2026-03-09T08:02:17.755601+0100", "flow_id": 430532058353827, "event_type": "alert", "src_ip": "176.65.148.199", "src_port": 50311, "dest_ip": "134.19.55.199", "dest_port": 123, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 220, "bytes_toclient": 0, "start": "2026-03-09T08:02:17.755601+0100", "src_ip": "176.65.148.199", "dest_ip": "134.19.55.199", "src_port": 50311, "dest_port": 123}}'); INSERT INTO alerts VALUES(1201,1773039737.755600929,'{"timestamp": "2026-03-09T08:02:17.755601+0100", "flow_id": 430532058353827, "event_type": "alert", "src_ip": "176.65.148.199", "src_port": 50311, "dest_ip": "134.19.55.199", "dest_port": 123, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 220, "bytes_toclient": 0, "start": "2026-03-09T08:02:17.755601+0100", "src_ip": "176.65.148.199", "dest_ip": "134.19.55.199", "src_port": 50311, "dest_port": 123}}'); INSERT INTO alerts VALUES(1202,1773039776.867799043,'{"timestamp": "2026-03-09T08:02:56.867799+0100", "flow_id": 67995517604268, "event_type": "alert", "src_ip": "64.62.197.240", "src_port": 46827, "dest_ip": "134.19.55.199", "dest_port": 17, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-09T08:02:56.867799+0100", "src_ip": "64.62.197.240", "dest_ip": "134.19.55.199", "src_port": 46827, "dest_port": 17}}'); INSERT INTO alerts VALUES(1203,1773039799.317321062,'{"timestamp": "2026-03-09T08:03:19.317321+0100", "flow_id": 2207308382666080, "event_type": "alert", "src_ip": "193.163.125.190", "src_port": 50119, "dest_ip": "134.19.55.199", "dest_port": 31402, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:03:19.317321+0100", "src_ip": "193.163.125.190", "dest_ip": "134.19.55.199", "src_port": 50119, "dest_port": 31402}}'); INSERT INTO alerts VALUES(1204,1773039822.215146064,'{"timestamp": "2026-03-09T08:03:42.215146+0100", "flow_id": 1768471430343076, "event_type": "alert", "src_ip": "116.206.241.146", "src_port": 56616, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:03:42.215146+0100", "src_ip": "116.206.241.146", "dest_ip": "134.19.55.199", "src_port": 56616, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1205,1773039871.350219011,'{"timestamp": "2026-03-09T08:04:31.350219+0100", "flow_id": 2067132897431087, "event_type": "alert", "src_ip": "162.217.98.180", "src_port": 52003, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 414, "bytes_toclient": 0, "start": "2026-03-09T08:04:31.350219+0100", "src_ip": "162.217.98.180", "dest_ip": "134.19.55.199", "src_port": 52003, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1206,1773039874.382780076,'{"timestamp": "2026-03-09T08:04:34.382780+0100", "flow_id": 799604040482191, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 14602, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:04:34.382780+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 14602}}'); INSERT INTO alerts VALUES(1207,1773039875.69086194,'{"timestamp": "2026-03-09T08:04:35.690862+0100", "flow_id": 996906719723761, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 53936, "dest_ip": "134.19.55.199", "dest_port": 19654, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400037, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 38", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:04:35.690862+0100", "src_ip": "192.109.200.219", "dest_ip": "134.19.55.199", "src_port": 53936, "dest_port": 19654}}'); INSERT INTO alerts VALUES(1208,1773039875.69086194,'{"timestamp": "2026-03-09T08:04:35.690862+0100", "flow_id": 996906719723761, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 53936, "dest_ip": "134.19.55.199", "dest_port": 19654, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500020, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 11", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:04:35.690862+0100", "src_ip": "192.109.200.219", "dest_ip": "134.19.55.199", "src_port": 53936, "dest_port": 19654}}'); INSERT INTO alerts VALUES(1209,1773039935.648847104,'{"timestamp": "2026-03-09T08:05:35.648847+0100", "flow_id": 2223829232983113, "event_type": "alert", "src_ip": "167.94.146.36", "src_port": 19742, "dest_ip": "134.19.55.199", "dest_port": 4684, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:05:35.648847+0100", "src_ip": "167.94.146.36", "dest_ip": "134.19.55.199", "src_port": 19742, "dest_port": 4684}}'); INSERT INTO alerts VALUES(1210,1773039938.041874886,'{"timestamp": "2026-03-09T08:05:38.041875+0100", "flow_id": 742801992182464, "event_type": "alert", "src_ip": "147.185.132.219", "src_port": 53685, "dest_ip": "134.19.55.199", "dest_port": 10259, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:05:38.041875+0100", "src_ip": "147.185.132.219", "dest_ip": "134.19.55.199", "src_port": 53685, "dest_port": 10259}}'); INSERT INTO alerts VALUES(1211,1773039994.91612506,'{"timestamp": "2026-03-09T08:06:34.916125+0100", "flow_id": 838503580370547, "event_type": "alert", "src_ip": "195.184.76.223", "src_port": 15186, "dest_ip": "134.19.55.199", "dest_port": 5134, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:06:34.916125+0100", "src_ip": "195.184.76.223", "dest_ip": "134.19.55.199", "src_port": 15186, "dest_port": 5134}}'); INSERT INTO alerts VALUES(1212,1773039996.820367098,'{"timestamp": "2026-03-09T08:06:36.820367+0100", "flow_id": 1271650271798537, "event_type": "alert", "src_ip": "198.235.24.113", "src_port": 54391, "dest_ip": "134.19.55.199", "dest_port": 83, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:06:36.820367+0100", "src_ip": "198.235.24.113", "dest_ip": "134.19.55.199", "src_port": 54391, "dest_port": 83}}'); INSERT INTO alerts VALUES(1213,1773040013.067867994,'{"timestamp": "2026-03-09T08:06:53.067868+0100", "flow_id": 1417392390430098, "event_type": "alert", "src_ip": "176.65.148.204", "src_port": 42722, "dest_ip": "134.19.55.199", "dest_port": 25593, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:06:53.067868+0100", "src_ip": "176.65.148.204", "dest_ip": "134.19.55.199", "src_port": 42722, "dest_port": 25593}}'); INSERT INTO alerts VALUES(1214,1773040013.067867994,'{"timestamp": "2026-03-09T08:06:53.067868+0100", "flow_id": 1417392390430098, "event_type": "alert", "src_ip": "176.65.148.204", "src_port": 42722, "dest_ip": "134.19.55.199", "dest_port": 25593, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:06:53.067868+0100", "src_ip": "176.65.148.204", "dest_ip": "134.19.55.199", "src_port": 42722, "dest_port": 25593}}'); INSERT INTO alerts VALUES(1215,1773040040.867050887,'{"timestamp": "2026-03-09T08:07:20.867051+0100", "flow_id": 64785257172452, "event_type": "alert", "src_ip": "64.62.156.156", "src_port": 57149, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:07:20.867051+0100", "src_ip": "64.62.156.156", "dest_ip": "134.19.55.199", "src_port": 57149, "dest_port": 3389}}'); INSERT INTO alerts VALUES(1216,1773040042.437798024,'{"timestamp": "2026-03-09T08:07:22.437798+0100", "flow_id": 754432207696357, "event_type": "alert", "src_ip": "205.210.31.39", "src_port": 52353, "dest_ip": "134.19.55.199", "dest_port": 54528, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:07:22.437798+0100", "src_ip": "205.210.31.39", "dest_ip": "134.19.55.199", "src_port": 52353, "dest_port": 54528}}'); INSERT INTO alerts VALUES(1217,1773040046.91168189,'{"timestamp": "2026-03-09T08:07:26.911682+0100", "flow_id": 1945320149379775, "event_type": "alert", "src_ip": "46.151.182.45", "src_port": 40873, "dest_ip": "134.19.55.199", "dest_port": 20117, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:07:26.911682+0100", "src_ip": "46.151.182.45", "dest_ip": "134.19.55.199", "src_port": 40873, "dest_port": 20117}}'); INSERT INTO alerts VALUES(1218,1773040069.170989991,'{"timestamp": "2026-03-09T08:07:49.170990+0100", "flow_id": 1578822249248313, "event_type": "alert", "src_ip": "65.49.1.140", "src_port": 46348, "dest_ip": "134.19.55.199", "dest_port": 12546, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T08:07:49.170990+0100", "src_ip": "65.49.1.140", "dest_ip": "134.19.55.199", "src_port": 46348, "dest_port": 12546}}'); INSERT INTO alerts VALUES(1219,1773040080.41356206,'{"timestamp": "2026-03-09T08:08:00.413562+0100", "flow_id": 87388816867669, "event_type": "alert", "src_ip": "198.235.24.222", "src_port": 53873, "dest_ip": "134.19.55.199", "dest_port": 2379, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:08:00.413562+0100", "src_ip": "198.235.24.222", "dest_ip": "134.19.55.199", "src_port": 53873, "dest_port": 2379}}'); INSERT INTO alerts VALUES(1220,1773040108.611851931,'{"timestamp": "2026-03-09T08:08:28.611852+0100", "flow_id": 1220510476611222, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 59223, "dest_ip": "134.19.55.199", "dest_port": 20020, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500020, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 11", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:08:28.611852+0100", "src_ip": "192.109.200.219", "dest_ip": "134.19.55.199", "src_port": 59223, "dest_port": 20020}}'); INSERT INTO alerts VALUES(1221,1773040128.252794981,'{"timestamp": "2026-03-09T08:08:48.252795+0100", "flow_id": 241324241480974, "event_type": "alert", "src_ip": "147.185.132.63", "src_port": 52213, "dest_ip": "134.19.55.199", "dest_port": 389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:08:48.252795+0100", "src_ip": "147.185.132.63", "dest_ip": "134.19.55.199", "src_port": 52213, "dest_port": 389}}'); INSERT INTO alerts VALUES(1222,1773040145.745502949,'{"timestamp": "2026-03-09T08:09:05.745503+0100", "flow_id": 387165337958083, "event_type": "alert", "src_ip": "65.49.1.227", "src_port": 39669, "dest_ip": "134.19.55.199", "dest_port": 21, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:09:05.745503+0100", "src_ip": "65.49.1.227", "dest_ip": "134.19.55.199", "src_port": 39669, "dest_port": 21}}'); INSERT INTO alerts VALUES(1223,1773040257.816510916,'{"timestamp": "2026-03-09T08:10:57.816511+0100", "flow_id": 410664507735585, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 55735, "dest_ip": "134.19.55.199", "dest_port": 42091, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:10:57.816511+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 55735, "dest_port": 42091}}'); INSERT INTO alerts VALUES(1224,1773040271.500108958,'{"timestamp": "2026-03-09T08:11:11.500109+0100", "flow_id": 2147955006571155, "event_type": "alert", "src_ip": "46.151.182.160", "src_port": 40173, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:11:11.500109+0100", "src_ip": "46.151.182.160", "dest_ip": "134.19.55.199", "src_port": 40173, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1225,1773040271.500108958,'{"timestamp": "2026-03-09T08:11:11.500109+0100", "flow_id": 2147955006571155, "event_type": "alert", "src_ip": "46.151.182.160", "src_port": 40173, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:11:11.500109+0100", "src_ip": "46.151.182.160", "dest_ip": "134.19.55.199", "src_port": 40173, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1226,1773040271.799360991,'{"timestamp": "2026-03-09T08:11:11.799361+0100", "flow_id": 2025858625180883, "event_type": "alert", "src_ip": "185.242.226.97", "src_port": 55400, "dest_ip": "134.19.55.199", "dest_port": 40975, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-09T08:11:11.799361+0100", "src_ip": "185.242.226.97", "dest_ip": "134.19.55.199", "src_port": 55400, "dest_port": 40975}}'); INSERT INTO alerts VALUES(1227,1773040285.711632014,'{"timestamp": "2026-03-09T08:11:25.711632+0100", "flow_id": 1649063001803656, "event_type": "alert", "src_ip": "176.65.132.143", "src_port": 36677, "dest_ip": "134.19.55.199", "dest_port": 2815, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:11:25.711632+0100", "src_ip": "176.65.132.143", "dest_ip": "134.19.55.199", "src_port": 36677, "dest_port": 2815}}'); INSERT INTO alerts VALUES(1228,1773040287.615003109,'{"timestamp": "2026-03-09T08:11:27.615003+0100", "flow_id": 2078471032860648, "event_type": "alert", "src_ip": "205.210.31.40", "src_port": 52111, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:11:27.615003+0100", "src_ip": "205.210.31.40", "dest_ip": "134.19.55.199", "src_port": 52111, "dest_port": 80}}'); INSERT INTO alerts VALUES(1229,1773040302.220082044,'{"timestamp": "2026-03-09T08:11:42.220082+0100", "flow_id": 1789670360002776, "event_type": "alert", "src_ip": "205.210.31.69", "src_port": 51266, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:11:42.220082+0100", "src_ip": "205.210.31.69", "dest_ip": "134.19.55.199", "src_port": 51266, "dest_port": 5555}}'); INSERT INTO alerts VALUES(1230,1773040322.792069911,'{"timestamp": "2026-03-09T08:12:02.792070+0100", "flow_id": 587166320839110, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 22808, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:12:02.792070+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 22808}}'); INSERT INTO alerts VALUES(1231,1773040322.792069911,'{"timestamp": "2026-03-09T08:12:02.792070+0100", "flow_id": 587166320839110, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 22808, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:12:02.792070+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 22808}}'); INSERT INTO alerts VALUES(1232,1773040345.620853901,'{"timestamp": "2026-03-09T08:12:25.620854+0100", "flow_id": 414750391926245, "event_type": "alert", "src_ip": "66.132.153.151", "src_port": 51707, "dest_ip": "134.19.55.199", "dest_port": 17186, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 92, "bytes_toclient": 0, "start": "2026-03-09T08:12:25.620854+0100", "src_ip": "66.132.153.151", "dest_ip": "134.19.55.199", "src_port": 51707, "dest_port": 17186}}'); INSERT INTO alerts VALUES(1233,1773040395.581067085,'{"timestamp": "2026-03-09T08:13:15.581067+0100", "flow_id": 1088291421242003, "event_type": "alert", "src_ip": "176.65.149.45", "src_port": 51327, "dest_ip": "134.19.55.199", "dest_port": 8081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:13:15.581067+0100", "src_ip": "176.65.149.45", "dest_ip": "134.19.55.199", "src_port": 51327, "dest_port": 8081}}'); INSERT INTO alerts VALUES(1234,1773040396.852627038,'{"timestamp": "2026-03-09T08:13:16.852627+0100", "flow_id": 1128732110910352, "event_type": "alert", "src_ip": "198.235.24.110", "src_port": 51527, "dest_ip": "134.19.55.199", "dest_port": 2525, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:13:16.852627+0100", "src_ip": "198.235.24.110", "dest_ip": "134.19.55.199", "src_port": 51527, "dest_port": 2525}}'); INSERT INTO alerts VALUES(1235,1773040397.351819038,'{"timestamp": "2026-03-09T08:13:17.351819+0100", "flow_id": 1511052875369634, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 40238, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:13:17.351819+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 40238, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1236,1773040397.351819038,'{"timestamp": "2026-03-09T08:13:17.351819+0100", "flow_id": 1511052875369634, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 40238, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:13:17.351819+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 40238, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1237,1773040410.096293926,'{"timestamp": "2026-03-09T08:13:30.096294+0100", "flow_id": 695056545007503, "event_type": "alert", "src_ip": "198.235.24.244", "src_port": 55043, "dest_ip": "134.19.55.199", "dest_port": 10000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:13:30.096294+0100", "src_ip": "198.235.24.244", "dest_ip": "134.19.55.199", "src_port": 55043, "dest_port": 10000}}'); INSERT INTO alerts VALUES(1238,1773040446.095185042,'{"timestamp": "2026-03-09T08:14:06.095185+0100", "flow_id": 1816192409743016, "event_type": "alert", "src_ip": "205.210.31.207", "src_port": 49322, "dest_ip": "134.19.55.199", "dest_port": 25827, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:14:06.095185+0100", "src_ip": "205.210.31.207", "dest_ip": "134.19.55.199", "src_port": 49322, "dest_port": 25827}}'); INSERT INTO alerts VALUES(1239,1773040451.893527985,'{"timestamp": "2026-03-09T08:14:11.893528+0100", "flow_id": 1022926160155108, "event_type": "alert", "src_ip": "198.235.24.54", "src_port": 55088, "dest_ip": "134.19.55.199", "dest_port": 21, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:14:11.893528+0100", "src_ip": "198.235.24.54", "dest_ip": "134.19.55.199", "src_port": 55088, "dest_port": 21}}'); INSERT INTO alerts VALUES(1240,1773040474.193777085,'{"timestamp": "2026-03-09T08:14:34.193777+0100", "flow_id": 832270160891229, "event_type": "alert", "src_ip": "195.184.76.76", "src_port": 5101, "dest_ip": "134.19.55.199", "dest_port": 21242, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:14:34.193777+0100", "src_ip": "195.184.76.76", "dest_ip": "134.19.55.199", "src_port": 5101, "dest_port": 21242}}'); INSERT INTO alerts VALUES(1241,1773040569.327961921,'{"timestamp": "2026-03-09T08:16:09.327962+0100", "flow_id": 282690442345109, "event_type": "alert", "src_ip": "167.94.138.146", "src_port": 1950, "dest_ip": "134.19.55.199", "dest_port": 17185, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 92, "bytes_toclient": 0, "start": "2026-03-09T08:16:09.327962+0100", "src_ip": "167.94.138.146", "dest_ip": "134.19.55.199", "src_port": 1950, "dest_port": 17185}}'); INSERT INTO alerts VALUES(1242,1773040580.172449111,'{"timestamp": "2026-03-09T08:16:20.172449+0100", "flow_id": 1303612902024532, "event_type": "alert", "src_ip": "182.8.196.168", "src_port": 61875, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:16:20.172449+0100", "src_ip": "182.8.196.168", "dest_ip": "134.19.55.199", "src_port": 61875, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1243,1773040599.070158005,'{"timestamp": "2026-03-09T08:16:39.070158+0100", "flow_id": 1990179096838814, "event_type": "alert", "src_ip": "64.89.163.244", "src_port": 40379, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:16:39.070158+0100", "src_ip": "64.89.163.244", "dest_ip": "134.19.55.199", "src_port": 40379, "dest_port": 27017}}'); INSERT INTO alerts VALUES(1244,1773040613.926537036,'{"timestamp": "2026-03-09T08:16:53.926537+0100", "flow_id": 1446174963685519, "event_type": "alert", "src_ip": "195.184.76.175", "src_port": 50688, "dest_ip": "134.19.55.199", "dest_port": 557, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:16:53.926537+0100", "src_ip": "195.184.76.175", "dest_ip": "134.19.55.199", "src_port": 50688, "dest_port": 557}}'); INSERT INTO alerts VALUES(1245,1773040622.872776985,'{"timestamp": "2026-03-09T08:17:02.872777+0100", "flow_id": 1778227658810771, "event_type": "alert", "src_ip": "147.185.132.75", "src_port": 54279, "dest_ip": "134.19.55.199", "dest_port": 23556, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:17:02.872777+0100", "src_ip": "147.185.132.75", "dest_ip": "134.19.55.199", "src_port": 54279, "dest_port": 23556}}'); INSERT INTO alerts VALUES(1246,1773040640.409400939,'{"timestamp": "2026-03-09T08:17:20.409401+0100", "flow_id": 63154151051705, "event_type": "alert", "src_ip": "35.172.245.152", "src_port": 443, "dest_ip": "192.168.2.37", "dest_port": 64494, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2031231, "rev": 3, "signature": "ET INFO Observed ZeroSSL SSL/TLS Certificate", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2020_11_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_12_01"]}}, "ts_progress": "client_handshake_done", "tc_progress": "server_handshake_done", "tls": {"subject": "CN=*.cheqzone.com", "issuerdn": "C=AT, O=ZeroSSL, CN=ZeroSSL ECC Domain Secure Site CA", "subjectaltname": ["*.cheqzone.com"], "serial": "00:DA:C9:89:D0:F2:15:4A:42:69:57:8A:B8:13:09:61:7A", "fingerprint": "59:95:e2:6e:bd:34:6f:42:1d:db:4d:53:cb:ed:04:c6:eb:f4:1c:2a", "sni": "obs.cheqzone.com", "version": "TLS 1.2", "notbefore": "2026-02-04T00:00:00", "notafter": "2026-05-05T23:59:59", "ja3": {"hash": "773906b0efdefa24a7f2b8eb6985bf37", "string": "771,4865-4866-4867-49196-49195-52393-49200-49199-52392-49162-49161-49172-49171-157-156-53-47-49160-49170-10,0-23-65281-10-11-16-5-13-18-51-45-43-27-21,29-23-24-25,0"}, "ja3s": {"hash": "80d47c47e3ce91bc3bd0a026dbd1664d", "string": "771,49196,5-65281-16"}, "ja4": "t13d2014h2_a09f3c656075_14788d8d241b", "client_alpns": ["h2", "http/1.1"], "server_alpns": ["h2"]}, "app_proto": "tls", "direction": "to_client", "flow": {"pkts_toserver": 3, "pkts_toclient": 5, "bytes_toserver": 685, "bytes_toclient": 3718, "start": "2026-03-09T08:17:20.211312+0100", "src_ip": "192.168.2.37", "dest_ip": "35.172.245.152", "src_port": 64494, "dest_port": 443}}'); INSERT INTO alerts VALUES(1247,1773040640.51050806,'{"timestamp": "2026-03-09T08:17:20.510508+0100", "flow_id": 221049189559259, "event_type": "alert", "src_ip": "52.45.196.192", "src_port": 443, "dest_ip": "192.168.2.37", "dest_port": 64495, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2031231, "rev": 3, "signature": "ET INFO Observed ZeroSSL SSL/TLS Certificate", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2020_11_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_12_01"]}}, "ts_progress": "client_handshake_done", "tc_progress": "server_handshake_done", "tls": {"subject": "CN=*.cheqzone.com", "issuerdn": "C=AT, O=ZeroSSL, CN=ZeroSSL ECC Domain Secure Site CA", "subjectaltname": ["*.cheqzone.com"], "serial": "00:DA:C9:89:D0:F2:15:4A:42:69:57:8A:B8:13:09:61:7A", "fingerprint": "59:95:e2:6e:bd:34:6f:42:1d:db:4d:53:cb:ed:04:c6:eb:f4:1c:2a", "sni": "obs.cheqzone.com", "version": "TLS 1.2", "notbefore": "2026-02-04T00:00:00", "notafter": "2026-05-05T23:59:59", "ja3": {"hash": "773906b0efdefa24a7f2b8eb6985bf37", "string": "771,4865-4866-4867-49196-49195-52393-49200-49199-52392-49162-49161-49172-49171-157-156-53-47-49160-49170-10,0-23-65281-10-11-16-5-13-18-51-45-43-27-21,29-23-24-25,0"}, "ja3s": {"hash": "80d47c47e3ce91bc3bd0a026dbd1664d", "string": "771,49196,5-65281-16"}, "ja4": "t13d2014h2_a09f3c656075_14788d8d241b", "client_alpns": ["h2", "http/1.1"], "server_alpns": ["h2"]}, "app_proto": "tls", "direction": "to_client", "flow": {"pkts_toserver": 3, "pkts_toclient": 5, "bytes_toserver": 685, "bytes_toclient": 3719, "start": "2026-03-09T08:17:20.313611+0100", "src_ip": "192.168.2.37", "dest_ip": "52.45.196.192", "src_port": 64495, "dest_port": 443}}'); INSERT INTO alerts VALUES(1248,1773040642.559329987,'{"timestamp": "2026-03-09T08:17:22.559330+0100", "flow_id": 799259026881546, "event_type": "alert", "src_ip": "50.16.211.97", "src_port": 443, "dest_ip": "192.168.2.37", "dest_port": 64499, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2031231, "rev": 3, "signature": "ET INFO Observed ZeroSSL SSL/TLS Certificate", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2020_11_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_12_01"]}}, "ts_progress": "client_handshake_done", "tc_progress": "server_handshake_done", "tls": {"subject": "CN=*.cheqzone.com", "issuerdn": "C=AT, O=ZeroSSL, CN=ZeroSSL ECC Domain Secure Site CA", "subjectaltname": ["*.cheqzone.com"], "serial": "00:DA:C9:89:D0:F2:15:4A:42:69:57:8A:B8:13:09:61:7A", "fingerprint": "59:95:e2:6e:bd:34:6f:42:1d:db:4d:53:cb:ed:04:c6:eb:f4:1c:2a", "sni": "obs.cheqzone.com", "version": "TLS 1.2", "notbefore": "2026-02-04T00:00:00", "notafter": "2026-05-05T23:59:59", "ja3": {"hash": "773906b0efdefa24a7f2b8eb6985bf37", "string": "771,4865-4866-4867-49196-49195-52393-49200-49199-52392-49162-49161-49172-49171-157-156-53-47-49160-49170-10,0-23-65281-10-11-16-5-13-18-51-45-43-27-21,29-23-24-25,0"}, "ja3s": {"hash": "80d47c47e3ce91bc3bd0a026dbd1664d", "string": "771,49196,5-65281-16"}, "ja4": "t13d2014h2_a09f3c656075_14788d8d241b", "client_alpns": ["h2", "http/1.1"], "server_alpns": ["h2"]}, "app_proto": "tls", "direction": "to_client", "flow": {"pkts_toserver": 3, "pkts_toclient": 5, "bytes_toserver": 685, "bytes_toclient": 3718, "start": "2026-03-09T08:17:22.317163+0100", "src_ip": "192.168.2.37", "dest_ip": "50.16.211.97", "src_port": 64499, "dest_port": 443}}'); INSERT INTO alerts VALUES(1249,1773040644.521404027,'{"timestamp": "2026-03-09T08:17:24.521404+0100", "flow_id": 1389010381583101, "event_type": "alert", "src_ip": "34.199.234.25", "src_port": 443, "dest_ip": "192.168.2.37", "dest_port": 64508, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2031231, "rev": 3, "signature": "ET INFO Observed ZeroSSL SSL/TLS Certificate", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2020_11_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_12_01"]}}, "ts_progress": "client_handshake_done", "tc_progress": "server_handshake_done", "tls": {"subject": "CN=*.cheqzone.com", "issuerdn": "C=AT, O=ZeroSSL, CN=ZeroSSL ECC Domain Secure Site CA", "subjectaltname": ["*.cheqzone.com"], "serial": "00:DA:C9:89:D0:F2:15:4A:42:69:57:8A:B8:13:09:61:7A", "fingerprint": "59:95:e2:6e:bd:34:6f:42:1d:db:4d:53:cb:ed:04:c6:eb:f4:1c:2a", "sni": "obs.cheqzone.com", "version": "TLS 1.2", "notbefore": "2026-02-04T00:00:00", "notafter": "2026-05-05T23:59:59", "ja3": {"hash": "773906b0efdefa24a7f2b8eb6985bf37", "string": "771,4865-4866-4867-49196-49195-52393-49200-49199-52392-49162-49161-49172-49171-157-156-53-47-49160-49170-10,0-23-65281-10-11-16-5-13-18-51-45-43-27-21,29-23-24-25,0"}, "ja3s": {"hash": "80d47c47e3ce91bc3bd0a026dbd1664d", "string": "771,49196,5-65281-16"}, "ja4": "t13d2014h2_a09f3c656075_14788d8d241b", "client_alpns": ["h2", "http/1.1"], "server_alpns": ["h2"]}, "app_proto": "tls", "direction": "to_client", "flow": {"pkts_toserver": 3, "pkts_toclient": 5, "bytes_toserver": 685, "bytes_toclient": 3718, "start": "2026-03-09T08:17:24.323404+0100", "src_ip": "192.168.2.37", "dest_ip": "34.199.234.25", "src_port": 64508, "dest_port": 443}}'); INSERT INTO alerts VALUES(1250,1773040646.520379067,'{"timestamp": "2026-03-09T08:17:26.520379+0100", "flow_id": 1961294632668276, "event_type": "alert", "src_ip": "54.83.110.109", "src_port": 443, "dest_ip": "192.168.2.37", "dest_port": 64509, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2031231, "rev": 3, "signature": "ET INFO Observed ZeroSSL SSL/TLS Certificate", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2020_11_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_12_01"]}}, "ts_progress": "client_handshake_done", "tc_progress": "server_handshake_done", "tls": {"subject": "CN=*.cheqzone.com", "issuerdn": "C=AT, O=ZeroSSL, CN=ZeroSSL ECC Domain Secure Site CA", "subjectaltname": ["*.cheqzone.com"], "serial": "00:DA:C9:89:D0:F2:15:4A:42:69:57:8A:B8:13:09:61:7A", "fingerprint": "59:95:e2:6e:bd:34:6f:42:1d:db:4d:53:cb:ed:04:c6:eb:f4:1c:2a", "sni": "obs.cheqzone.com", "version": "TLS 1.2", "notbefore": "2026-02-04T00:00:00", "notafter": "2026-05-05T23:59:59", "ja3": {"hash": "773906b0efdefa24a7f2b8eb6985bf37", "string": "771,4865-4866-4867-49196-49195-52393-49200-49199-52392-49162-49161-49172-49171-157-156-53-47-49160-49170-10,0-23-65281-10-11-16-5-13-18-51-45-43-27-21,29-23-24-25,0"}, "ja3s": {"hash": "80d47c47e3ce91bc3bd0a026dbd1664d", "string": "771,49196,5-65281-16"}, "ja4": "t13d2014h2_a09f3c656075_14788d8d241b", "client_alpns": ["h2", "http/1.1"], "server_alpns": ["h2"]}, "app_proto": "tls", "direction": "to_client", "flow": {"pkts_toserver": 3, "pkts_toclient": 5, "bytes_toserver": 685, "bytes_toclient": 3719, "start": "2026-03-09T08:17:26.325577+0100", "src_ip": "192.168.2.37", "dest_ip": "54.83.110.109", "src_port": 64509, "dest_port": 443}}'); INSERT INTO alerts VALUES(1251,1773040648.534176111,'{"timestamp": "2026-03-09T08:17:28.534176+0100", "flow_id": 48970587830873, "event_type": "alert", "src_ip": "3.227.190.204", "src_port": 443, "dest_ip": "192.168.2.37", "dest_port": 64510, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2031231, "rev": 3, "signature": "ET INFO Observed ZeroSSL SSL/TLS Certificate", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2020_11_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_12_01"]}}, "ts_progress": "client_handshake_done", "tc_progress": "server_handshake_done", "tls": {"subject": "CN=*.cheqzone.com", "issuerdn": "C=AT, O=ZeroSSL, CN=ZeroSSL ECC Domain Secure Site CA", "subjectaltname": ["*.cheqzone.com"], "serial": "00:DA:C9:89:D0:F2:15:4A:42:69:57:8A:B8:13:09:61:7A", "fingerprint": "59:95:e2:6e:bd:34:6f:42:1d:db:4d:53:cb:ed:04:c6:eb:f4:1c:2a", "sni": "obs.cheqzone.com", "version": "TLS 1.2", "notbefore": "2026-02-04T00:00:00", "notafter": "2026-05-05T23:59:59", "ja3": {"hash": "773906b0efdefa24a7f2b8eb6985bf37", "string": "771,4865-4866-4867-49196-49195-52393-49200-49199-52392-49162-49161-49172-49171-157-156-53-47-49160-49170-10,0-23-65281-10-11-16-5-13-18-51-45-43-27-21,29-23-24-25,0"}, "ja3s": {"hash": "80d47c47e3ce91bc3bd0a026dbd1664d", "string": "771,49196,5-65281-16"}, "ja4": "t13d2014h2_a09f3c656075_14788d8d241b", "client_alpns": ["h2", "http/1.1"], "server_alpns": ["h2"]}, "app_proto": "tls", "direction": "to_client", "flow": {"pkts_toserver": 3, "pkts_toclient": 5, "bytes_toserver": 685, "bytes_toclient": 3718, "start": "2026-03-09T08:17:28.339081+0100", "src_ip": "192.168.2.37", "dest_ip": "3.227.190.204", "src_port": 64510, "dest_port": 443}}'); INSERT INTO alerts VALUES(1252,1773040751.791302919,'{"timestamp": "2026-03-09T08:19:11.791303+0100", "flow_id": 1991249741933838, "event_type": "alert", "src_ip": "88.210.63.192", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44350, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:19:11.791303+0100", "src_ip": "88.210.63.192", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44350}}'); INSERT INTO alerts VALUES(1253,1773040757.067863942,'{"timestamp": "2026-03-09T08:19:17.067864+0100", "flow_id": 1417377473694561, "event_type": "alert", "src_ip": "193.163.125.199", "src_port": 41587, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:19:17.067864+0100", "src_ip": "193.163.125.199", "dest_ip": "134.19.55.199", "src_port": 41587, "dest_port": 27017}}'); INSERT INTO alerts VALUES(1254,1773040766.319267989,'{"timestamp": "2026-03-09T08:19:26.319268+0100", "flow_id": 1934196284869023, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44366, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:19:26.319268+0100", "src_ip": "185.156.73.86", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44366}}'); INSERT INTO alerts VALUES(1255,1773040795.66325903,'{"timestamp": "2026-03-09T08:19:55.663259+0100", "flow_id": 878354269268027, "event_type": "alert", "src_ip": "195.184.76.84", "src_port": 38823, "dest_ip": "134.19.55.199", "dest_port": 1701, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:19:55.663259+0100", "src_ip": "195.184.76.84", "dest_ip": "134.19.55.199", "src_port": 38823, "dest_port": 1701}}'); INSERT INTO alerts VALUES(1256,1773040802.787348031,'{"timestamp": "2026-03-09T08:20:02.787348+0100", "flow_id": 566885206029434, "event_type": "alert", "src_ip": "147.185.132.117", "src_port": 53882, "dest_ip": "134.19.55.199", "dest_port": 52590, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:20:02.787348+0100", "src_ip": "147.185.132.117", "dest_ip": "134.19.55.199", "src_port": 53882, "dest_port": 52590}}'); INSERT INTO alerts VALUES(1257,1773040821.892981052,'{"timestamp": "2026-03-09T08:20:21.892981+0100", "flow_id": 1583527321866087, "event_type": "alert", "src_ip": "193.163.125.202", "src_port": 59750, "dest_ip": "134.19.55.199", "dest_port": 38881, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:20:21.892981+0100", "src_ip": "193.163.125.202", "dest_ip": "134.19.55.199", "src_port": 59750, "dest_port": 38881}}'); INSERT INTO alerts VALUES(1258,1773040824.683183908,'{"timestamp": "2026-03-09T08:20:24.683184+0100", "flow_id": 119504796336149, "event_type": "alert", "src_ip": "198.235.24.254", "src_port": 50600, "dest_ip": "134.19.55.199", "dest_port": 123, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ntp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T08:20:24.683184+0100", "src_ip": "198.235.24.254", "dest_ip": "134.19.55.199", "src_port": 50600, "dest_port": 123}}'); INSERT INTO alerts VALUES(1259,1773040857.843436003,'{"timestamp": "2026-03-09T08:20:57.843436+0100", "flow_id": 526307881926403, "event_type": "alert", "src_ip": "91.196.152.213", "src_port": 26038, "dest_ip": "134.19.55.199", "dest_port": 17754, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:20:57.843436+0100", "src_ip": "91.196.152.213", "dest_ip": "134.19.55.199", "src_port": 26038, "dest_port": 17754}}'); INSERT INTO alerts VALUES(1260,1773040858.916147948,'{"timestamp": "2026-03-09T08:20:58.916148+0100", "flow_id": 838605167066991, "event_type": "alert", "src_ip": "91.196.152.191", "src_port": 45436, "dest_ip": "134.19.55.199", "dest_port": 20014, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:20:58.916148+0100", "src_ip": "91.196.152.191", "dest_ip": "134.19.55.199", "src_port": 45436, "dest_port": 20014}}'); INSERT INTO alerts VALUES(1261,1773040868.873147964,'{"timestamp": "2026-03-09T08:21:08.873148+0100", "flow_id": 1216868862984754, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 47704, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54806, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:21:08.873148+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 47704, "dest_port": 53}}'); INSERT INTO alerts VALUES(1262,1773040868.873148919,'{"timestamp": "2026-03-09T08:21:08.873149+0100", "flow_id": 1216871770274383, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41744, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11760, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:21:08.873149+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41744, "dest_port": 53}}'); INSERT INTO alerts VALUES(1263,1773040872.309253931,'{"timestamp": "2026-03-09T08:21:12.309254+0100", "flow_id": 202337510225266, "event_type": "alert", "src_ip": "205.210.31.76", "src_port": 51916, "dest_ip": "134.19.55.199", "dest_port": 17516, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:21:12.309254+0100", "src_ip": "205.210.31.76", "dest_ip": "134.19.55.199", "src_port": 51916, "dest_port": 17516}}'); INSERT INTO alerts VALUES(1264,1773040876.148085117,'{"timestamp": "2026-03-09T08:21:16.148085+0100", "flow_id": 1198971761453944, "event_type": "alert", "src_ip": "205.210.31.253", "src_port": 51133, "dest_ip": "134.19.55.199", "dest_port": 10250, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:21:16.148085+0100", "src_ip": "205.210.31.253", "dest_ip": "134.19.55.199", "src_port": 51133, "dest_port": 10250}}'); INSERT INTO alerts VALUES(1265,1773040958.36405611,'{"timestamp": "2026-03-09T08:22:38.364056+0100", "flow_id": 1845087644613330, "event_type": "alert", "src_ip": "167.94.146.35", "src_port": 24082, "dest_ip": "134.19.55.199", "dest_port": 32668, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:22:38.364056+0100", "src_ip": "167.94.146.35", "dest_ip": "134.19.55.199", "src_port": 24082, "dest_port": 32668}}'); INSERT INTO alerts VALUES(1266,1773040990.759915113,'{"timestamp": "2026-03-09T08:23:10.759915+0100", "flow_id": 1856436995537501, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59681, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59922, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T08:23:10.759915+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59681, "dest_port": 53}}'); INSERT INTO alerts VALUES(1267,1773040990.759916067,'{"timestamp": "2026-03-09T08:23:10.759916+0100", "flow_id": 1856440529942438, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39405, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2502, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T08:23:10.759916+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39405, "dest_port": 53}}'); INSERT INTO alerts VALUES(1268,1773040990.760206937,'{"timestamp": "2026-03-09T08:23:10.760207+0100", "flow_id": 1857692368689743, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39483, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38284, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T08:23:10.760207+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39483, "dest_port": 53}}'); INSERT INTO alerts VALUES(1269,1773041008.91616106,'{"timestamp": "2026-03-09T08:23:28.916161+0100", "flow_id": 275708336979879, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33869, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60175, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:23:28.916161+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33869, "dest_port": 53}}'); INSERT INTO alerts VALUES(1270,1773041008.91616106,'{"timestamp": "2026-03-09T08:23:28.916161+0100", "flow_id": 275710868768324, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16380, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:23:28.916161+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59927, "dest_port": 53}}'); INSERT INTO alerts VALUES(1271,1773041067.202440977,'{"timestamp": "2026-03-09T08:24:27.202441+0100", "flow_id": 869480543312571, "event_type": "alert", "src_ip": "167.94.138.129", "src_port": 47516, "dest_ip": "134.19.55.199", "dest_port": 9142, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:24:27.202441+0100", "src_ip": "167.94.138.129", "dest_ip": "134.19.55.199", "src_port": 47516, "dest_port": 9142}}'); INSERT INTO alerts VALUES(1272,1773041096.384428978,'{"timestamp": "2026-03-09T08:24:56.384429+0100", "flow_id": 243736419701380, "event_type": "alert", "src_ip": "167.94.146.42", "src_port": 8475, "dest_ip": "134.19.55.199", "dest_port": 31858, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:24:56.384429+0100", "src_ip": "167.94.146.42", "dest_ip": "134.19.55.199", "src_port": 8475, "dest_port": 31858}}'); INSERT INTO alerts VALUES(1273,1773041148.964375973,'{"timestamp": "2026-03-09T08:25:48.964376+0100", "flow_id": 1327215587459947, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34875, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23253, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:25:48.964376+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34875, "dest_port": 53}}'); INSERT INTO alerts VALUES(1274,1773041148.964376926,'{"timestamp": "2026-03-09T08:25:48.964377+0100", "flow_id": 1327221745406649, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34900, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19988, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:25:48.964377+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34900, "dest_port": 53}}'); INSERT INTO alerts VALUES(1275,1773041162.195710898,'{"timestamp": "2026-03-09T08:26:02.195711+0100", "flow_id": 840575139528657, "event_type": "alert", "src_ip": "198.235.24.121", "src_port": 51038, "dest_ip": "134.19.55.199", "dest_port": 10002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:26:02.195711+0100", "src_ip": "198.235.24.121", "dest_ip": "134.19.55.199", "src_port": 51038, "dest_port": 10002}}'); INSERT INTO alerts VALUES(1276,1773041189.314227105,'{"timestamp": "2026-03-09T08:26:29.314227+0100", "flow_id": 1631070940427396, "event_type": "alert", "src_ip": "14.222.46.148", "src_port": 53530, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:26:29.314227+0100", "src_ip": "14.222.46.148", "dest_ip": "134.19.55.199", "src_port": 53530, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1277,1773041202.865797996,'{"timestamp": "2026-03-09T08:26:42.865798+0100", "flow_id": 622350102821743, "event_type": "alert", "src_ip": "185.93.89.79", "src_port": 54679, "dest_ip": "134.19.55.199", "dest_port": 4444, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400033, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 34", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:26:42.865798+0100", "src_ip": "185.93.89.79", "dest_ip": "134.19.55.199", "src_port": 54679, "dest_port": 4444}}'); INSERT INTO alerts VALUES(1278,1773041256.545604944,'{"timestamp": "2026-03-09T08:27:36.545605+0100", "flow_id": 91559081188074, "event_type": "alert", "src_ip": "64.62.156.198", "src_port": 47498, "dest_ip": "134.19.55.199", "dest_port": 8443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:27:36.545605+0100", "src_ip": "64.62.156.198", "dest_ip": "134.19.55.199", "src_port": 47498, "dest_port": 8443}}'); INSERT INTO alerts VALUES(1279,1773041279.871537923,'{"timestamp": "2026-03-09T08:27:59.871538+0100", "flow_id": 2054378171390796, "event_type": "alert", "src_ip": "64.89.163.85", "src_port": 41156, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:27:59.871538+0100", "src_ip": "64.89.163.85", "dest_ip": "134.19.55.199", "src_port": 41156, "dest_port": 27017}}'); INSERT INTO alerts VALUES(1280,1773041289.013734103,'{"timestamp": "2026-03-09T08:28:09.013734+0100", "flow_id": 340466134881160, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59269, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24513, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:28:09.013734+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59269, "dest_port": 53}}'); INSERT INTO alerts VALUES(1281,1773041289.014020919,'{"timestamp": "2026-03-09T08:28:09.014021+0100", "flow_id": 341697793652758, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51009, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25098, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:28:09.014021+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51009, "dest_port": 53}}'); INSERT INTO alerts VALUES(1282,1773041290.671058894,'{"timestamp": "2026-03-09T08:28:10.671059+0100", "flow_id": 630377447166040, "event_type": "alert", "src_ip": "195.184.76.129", "src_port": 31242, "dest_ip": "134.19.55.199", "dest_port": 6717, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:28:10.671059+0100", "src_ip": "195.184.76.129", "dest_ip": "134.19.55.199", "src_port": 31242, "dest_port": 6717}}'); INSERT INTO alerts VALUES(1283,1773041314.347446919,'{"timestamp": "2026-03-09T08:28:34.347447+0100", "flow_id": 647849948446045, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 3001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:28:34.347447+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 3001}}'); INSERT INTO alerts VALUES(1284,1773041314.347446919,'{"timestamp": "2026-03-09T08:28:34.347447+0100", "flow_id": 647849948446045, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 3001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:28:34.347447+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 3001}}'); INSERT INTO alerts VALUES(1285,1773041347.472271919,'{"timestamp": "2026-03-09T08:29:07.472272+0100", "flow_id": 902493768382772, "event_type": "alert", "src_ip": "45.142.154.70", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 36816, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:29:07.472272+0100", "src_ip": "45.142.154.70", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 36816}}'); INSERT INTO alerts VALUES(1286,1773041368.282804012,'{"timestamp": "2026-03-09T08:29:28.282804+0100", "flow_id": 88735751110974, "event_type": "alert", "src_ip": "147.185.132.70", "src_port": 52761, "dest_ip": "134.19.55.199", "dest_port": 10000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:29:28.282804+0100", "src_ip": "147.185.132.70", "dest_ip": "134.19.55.199", "src_port": 52761, "dest_port": 10000}}'); INSERT INTO alerts VALUES(1287,1773041402.644164086,'{"timestamp": "2026-03-09T08:30:02.644164+0100", "flow_id": 796341428078655, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 54772, "dest_ip": "134.19.55.199", "dest_port": 10001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:30:02.644164+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.55.199", "src_port": 54772, "dest_port": 10001}}'); INSERT INTO alerts VALUES(1288,1773041402.644164086,'{"timestamp": "2026-03-09T08:30:02.644164+0100", "flow_id": 796341428078655, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 54772, "dest_ip": "134.19.55.199", "dest_port": 10001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:30:02.644164+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.55.199", "src_port": 54772, "dest_port": 10001}}'); INSERT INTO alerts VALUES(1289,1773041429.080955982,'{"timestamp": "2026-03-09T08:30:29.080956+0100", "flow_id": 1473603638744755, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 38256, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63791, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:30:29.080956+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 38256, "dest_port": 53}}'); INSERT INTO alerts VALUES(1290,1773041429.080956935,'{"timestamp": "2026-03-09T08:30:29.080957+0100", "flow_id": 1473608729112440, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59317, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10361, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:30:29.080957+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59317, "dest_port": 53}}'); INSERT INTO alerts VALUES(1291,1773041547.019571065,'{"timestamp": "2026-03-09T08:32:27.019571+0100", "flow_id": 928482546571977, "event_type": "alert", "src_ip": "167.94.146.44", "src_port": 16105, "dest_ip": "134.19.55.199", "dest_port": 36827, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:32:27.019571+0100", "src_ip": "167.94.146.44", "dest_ip": "134.19.55.199", "src_port": 16105, "dest_port": 36827}}'); INSERT INTO alerts VALUES(1292,1773041569.147991895,'{"timestamp": "2026-03-09T08:32:49.147992+0100", "flow_id": 354147553356788, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 54260, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25529, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:32:49.147992+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 54260, "dest_port": 53}}'); INSERT INTO alerts VALUES(1293,1773041569.147993088,'{"timestamp": "2026-03-09T08:32:49.147993+0100", "flow_id": 354153696427483, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57311, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4840, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:32:49.147993+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57311, "dest_port": 53}}'); INSERT INTO alerts VALUES(1294,1773041569.390640021,'{"timestamp": "2026-03-09T08:32:49.390640+0100", "flow_id": 551887962133970, "event_type": "alert", "src_ip": "45.135.194.48", "src_port": 56662, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:32:49.390640+0100", "src_ip": "45.135.194.48", "dest_ip": "134.19.55.199", "src_port": 56662, "dest_port": 5555}}'); INSERT INTO alerts VALUES(1295,1773041580.333933115,'{"timestamp": "2026-03-09T08:33:00.333933+0100", "flow_id": 1152757961442375, "event_type": "alert", "src_ip": "185.242.3.25", "src_port": 40349, "dest_ip": "134.19.55.199", "dest_port": 5678, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:33:00.333933+0100", "src_ip": "185.242.3.25", "dest_ip": "134.19.55.199", "src_port": 40349, "dest_port": 5678}}'); INSERT INTO alerts VALUES(1296,1773041638.106466054,'{"timestamp": "2026-03-09T08:33:58.106466+0100", "flow_id": 1864646196032127, "event_type": "alert", "src_ip": "64.62.156.64", "src_port": 36960, "dest_ip": "134.19.55.199", "dest_port": 1883, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:33:58.106466+0100", "src_ip": "64.62.156.64", "dest_ip": "134.19.55.199", "src_port": 36960, "dest_port": 1883}}'); INSERT INTO alerts VALUES(1297,1773041686.388427973,'{"timestamp": "2026-03-09T08:34:46.388428+0100", "flow_id": 1949764176565233, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50268, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52692, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T08:34:46.388428+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50268, "dest_port": 53}}'); INSERT INTO alerts VALUES(1298,1773041686.389169931,'{"timestamp": "2026-03-09T08:34:46.389170+0100", "flow_id": 1952949981435402, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33827, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46284, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T08:34:46.389170+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33827, "dest_port": 53}}'); INSERT INTO alerts VALUES(1299,1773041686.389169931,'{"timestamp": "2026-03-09T08:34:46.389170+0100", "flow_id": 1952948683778425, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 52531, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29566, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T08:34:46.389170+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 52531, "dest_port": 53}}'); INSERT INTO alerts VALUES(1300,1773041691.875499964,'{"timestamp": "2026-03-09T08:34:51.875500+0100", "flow_id": 945497053237112, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 40410, "dest_ip": "134.19.55.199", "dest_port": 3833, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:34:51.875500+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 40410, "dest_port": 3833}}'); INSERT INTO alerts VALUES(1301,1773041709.209482909,'{"timestamp": "2026-03-09T08:35:09.209483+0100", "flow_id": 1462672902286222, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39861, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44534, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:35:09.209483+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39861, "dest_port": 53}}'); INSERT INTO alerts VALUES(1302,1773041709.209482909,'{"timestamp": "2026-03-09T08:35:09.209483+0100", "flow_id": 1462676361500815, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 37499, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56174, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:35:09.209483+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 37499, "dest_port": 53}}'); INSERT INTO alerts VALUES(1303,1773041710.046297074,'{"timestamp": "2026-03-09T08:35:10.046297+0100", "flow_id": 1887694969922905, "event_type": "alert", "src_ip": "176.65.149.194", "src_port": 48498, "dest_ip": "134.19.55.199", "dest_port": 8000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:35:10.046297+0100", "src_ip": "176.65.149.194", "dest_ip": "134.19.55.199", "src_port": 48498, "dest_port": 8000}}'); INSERT INTO alerts VALUES(1304,1773041724.037151098,'{"timestamp": "2026-03-09T08:35:24.037151+0100", "flow_id": 1285464050708860, "event_type": "alert", "src_ip": "193.163.125.207", "src_port": 57112, "dest_ip": "134.19.55.199", "dest_port": 3131, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:35:24.037151+0100", "src_ip": "193.163.125.207", "dest_ip": "134.19.55.199", "src_port": 57112, "dest_port": 3131}}'); INSERT INTO alerts VALUES(1305,1773041751.050868034,'{"timestamp": "2026-03-09T08:35:51.050868+0100", "flow_id": 2188803658509975, "event_type": "alert", "src_ip": "36.73.34.51", "src_port": 26359, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:35:51.050868+0100", "src_ip": "36.73.34.51", "dest_ip": "134.19.55.199", "src_port": 26359, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1306,1773041754.074333907,'{"timestamp": "2026-03-09T08:35:54.074334+0100", "flow_id": 2188803658509975, "event_type": "alert", "src_ip": "36.73.34.51", "src_port": 26359, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 104, "bytes_toclient": 0, "start": "2026-03-09T08:35:51.050868+0100", "src_ip": "36.73.34.51", "dest_ip": "134.19.55.199", "src_port": 26359, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1307,1773041781.008702039,'{"timestamp": "2026-03-09T08:36:21.008702+0100", "flow_id": 1444753801645690, "event_type": "alert", "src_ip": "193.163.125.217", "src_port": 36869, "dest_ip": "134.19.55.199", "dest_port": 873, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:36:21.008702+0100", "src_ip": "193.163.125.217", "dest_ip": "134.19.55.199", "src_port": 36869, "dest_port": 873}}'); INSERT INTO alerts VALUES(1308,1773041789.644517898,'{"timestamp": "2026-03-09T08:36:29.644518+0100", "flow_id": 1642284708929063, "event_type": "alert", "src_ip": "185.242.226.120", "src_port": 46421, "dest_ip": "134.19.55.199", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:36:29.644518+0100", "src_ip": "185.242.226.120", "dest_ip": "134.19.55.199", "src_port": 46421, "dest_port": 443}}'); INSERT INTO alerts VALUES(1309,1773041840.738924027,'{"timestamp": "2026-03-09T08:37:20.738924+0100", "flow_id": 77433826413497, "event_type": "alert", "src_ip": "187.59.156.8", "src_port": 52374, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:37:20.738924+0100", "src_ip": "187.59.156.8", "dest_ip": "134.19.55.199", "src_port": 52374, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1310,1773041843.557881116,'{"timestamp": "2026-03-09T08:37:23.557881+0100", "flow_id": 988709813711380, "event_type": "alert", "src_ip": "66.132.153.159", "src_port": 12852, "dest_ip": "134.19.55.199", "dest_port": 8001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:37:23.557881+0100", "src_ip": "66.132.153.159", "dest_ip": "134.19.55.199", "src_port": 12852, "dest_port": 8001}}'); INSERT INTO alerts VALUES(1311,1773041849.317636014,'{"timestamp": "2026-03-09T08:37:29.317636+0100", "flow_id": 519813834729044, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 32843, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60001, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:37:29.317636+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 32843, "dest_port": 53}}'); INSERT INTO alerts VALUES(1312,1773041849.317636014,'{"timestamp": "2026-03-09T08:37:29.317636+0100", "flow_id": 519814292959469, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 47223, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21070, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:37:29.317636+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 47223, "dest_port": 53}}'); INSERT INTO alerts VALUES(1313,1773041869.663781882,'{"timestamp": "2026-03-09T08:37:49.663782+0100", "flow_id": 1443551252729077, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 57617, "dest_ip": "134.19.55.199", "dest_port": 40797, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:37:49.663782+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 57617, "dest_port": 40797}}'); INSERT INTO alerts VALUES(1314,1773041890.697881937,'{"timestamp": "2026-03-09T08:38:10.697882+0100", "flow_id": 745584103917643, "event_type": "alert", "src_ip": "193.163.125.214", "src_port": 44911, "dest_ip": "134.19.55.199", "dest_port": 11102, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:38:10.697882+0100", "src_ip": "193.163.125.214", "dest_ip": "134.19.55.199", "src_port": 44911, "dest_port": 11102}}'); INSERT INTO alerts VALUES(1315,1773041903.159667015,'{"timestamp": "2026-03-09T08:38:23.159667+0100", "flow_id": 2093141459241089, "event_type": "alert", "src_ip": "147.185.132.109", "src_port": 56378, "dest_ip": "134.19.55.199", "dest_port": 50995, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:38:23.159667+0100", "src_ip": "147.185.132.109", "dest_ip": "134.19.55.199", "src_port": 56378, "dest_port": 50995}}'); INSERT INTO alerts VALUES(1316,1773041935.367959023,'{"timestamp": "2026-03-09T08:38:55.367959+0100", "flow_id": 2143322829353053, "event_type": "alert", "src_ip": "195.184.76.33", "src_port": 47743, "dest_ip": "134.19.55.199", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:38:55.367959+0100", "src_ip": "195.184.76.33", "dest_ip": "134.19.55.199", "src_port": 47743, "dest_port": 5900}}'); INSERT INTO alerts VALUES(1317,1773041944.884654046,'{"timestamp": "2026-03-09T08:39:04.884654+0100", "flow_id": 140389167469609, "event_type": "alert", "src_ip": "198.235.24.184", "src_port": 51623, "dest_ip": "134.19.55.199", "dest_port": 7001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:39:04.884654+0100", "src_ip": "198.235.24.184", "dest_ip": "134.19.55.199", "src_port": 51623, "dest_port": 7001}}'); INSERT INTO alerts VALUES(1318,1773041989.39361906,'{"timestamp": "2026-03-09T08:39:49.393619+0100", "flow_id": 1409106990444879, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 54746, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:39:49.393619+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 54746, "dest_port": 53}}'); INSERT INTO alerts VALUES(1319,1773041989.393620014,'{"timestamp": "2026-03-09T08:39:49.393620+0100", "flow_id": 1409113922873745, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43313, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26432, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:39:49.393620+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43313, "dest_port": 53}}'); INSERT INTO alerts VALUES(1320,1773042022.447922945,'{"timestamp": "2026-03-09T08:40:22.447923+0100", "flow_id": 1923814906479433, "event_type": "alert", "src_ip": "167.94.138.124", "src_port": 63048, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 290, "bytes_toclient": 0, "start": "2026-03-09T08:40:22.447923+0100", "src_ip": "167.94.138.124", "dest_ip": "134.19.55.199", "src_port": 63048, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1321,1773042027.815105915,'{"timestamp": "2026-03-09T08:40:27.815106+0100", "flow_id": 967582206709219, "event_type": "alert", "src_ip": "195.184.76.217", "src_port": 8856, "dest_ip": "134.19.55.199", "dest_port": 5152, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:40:27.815106+0100", "src_ip": "195.184.76.217", "dest_ip": "134.19.55.199", "src_port": 8856, "dest_port": 5152}}'); INSERT INTO alerts VALUES(1322,1773042037.033541917,'{"timestamp": "2026-03-09T08:40:37.033542+0100", "flow_id": 1551439466746805, "event_type": "alert", "src_ip": "198.235.24.241", "src_port": 49668, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:40:37.033542+0100", "src_ip": "198.235.24.241", "dest_ip": "134.19.55.199", "src_port": 49668, "dest_port": 22}}'); INSERT INTO alerts VALUES(1323,1773042040.681472063,'{"timestamp": "2026-03-09T08:40:40.681472+0100", "flow_id": 112153510640417, "event_type": "alert", "src_ip": "185.242.226.73", "src_port": 39526, "dest_ip": "134.19.55.199", "dest_port": 8415, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:40:40.681472+0100", "src_ip": "185.242.226.73", "dest_ip": "134.19.55.199", "src_port": 39526, "dest_port": 8415}}'); INSERT INTO alerts VALUES(1324,1773042047.951941014,'{"timestamp": "2026-03-09T08:40:47.951941+0100", "flow_id": 2118232853222727, "event_type": "alert", "src_ip": "66.132.153.126", "src_port": 14947, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 290, "bytes_toclient": 0, "start": "2026-03-09T08:40:47.951941+0100", "src_ip": "66.132.153.126", "dest_ip": "134.19.55.199", "src_port": 14947, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1325,1773042089.986219882,'{"timestamp": "2026-03-09T08:41:29.986220+0100", "flow_id": 295136228307071, "event_type": "alert", "src_ip": "167.94.138.143", "src_port": 65088, "dest_ip": "134.19.55.199", "dest_port": 103, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:41:29.986220+0100", "src_ip": "167.94.138.143", "dest_ip": "134.19.55.199", "src_port": 65088, "dest_port": 103}}'); INSERT INTO alerts VALUES(1326,1773042129.571105004,'{"timestamp": "2026-03-09T08:42:09.571105+0100", "flow_id": 482556053660012, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 53881, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58096, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:42:09.571105+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 53881, "dest_port": 53}}'); INSERT INTO alerts VALUES(1327,1773042129.571105004,'{"timestamp": "2026-03-09T08:42:09.571105+0100", "flow_id": 482552927649351, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41227, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58492, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:42:09.571105+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41227, "dest_port": 53}}'); INSERT INTO alerts VALUES(1328,1773042156.733419895,'{"timestamp": "2026-03-09T08:42:36.733420+0100", "flow_id": 1179692854441837, "event_type": "alert", "src_ip": "193.163.125.182", "src_port": 59675, "dest_ip": "134.19.55.199", "dest_port": 18088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:42:36.733420+0100", "src_ip": "193.163.125.182", "dest_ip": "134.19.55.199", "src_port": 59675, "dest_port": 18088}}'); INSERT INTO alerts VALUES(1329,1773042159.240394116,'{"timestamp": "2026-03-09T08:42:39.240394+0100", "flow_id": 2158387113004362, "event_type": "alert", "src_ip": "64.62.156.22", "src_port": 42512, "dest_ip": "134.19.55.199", "dest_port": 449, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:42:39.240394+0100", "src_ip": "64.62.156.22", "dest_ip": "134.19.55.199", "src_port": 42512, "dest_port": 449}}'); INSERT INTO alerts VALUES(1330,1773042171.730057001,'{"timestamp": "2026-03-09T08:42:51.730057+0100", "flow_id": 883771892397764, "event_type": "alert", "src_ip": "198.235.24.107", "src_port": 55876, "dest_ip": "134.19.55.199", "dest_port": 2455, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:42:51.730057+0100", "src_ip": "198.235.24.107", "dest_ip": "134.19.55.199", "src_port": 55876, "dest_port": 2455}}'); INSERT INTO alerts VALUES(1331,1773042212.547238112,'{"timestamp": "2026-03-09T08:43:32.547238+0100", "flow_id": 1224471955451713, "event_type": "alert", "src_ip": "205.210.31.104", "src_port": 50191, "dest_ip": "134.19.55.199", "dest_port": 7001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:43:32.547238+0100", "src_ip": "205.210.31.104", "dest_ip": "134.19.55.199", "src_port": 50191, "dest_port": 7001}}'); INSERT INTO alerts VALUES(1332,1773042222.751460076,'{"timestamp": "2026-03-09T08:43:42.751460+0100", "flow_id": 1820122641263083, "event_type": "alert", "src_ip": "193.163.125.211", "src_port": 39058, "dest_ip": "134.19.55.199", "dest_port": 161, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:43:42.751460+0100", "src_ip": "193.163.125.211", "dest_ip": "134.19.55.199", "src_port": 39058, "dest_port": 161}}'); INSERT INTO alerts VALUES(1333,1773042246.778403044,'{"timestamp": "2026-03-09T08:44:06.778403+0100", "flow_id": 1935841737781191, "event_type": "alert", "src_ip": "167.94.138.150", "src_port": 48238, "dest_ip": "134.19.55.199", "dest_port": 995, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:44:06.778403+0100", "src_ip": "167.94.138.150", "dest_ip": "134.19.55.199", "src_port": 48238, "dest_port": 995}}'); INSERT INTO alerts VALUES(1334,1773042250.458306074,'{"timestamp": "2026-03-09T08:44:10.458306+0100", "flow_id": 842510152697086, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 1747, "dest_ip": "134.19.55.199", "dest_port": 64442, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:44:10.458306+0100", "src_ip": "167.94.146.37", "dest_ip": "134.19.55.199", "src_port": 1747, "dest_port": 64442}}'); INSERT INTO alerts VALUES(1335,1773042262.25745511,'{"timestamp": "2026-03-09T08:44:22.257455+0100", "flow_id": 1950188763847477, "event_type": "alert", "src_ip": "176.65.134.24", "src_port": 61339, "dest_ip": "134.19.55.199", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 48, "bytes_toclient": 0, "start": "2026-03-09T08:44:22.257455+0100", "src_ip": "176.65.134.24", "dest_ip": "134.19.55.199", "src_port": 61339, "dest_port": 25565}}'); INSERT INTO alerts VALUES(1336,1773042269.654906988,'{"timestamp": "2026-03-09T08:44:29.654907+0100", "flow_id": 1686906326098828, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 35583, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9032, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:44:29.654907+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 35583, "dest_port": 53}}'); INSERT INTO alerts VALUES(1337,1773042269.655777932,'{"timestamp": "2026-03-09T08:44:29.655778+0100", "flow_id": 1409172235636125, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43165, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38237, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:44:29.655778+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43165, "dest_port": 53}}'); INSERT INTO alerts VALUES(1338,1773042296.687462092,'{"timestamp": "2026-03-09T08:44:56.687462+0100", "flow_id": 137877183132816, "event_type": "alert", "src_ip": "198.235.24.106", "src_port": 57058, "dest_ip": "134.19.55.199", "dest_port": 4433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:44:56.687462+0100", "src_ip": "198.235.24.106", "dest_ip": "134.19.55.199", "src_port": 57058, "dest_port": 4433}}'); INSERT INTO alerts VALUES(1339,1773042405.158655882,'{"timestamp": "2026-03-09T08:46:45.158656+0100", "flow_id": 1525850114727887, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 50371, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:46:45.158656+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 50371, "dest_port": 8545}}'); INSERT INTO alerts VALUES(1340,1773042405.158655882,'{"timestamp": "2026-03-09T08:46:45.158656+0100", "flow_id": 1525850114727887, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 50371, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T08:46:45.158656+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 50371, "dest_port": 8545}}'); INSERT INTO alerts VALUES(1341,1773042423.943969965,'{"timestamp": "2026-03-09T08:47:03.943970+0100", "flow_id": 2083998796373407, "event_type": "alert", "src_ip": "80.71.235.16", "src_port": 57031, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.TorIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2520108, "rev": 6187, "signature": "ET TOR Known Tor Exit Node Traffic group 109", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2008_12_01"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["TOR"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:47:03.943970+0100", "src_ip": "80.71.235.16", "dest_ip": "134.19.55.199", "src_port": 57031, "dest_port": 80}}'); INSERT INTO alerts VALUES(1342,1773042423.943969965,'{"timestamp": "2026-03-09T08:47:03.943970+0100", "flow_id": 2083998796373407, "event_type": "alert", "src_ip": "80.71.235.16", "src_port": 57031, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.TorIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2522108, "rev": 6187, "signature": "ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 109", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2008_12_01"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["TOR"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:47:03.943970+0100", "src_ip": "80.71.235.16", "dest_ip": "134.19.55.199", "src_port": 57031, "dest_port": 80}}'); INSERT INTO alerts VALUES(1343,1773042444.664587975,'{"timestamp": "2026-03-09T08:47:24.664588+0100", "flow_id": 1165534190571927, "event_type": "alert", "src_ip": "64.62.197.51", "src_port": 58934, "dest_ip": "134.19.55.199", "dest_port": 447, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:47:24.664588+0100", "src_ip": "64.62.197.51", "dest_ip": "134.19.55.199", "src_port": 58934, "dest_port": 447}}'); INSERT INTO alerts VALUES(1344,1773042468.023608922,'{"timestamp": "2026-03-09T08:47:48.023609+0100", "flow_id": 1227301994529077, "event_type": "alert", "src_ip": "147.185.132.25", "src_port": 51025, "dest_ip": "134.19.55.199", "dest_port": 24156, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:47:48.023609+0100", "src_ip": "147.185.132.25", "dest_ip": "134.19.55.199", "src_port": 51025, "dest_port": 24156}}'); INSERT INTO alerts VALUES(1345,1773042569.767087936,'{"timestamp": "2026-03-09T08:49:29.767088+0100", "flow_id": 479870072957717, "event_type": "alert", "src_ip": "195.184.76.113", "src_port": 24226, "dest_ip": "134.19.55.199", "dest_port": 52224, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:49:29.767088+0100", "src_ip": "195.184.76.113", "dest_ip": "134.19.55.199", "src_port": 24226, "dest_port": 52224}}'); INSERT INTO alerts VALUES(1346,1773042620.27335,'{"timestamp": "2026-03-09T08:50:20.273350+0100", "flow_id": 1174032551946755, "event_type": "alert", "src_ip": "45.142.154.87", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 3116, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:50:20.273350+0100", "src_ip": "45.142.154.87", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 3116}}'); INSERT INTO alerts VALUES(1347,1773042649.940414906,'{"timestamp": "2026-03-09T08:50:49.940415+0100", "flow_id": 379878525328009, "event_type": "alert", "src_ip": "147.185.132.234", "src_port": 54277, "dest_ip": "134.19.55.199", "dest_port": 5902, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:50:49.940415+0100", "src_ip": "147.185.132.234", "dest_ip": "134.19.55.199", "src_port": 54277, "dest_port": 5902}}'); INSERT INTO alerts VALUES(1348,1773042670.052567959,'{"timestamp": "2026-03-09T08:51:10.052568+0100", "flow_id": 1914628760052713, "event_type": "alert", "src_ip": "192.109.200.157", "src_port": 38152, "dest_ip": "134.19.55.199", "dest_port": 17000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400037, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 38", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:51:10.052568+0100", "src_ip": "192.109.200.157", "dest_ip": "134.19.55.199", "src_port": 38152, "dest_port": 17000}}'); INSERT INTO alerts VALUES(1349,1773042690.918814898,'{"timestamp": "2026-03-09T08:51:30.918815+0100", "flow_id": 568584466531756, "event_type": "alert", "src_ip": "147.185.132.118", "src_port": 57277, "dest_ip": "134.19.55.199", "dest_port": 13946, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T08:51:30.918815+0100", "src_ip": "147.185.132.118", "dest_ip": "134.19.55.199", "src_port": 57277, "dest_port": 13946}}'); INSERT INTO alerts VALUES(1350,1773042712.448183059,'{"timestamp": "2026-03-09T08:51:52.448183+0100", "flow_id": 236084005265364, "event_type": "alert", "src_ip": "64.62.156.120", "src_port": 47287, "dest_ip": "134.19.55.199", "dest_port": 82, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:51:52.448183+0100", "src_ip": "64.62.156.120", "dest_ip": "134.19.55.199", "src_port": 47287, "dest_port": 82}}'); INSERT INTO alerts VALUES(1351,1773042724.331337929,'{"timestamp": "2026-03-09T08:52:04.331338+0100", "flow_id": 1141611319379402, "event_type": "alert", "src_ip": "204.76.203.17", "src_port": 47534, "dest_ip": "134.19.55.199", "dest_port": 2302, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 38, "bytes_toclient": 0, "start": "2026-03-09T08:52:04.331338+0100", "src_ip": "204.76.203.17", "dest_ip": "134.19.55.199", "src_port": 47534, "dest_port": 2302}}'); INSERT INTO alerts VALUES(1352,1773042724.331337929,'{"timestamp": "2026-03-09T08:52:04.331338+0100", "flow_id": 1141611319379402, "event_type": "alert", "src_ip": "204.76.203.17", "src_port": 47534, "dest_ip": "134.19.55.199", "dest_port": 2302, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 38, "bytes_toclient": 0, "start": "2026-03-09T08:52:04.331338+0100", "src_ip": "204.76.203.17", "dest_ip": "134.19.55.199", "src_port": 47534, "dest_port": 2302}}'); INSERT INTO alerts VALUES(1353,1773042750.702008963,'{"timestamp": "2026-03-09T08:52:30.702009+0100", "flow_id": 1889209709611690, "event_type": "alert", "src_ip": "185.242.226.8", "src_port": 57170, "dest_ip": "134.19.55.199", "dest_port": 8884, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:52:30.702009+0100", "src_ip": "185.242.226.8", "dest_ip": "134.19.55.199", "src_port": 57170, "dest_port": 8884}}'); INSERT INTO alerts VALUES(1354,1773042817.742235899,'{"timestamp": "2026-03-09T08:53:37.742236+0100", "flow_id": 373130354764414, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 161, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:53:37.742236+0100", "src_ip": "88.210.63.69", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 161}}'); INSERT INTO alerts VALUES(1355,1773042828.405090093,'{"timestamp": "2026-03-09T08:53:48.405090+0100", "flow_id": 1176901866660665, "event_type": "alert", "src_ip": "167.94.146.38", "src_port": 25089, "dest_ip": "134.19.55.199", "dest_port": 64572, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:53:48.405090+0100", "src_ip": "167.94.146.38", "dest_ip": "134.19.55.199", "src_port": 25089, "dest_port": 64572}}'); INSERT INTO alerts VALUES(1356,1773042832.473773003,'{"timestamp": "2026-03-09T08:53:52.473773+0100", "flow_id": 64518599039321, "event_type": "alert", "src_ip": "65.49.1.130", "src_port": 59552, "dest_ip": "134.19.55.199", "dest_port": 83, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:53:52.473773+0100", "src_ip": "65.49.1.130", "dest_ip": "134.19.55.199", "src_port": 59552, "dest_port": 83}}'); INSERT INTO alerts VALUES(1357,1773042839.136137008,'{"timestamp": "2026-03-09T08:53:59.136137+0100", "flow_id": 1992081351126702, "event_type": "alert", "src_ip": "45.142.154.10", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 5601, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:53:59.136137+0100", "src_ip": "45.142.154.10", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 5601}}'); INSERT INTO alerts VALUES(1358,1773042858.324991942,'{"timestamp": "2026-03-09T08:54:18.324992+0100", "flow_id": 832883351708325, "event_type": "alert", "src_ip": "64.62.156.161", "src_port": 47034, "dest_ip": "134.19.55.199", "dest_port": 85, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:54:18.324992+0100", "src_ip": "64.62.156.161", "dest_ip": "134.19.55.199", "src_port": 47034, "dest_port": 85}}'); INSERT INTO alerts VALUES(1359,1773042871.674865007,'{"timestamp": "2026-03-09T08:54:31.674865+0100", "flow_id": 2054101616228276, "event_type": "alert", "src_ip": "64.62.197.216", "src_port": 33286, "dest_ip": "134.19.55.199", "dest_port": 427, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 62, "bytes_toclient": 0, "start": "2026-03-09T08:54:31.674865+0100", "src_ip": "64.62.197.216", "dest_ip": "134.19.55.199", "src_port": 33286, "dest_port": 427}}'); INSERT INTO alerts VALUES(1360,1773042903.363434076,'{"timestamp": "2026-03-09T08:55:03.363434+0100", "flow_id": 2123888656588155, "event_type": "alert", "src_ip": "176.65.139.38", "src_port": 50000, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:55:03.363434+0100", "src_ip": "176.65.139.38", "dest_ip": "134.19.55.199", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(1361,1773042935.078912019,'{"timestamp": "2026-03-09T08:55:35.078912+0100", "flow_id": 2027775265247292, "event_type": "alert", "src_ip": "198.235.24.198", "src_port": 55672, "dest_ip": "134.19.55.199", "dest_port": 23856, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T08:55:35.078912+0100", "src_ip": "198.235.24.198", "dest_ip": "134.19.55.199", "src_port": 55672, "dest_port": 23856}}'); INSERT INTO alerts VALUES(1362,1773042938.748547077,'{"timestamp": "2026-03-09T08:55:38.748547+0100", "flow_id": 681710382443501, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57620, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26323, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:55:38.748547+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57620, "dest_port": 53}}'); INSERT INTO alerts VALUES(1363,1773042938.748547077,'{"timestamp": "2026-03-09T08:55:38.748547+0100", "flow_id": 681713970456729, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49021, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58532, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:55:38.748547+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49021, "dest_port": 53}}'); INSERT INTO alerts VALUES(1364,1773042989.390522956,'{"timestamp": "2026-03-09T08:56:29.390523+0100", "flow_id": 1677287282407222, "event_type": "alert", "src_ip": "91.196.152.39", "src_port": 33478, "dest_ip": "134.19.55.199", "dest_port": 20015, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T08:56:29.390523+0100", "src_ip": "91.196.152.39", "dest_ip": "134.19.55.199", "src_port": 33478, "dest_port": 20015}}'); INSERT INTO alerts VALUES(1365,1773043078.823252917,'{"timestamp": "2026-03-09T08:57:58.823253+0100", "flow_id": 1846997217431223, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43245, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44748, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:57:58.823253+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43245, "dest_port": 53}}'); INSERT INTO alerts VALUES(1366,1773043078.823771953,'{"timestamp": "2026-03-09T08:57:58.823772+0100", "flow_id": 1849225624808926, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60164, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11015, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T08:57:58.823772+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60164, "dest_port": 53}}'); INSERT INTO alerts VALUES(1367,1773043079.941854954,'{"timestamp": "2026-03-09T08:57:59.941855+0100", "flow_id": 2074914266136749, "event_type": "alert", "src_ip": "87.121.84.76", "src_port": 43150, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:57:59.941855+0100", "src_ip": "87.121.84.76", "dest_ip": "134.19.55.199", "src_port": 43150, "dest_port": 80}}'); INSERT INTO alerts VALUES(1368,1773043121.3750391,'{"timestamp": "2026-03-09T08:58:41.375039+0100", "flow_id": 484881899166094, "event_type": "alert", "src_ip": "65.49.1.202", "src_port": 43325, "dest_ip": "134.19.55.199", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:58:41.375039+0100", "src_ip": "65.49.1.202", "dest_ip": "134.19.55.199", "src_port": 43325, "dest_port": 8888}}'); INSERT INTO alerts VALUES(1369,1773043154.838767052,'{"timestamp": "2026-03-09T08:59:14.838767+0100", "flow_id": 787730368456058, "event_type": "alert", "src_ip": "64.62.156.185", "src_port": 32857, "dest_ip": "134.19.55.199", "dest_port": 5985, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T08:59:14.838767+0100", "src_ip": "64.62.156.185", "dest_ip": "134.19.55.199", "src_port": 32857, "dest_port": 5985}}'); INSERT INTO alerts VALUES(1370,1773043155.930984973,'{"timestamp": "2026-03-09T08:59:15.930985+0100", "flow_id": 902327833080332, "event_type": "alert", "src_ip": "65.49.1.35", "src_port": 2536, "dest_ip": "134.19.55.199", "dest_port": 69, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "tftp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 42, "bytes_toclient": 0, "start": "2026-03-09T08:59:15.930985+0100", "src_ip": "65.49.1.35", "dest_ip": "134.19.55.199", "src_port": 2536, "dest_port": 69}}'); INSERT INTO alerts VALUES(1371,1773043197.801744937,'{"timestamp": "2026-03-09T08:59:57.801745+0100", "flow_id": 1473147359594435, "event_type": "alert", "src_ip": "101.0.104.38", "src_port": 5075, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 431, "bytes_toclient": 0, "start": "2026-03-09T08:59:57.801745+0100", "src_ip": "101.0.104.38", "dest_ip": "134.19.55.199", "src_port": 5075, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1372,1773043197.801744937,'{"timestamp": "2026-03-09T08:59:57.801745+0100", "flow_id": 1473147359594435, "event_type": "alert", "src_ip": "101.0.104.38", "src_port": 5075, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 431, "bytes_toclient": 0, "start": "2026-03-09T08:59:57.801745+0100", "src_ip": "101.0.104.38", "dest_ip": "134.19.55.199", "src_port": 5075, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1373,1773043216.07357192,'{"timestamp": "2026-03-09T09:00:16.073572+0100", "flow_id": 34517357570114, "event_type": "alert", "src_ip": "167.94.138.109", "src_port": 47170, "dest_ip": "134.19.55.199", "dest_port": 35143, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:00:16.073572+0100", "src_ip": "167.94.138.109", "dest_ip": "134.19.55.199", "src_port": 47170, "dest_port": 35143}}'); INSERT INTO alerts VALUES(1374,1773043219.074345112,'{"timestamp": "2026-03-09T09:00:19.074345+0100", "flow_id": 882260338034556, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60310, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33190, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:00:19.074345+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60310, "dest_port": 53}}'); INSERT INTO alerts VALUES(1375,1773043219.075133086,'{"timestamp": "2026-03-09T09:00:19.075133+0100", "flow_id": 885644545511743, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51842, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54460, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:00:19.075133+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51842, "dest_port": 53}}'); INSERT INTO alerts VALUES(1376,1773043219.641081094,'{"timestamp": "2026-03-09T09:00:19.641081+0100", "flow_id": 1064572586429097, "event_type": "alert", "src_ip": "176.65.134.3", "src_port": 51613, "dest_ip": "134.19.55.199", "dest_port": 7890, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:00:19.641081+0100", "src_ip": "176.65.134.3", "dest_ip": "134.19.55.199", "src_port": 51613, "dest_port": 7890}}'); INSERT INTO alerts VALUES(1377,1773043227.085979938,'{"timestamp": "2026-03-09T09:00:27.085980+0100", "flow_id": 932232036075215, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 43008, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:00:27.085980+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 43008, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1378,1773043243.106864929,'{"timestamp": "2026-03-09T09:00:43.106865+0100", "flow_id": 1021934765599086, "event_type": "alert", "src_ip": "147.185.132.115", "src_port": 56213, "dest_ip": "134.19.55.199", "dest_port": 8015, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:00:43.106865+0100", "src_ip": "147.185.132.115", "dest_ip": "134.19.55.199", "src_port": 56213, "dest_port": 8015}}'); INSERT INTO alerts VALUES(1379,1773043267.943861007,'{"timestamp": "2026-03-09T09:01:07.943861+0100", "flow_id": 957628266287706, "event_type": "alert", "src_ip": "176.65.148.92", "src_port": 42477, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:01:07.943861+0100", "src_ip": "176.65.148.92", "dest_ip": "134.19.55.199", "src_port": 42477, "dest_port": 3389}}'); INSERT INTO alerts VALUES(1380,1773043267.943861007,'{"timestamp": "2026-03-09T09:01:07.943861+0100", "flow_id": 957628266287706, "event_type": "alert", "src_ip": "176.65.148.92", "src_port": 42477, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:01:07.943861+0100", "src_ip": "176.65.148.92", "dest_ip": "134.19.55.199", "src_port": 42477, "dest_port": 3389}}'); INSERT INTO alerts VALUES(1381,1773043270.029303073,'{"timestamp": "2026-03-09T09:01:10.029303+0100", "flow_id": 1814706266967089, "event_type": "alert", "src_ip": "147.185.132.106", "src_port": 52300, "dest_ip": "134.19.55.199", "dest_port": 1025, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:01:10.029303+0100", "src_ip": "147.185.132.106", "dest_ip": "134.19.55.199", "src_port": 52300, "dest_port": 1025}}'); INSERT INTO alerts VALUES(1382,1773043275.797842025,'{"timestamp": "2026-03-09T09:01:15.797842+0100", "flow_id": 893433829365829, "event_type": "alert", "src_ip": "64.62.156.165", "src_port": 52430, "dest_ip": "134.19.55.199", "dest_port": 3128, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:01:15.797842+0100", "src_ip": "64.62.156.165", "dest_ip": "134.19.55.199", "src_port": 52430, "dest_port": 3128}}'); INSERT INTO alerts VALUES(1383,1773043352.752641916,'{"timestamp": "2026-03-09T09:02:32.752642+0100", "flow_id": 136351056202862, "event_type": "alert", "src_ip": "101.0.104.38", "src_port": 5074, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-09T09:02:32.752642+0100", "src_ip": "101.0.104.38", "dest_ip": "134.19.55.199", "src_port": 5074, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1384,1773043352.752641916,'{"timestamp": "2026-03-09T09:02:32.752642+0100", "flow_id": 136351056202862, "event_type": "alert", "src_ip": "101.0.104.38", "src_port": 5074, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-09T09:02:32.752642+0100", "src_ip": "101.0.104.38", "dest_ip": "134.19.55.199", "src_port": 5074, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1385,1773043359.149214029,'{"timestamp": "2026-03-09T09:02:39.149214+0100", "flow_id": 2048244210637411, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39171, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35869, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:02:39.149214+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39171, "dest_port": 53}}'); INSERT INTO alerts VALUES(1386,1773043359.149214982,'{"timestamp": "2026-03-09T09:02:39.149215+0100", "flow_id": 2048252094808737, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 53126, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28727, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:02:39.149215+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 53126, "dest_port": 53}}'); INSERT INTO alerts VALUES(1387,1773043371.126594066,'{"timestamp": "2026-03-09T09:02:51.126594+0100", "flow_id": 1106670187820676, "event_type": "alert", "src_ip": "205.210.31.198", "src_port": 51472, "dest_ip": "134.19.55.199", "dest_port": 8005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:02:51.126594+0100", "src_ip": "205.210.31.198", "dest_ip": "134.19.55.199", "src_port": 51472, "dest_port": 8005}}'); INSERT INTO alerts VALUES(1388,1773043382.963685989,'{"timestamp": "2026-03-09T09:03:02.963686+0100", "flow_id": 1887200347942102, "event_type": "alert", "src_ip": "64.62.156.199", "src_port": 40645, "dest_ip": "134.19.55.199", "dest_port": 2083, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:03:02.963686+0100", "src_ip": "64.62.156.199", "dest_ip": "134.19.55.199", "src_port": 40645, "dest_port": 2083}}'); INSERT INTO alerts VALUES(1389,1773043463.043385982,'{"timestamp": "2026-03-09T09:04:23.043386+0100", "flow_id": 2156666850074675, "event_type": "alert", "src_ip": "147.185.132.112", "src_port": 49581, "dest_ip": "134.19.55.199", "dest_port": 143, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:04:23.043386+0100", "src_ip": "147.185.132.112", "dest_ip": "134.19.55.199", "src_port": 49581, "dest_port": 143}}'); INSERT INTO alerts VALUES(1390,1773043475.168035031,'{"timestamp": "2026-03-09T09:04:35.168035+0100", "flow_id": 1003180512472629, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 13631, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:04:35.168035+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 13631}}'); INSERT INTO alerts VALUES(1391,1773043499.297693014,'{"timestamp": "2026-03-09T09:04:59.297693+0100", "flow_id": 997107282117375, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43931, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6570, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:04:59.297693+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43931, "dest_port": 53}}'); INSERT INTO alerts VALUES(1392,1773043499.297693014,'{"timestamp": "2026-03-09T09:04:59.297693+0100", "flow_id": 997107085920468, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34443, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5919, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:04:59.297693+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34443, "dest_port": 53}}'); INSERT INTO alerts VALUES(1393,1773043534.505038023,'{"timestamp": "2026-03-09T09:05:34.505038+0100", "flow_id": 1887647638990773, "event_type": "alert", "src_ip": "91.196.152.228", "src_port": 3030, "dest_ip": "134.19.55.199", "dest_port": 21242, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:05:34.505038+0100", "src_ip": "91.196.152.228", "dest_ip": "134.19.55.199", "src_port": 3030, "dest_port": 21242}}'); INSERT INTO alerts VALUES(1394,1773043545.226897001,'{"timestamp": "2026-03-09T09:05:45.226897+0100", "flow_id": 411566148396152, "event_type": "alert", "src_ip": "195.184.76.137", "src_port": 3984, "dest_ip": "134.19.55.199", "dest_port": 5445, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:05:45.226897+0100", "src_ip": "195.184.76.137", "dest_ip": "134.19.55.199", "src_port": 3984, "dest_port": 5445}}'); INSERT INTO alerts VALUES(1395,1773043561.225061893,'{"timestamp": "2026-03-09T09:06:01.225062+0100", "flow_id": 403687885887811, "event_type": "alert", "src_ip": "176.65.139.12", "src_port": 44710, "dest_ip": "134.19.55.199", "dest_port": 17000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:06:01.225062+0100", "src_ip": "176.65.139.12", "dest_ip": "134.19.55.199", "src_port": 44710, "dest_port": 17000}}'); INSERT INTO alerts VALUES(1396,1773043568.862445116,'{"timestamp": "2026-03-09T09:06:08.862445+0100", "flow_id": 45000506615336, "event_type": "alert", "src_ip": "147.185.132.87", "src_port": 51921, "dest_ip": "134.19.55.199", "dest_port": 7070, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:06:08.862445+0100", "src_ip": "147.185.132.87", "dest_ip": "134.19.55.199", "src_port": 51921, "dest_port": 7070}}'); INSERT INTO alerts VALUES(1397,1773043605.789377928,'{"timestamp": "2026-03-09T09:06:45.789378+0100", "flow_id": 1420027946721261, "event_type": "alert", "src_ip": "172.94.9.253", "src_port": 50776, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400031, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 32", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:06:45.789378+0100", "src_ip": "172.94.9.253", "dest_ip": "134.19.55.199", "src_port": 50776, "dest_port": 80}}'); INSERT INTO alerts VALUES(1398,1773043626.672209978,'{"timestamp": "2026-03-09T09:07:06.672210+0100", "flow_id": 635322235749385, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 9999, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:07:06.672210+0100", "src_ip": "185.156.73.181", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 9999}}'); INSERT INTO alerts VALUES(1399,1773043639.37448597,'{"timestamp": "2026-03-09T09:07:19.374486+0100", "flow_id": 2171356720059415, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 32883, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21161, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:07:19.374486+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 32883, "dest_port": 53}}'); INSERT INTO alerts VALUES(1400,1773043639.374486924,'{"timestamp": "2026-03-09T09:07:19.374487+0100", "flow_id": 2171360367242021, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61993, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:07:19.374487+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49375, "dest_port": 53}}'); INSERT INTO alerts VALUES(1401,1773043663.745393991,'{"timestamp": "2026-03-09T09:07:43.745394+0100", "flow_id": 2075544185086767, "event_type": "alert", "src_ip": "167.94.146.41", "src_port": 19072, "dest_ip": "134.19.55.199", "dest_port": 40248, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:07:43.745394+0100", "src_ip": "167.94.146.41", "dest_ip": "134.19.55.199", "src_port": 19072, "dest_port": 40248}}'); INSERT INTO alerts VALUES(1402,1773043688.242113113,'{"timestamp": "2026-03-09T09:08:08.242113+0100", "flow_id": 195444624254767, "event_type": "alert", "src_ip": "195.184.76.203", "src_port": 34486, "dest_ip": "134.19.55.199", "dest_port": 5666, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:08:08.242113+0100", "src_ip": "195.184.76.203", "dest_ip": "134.19.55.199", "src_port": 34486, "dest_port": 5666}}'); INSERT INTO alerts VALUES(1403,1773043702.998442889,'{"timestamp": "2026-03-09T09:08:22.998443+0100", "flow_id": 1755007953679210, "event_type": "alert", "src_ip": "147.185.132.31", "src_port": 49349, "dest_ip": "134.19.55.199", "dest_port": 40000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:08:22.998443+0100", "src_ip": "147.185.132.31", "dest_ip": "134.19.55.199", "src_port": 49349, "dest_port": 40000}}'); INSERT INTO alerts VALUES(1404,1773043746.46506691,'{"timestamp": "2026-03-09T09:09:06.465067+0100", "flow_id": 590076605726817, "event_type": "alert", "src_ip": "193.163.125.198", "src_port": 54603, "dest_ip": "134.19.55.199", "dest_port": 30081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:09:06.465067+0100", "src_ip": "193.163.125.198", "dest_ip": "134.19.55.199", "src_port": 54603, "dest_port": 30081}}'); INSERT INTO alerts VALUES(1405,1773043779.445811033,'{"timestamp": "2026-03-09T09:09:39.445811+0100", "flow_id": 1070321979103541, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 58735, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35161, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:09:39.445811+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 58735, "dest_port": 53}}'); INSERT INTO alerts VALUES(1406,1773043779.446139098,'{"timestamp": "2026-03-09T09:09:39.446139+0100", "flow_id": 1071730427761100, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50262, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40151, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:09:39.446139+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50262, "dest_port": 53}}'); INSERT INTO alerts VALUES(1407,1773043786.010049104,'{"timestamp": "2026-03-09T09:09:46.010049+0100", "flow_id": 606112894376520, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49887, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15700, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T09:09:46.010049+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49887, "dest_port": 53}}'); INSERT INTO alerts VALUES(1408,1773043786.011413097,'{"timestamp": "2026-03-09T09:09:46.011413+0100", "flow_id": 611970903106466, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 58741, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40452, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T09:09:46.011413+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 58741, "dest_port": 53}}'); INSERT INTO alerts VALUES(1409,1773043786.011414051,'{"timestamp": "2026-03-09T09:09:46.011414+0100", "flow_id": 611972736111671, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33091, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35885, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T09:09:46.011414+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33091, "dest_port": 53}}'); INSERT INTO alerts VALUES(1410,1773043798.434673071,'{"timestamp": "2026-03-09T09:09:58.434673+0100", "flow_id": 1866907172478864, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 40097, "dest_ip": "134.19.55.199", "dest_port": 45454, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:09:58.434673+0100", "src_ip": "79.124.40.82", "dest_ip": "134.19.55.199", "src_port": 40097, "dest_port": 45454}}'); INSERT INTO alerts VALUES(1411,1773043857.233711005,'{"timestamp": "2026-03-09T09:10:57.233711+0100", "flow_id": 440832124773843, "event_type": "alert", "src_ip": "205.210.31.102", "src_port": 55978, "dest_ip": "134.19.55.199", "dest_port": 1801, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:10:57.233711+0100", "src_ip": "205.210.31.102", "dest_ip": "134.19.55.199", "src_port": 55978, "dest_port": 1801}}'); INSERT INTO alerts VALUES(1412,1773043881.604899883,'{"timestamp": "2026-03-09T09:11:21.604900+0100", "flow_id": 346229667384448, "event_type": "alert", "src_ip": "198.235.24.51", "src_port": 53356, "dest_ip": "134.19.55.199", "dest_port": 23756, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:11:21.604900+0100", "src_ip": "198.235.24.51", "dest_ip": "134.19.55.199", "src_port": 53356, "dest_port": 23756}}'); INSERT INTO alerts VALUES(1413,1773043919.628087998,'{"timestamp": "2026-03-09T09:11:59.628088+0100", "flow_id": 2134668011590438, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 47329, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:11:59.628088+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 47329, "dest_port": 53}}'); INSERT INTO alerts VALUES(1414,1773043919.628087998,'{"timestamp": "2026-03-09T09:11:59.628088+0100", "flow_id": 2134670391788383, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 38914, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45085, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:11:59.628088+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 38914, "dest_port": 53}}'); INSERT INTO alerts VALUES(1415,1773043931.91011691,'{"timestamp": "2026-03-09T09:12:11.910117+0100", "flow_id": 1094175809463040, "event_type": "alert", "src_ip": "64.62.197.116", "src_port": 47542, "dest_ip": "134.19.55.199", "dest_port": 9200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:12:11.910117+0100", "src_ip": "64.62.197.116", "dest_ip": "134.19.55.199", "src_port": 47542, "dest_port": 9200}}'); INSERT INTO alerts VALUES(1416,1773043942.219010114,'{"timestamp": "2026-03-09T09:12:22.219010+0100", "flow_id": 1785067813847961, "event_type": "alert", "src_ip": "176.65.149.235", "src_port": 60805, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:12:22.219010+0100", "src_ip": "176.65.149.235", "dest_ip": "134.19.55.199", "src_port": 60805, "dest_port": 80}}'); INSERT INTO alerts VALUES(1417,1773043951.015074015,'{"timestamp": "2026-03-09T09:12:31.015074+0100", "flow_id": 2035068899346215, "event_type": "alert", "src_ip": "147.185.132.43", "src_port": 24071, "dest_ip": "134.19.55.199", "dest_port": 12746, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T09:12:31.015074+0100", "src_ip": "147.185.132.43", "dest_ip": "134.19.55.199", "src_port": 24071, "dest_port": 12746}}'); INSERT INTO alerts VALUES(1418,1773044029.280039073,'{"timestamp": "2026-03-09T09:13:49.280039+0100", "flow_id": 1484234180528037, "event_type": "alert", "src_ip": "176.65.134.22", "src_port": 60775, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:13:49.280039+0100", "src_ip": "176.65.134.22", "dest_ip": "134.19.55.199", "src_port": 60775, "dest_port": 22}}'); INSERT INTO alerts VALUES(1419,1773044052.662345887,'{"timestamp": "2026-03-09T09:14:12.662346+0100", "flow_id": 1155906545903480, "event_type": "alert", "src_ip": "195.184.76.179", "src_port": 47704, "dest_ip": "134.19.55.199", "dest_port": 5156, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:14:12.662346+0100", "src_ip": "195.184.76.179", "dest_ip": "134.19.55.199", "src_port": 47704, "dest_port": 5156}}'); INSERT INTO alerts VALUES(1420,1773044059.780213117,'{"timestamp": "2026-03-09T09:14:19.780213+0100", "flow_id": 1099191503392951, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 38437, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42533, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:14:19.780213+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 38437, "dest_port": 53}}'); INSERT INTO alerts VALUES(1421,1773044059.780213117,'{"timestamp": "2026-03-09T09:14:19.780213+0100", "flow_id": 1099192007562795, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43994, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6669, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:14:19.780213+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43994, "dest_port": 53}}'); INSERT INTO alerts VALUES(1422,1773044065.197205066,'{"timestamp": "2026-03-09T09:14:25.197205+0100", "flow_id": 284042360203174, "event_type": "alert", "src_ip": "64.62.197.65", "src_port": 52949, "dest_ip": "134.19.55.199", "dest_port": 12946, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T09:14:25.197205+0100", "src_ip": "64.62.197.65", "dest_ip": "134.19.55.199", "src_port": 52949, "dest_port": 12946}}'); INSERT INTO alerts VALUES(1423,1773044115.67157793,'{"timestamp": "2026-03-09T09:15:15.671578+0100", "flow_id": 914081309734617, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 25680, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:15:15.671578+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 25680}}'); INSERT INTO alerts VALUES(1424,1773044115.67157793,'{"timestamp": "2026-03-09T09:15:15.671578+0100", "flow_id": 914081309734617, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 25680, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:15:15.671578+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 25680}}'); INSERT INTO alerts VALUES(1425,1773044128.982762098,'{"timestamp": "2026-03-09T09:15:28.982762+0100", "flow_id": 280283755264545, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 57202, "dest_ip": "134.19.55.199", "dest_port": 3456, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:15:28.982762+0100", "src_ip": "45.142.193.7", "dest_ip": "134.19.55.199", "src_port": 57202, "dest_port": 3456}}'); INSERT INTO alerts VALUES(1426,1773044155.838803052,'{"timestamp": "2026-03-09T09:15:55.838803+0100", "flow_id": 1069360258432628, "event_type": "alert", "src_ip": "64.62.156.202", "src_port": 42934, "dest_ip": "134.19.55.199", "dest_port": 12346, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T09:15:55.838803+0100", "src_ip": "64.62.156.202", "dest_ip": "134.19.55.199", "src_port": 42934, "dest_port": 12346}}'); INSERT INTO alerts VALUES(1427,1773044199.861764907,'{"timestamp": "2026-03-09T09:16:39.861765+0100", "flow_id": 2012404053130059, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59559, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54235, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:16:39.861765+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59559, "dest_port": 53}}'); INSERT INTO alerts VALUES(1428,1773044199.861764907,'{"timestamp": "2026-03-09T09:16:39.861765+0100", "flow_id": 2012403483287141, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44044, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2839, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:16:39.861765+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44044, "dest_port": 53}}'); INSERT INTO alerts VALUES(1429,1773044226.218697071,'{"timestamp": "2026-03-09T09:17:06.218697+0100", "flow_id": 657824564535948, "event_type": "alert", "src_ip": "205.210.31.244", "src_port": 49455, "dest_ip": "134.19.55.199", "dest_port": 8999, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:17:06.218697+0100", "src_ip": "205.210.31.244", "dest_ip": "134.19.55.199", "src_port": 49455, "dest_port": 8999}}'); INSERT INTO alerts VALUES(1430,1773044279.001318931,'{"timestamp": "2026-03-09T09:17:59.001319+0100", "flow_id": 1975990468823946, "event_type": "alert", "src_ip": "205.210.31.192", "src_port": 56872, "dest_ip": "134.19.55.199", "dest_port": 5986, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:17:59.001319+0100", "src_ip": "205.210.31.192", "dest_ip": "134.19.55.199", "src_port": 56872, "dest_port": 5986}}'); INSERT INTO alerts VALUES(1431,1773044330.971462965,'{"timestamp": "2026-03-09T09:18:50.971463+0100", "flow_id": 794702302374444, "event_type": "alert", "src_ip": "176.65.149.137", "src_port": 40724, "dest_ip": "134.19.55.199", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:18:50.971463+0100", "src_ip": "176.65.149.137", "dest_ip": "134.19.55.199", "src_port": 40724, "dest_port": 25565}}'); INSERT INTO alerts VALUES(1432,1773044340.003519058,'{"timestamp": "2026-03-09T09:19:00.003519+0100", "flow_id": 1141015314169860, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 38794, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14069, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:19:00.003519+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 38794, "dest_port": 53}}'); INSERT INTO alerts VALUES(1433,1773044340.003520011,'{"timestamp": "2026-03-09T09:19:00.003520+0100", "flow_id": 1141022457828340, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50274, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37913, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:19:00.003520+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50274, "dest_port": 53}}'); INSERT INTO alerts VALUES(1434,1773044353.013748885,'{"timestamp": "2026-03-09T09:19:13.013749+0100", "flow_id": 340528370520090, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 56020, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:19:13.013749+0100", "src_ip": "45.153.34.32", "dest_ip": "134.19.55.199", "src_port": 56020, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1435,1773044353.013748885,'{"timestamp": "2026-03-09T09:19:13.013749+0100", "flow_id": 340528370520090, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 56020, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:19:13.013749+0100", "src_ip": "45.153.34.32", "dest_ip": "134.19.55.199", "src_port": 56020, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1436,1773044369.172286987,'{"timestamp": "2026-03-09T09:19:29.172287+0100", "flow_id": 458495340458124, "event_type": "alert", "src_ip": "101.0.104.38", "src_port": 5065, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 433, "bytes_toclient": 0, "start": "2026-03-09T09:19:29.172287+0100", "src_ip": "101.0.104.38", "dest_ip": "134.19.55.199", "src_port": 5065, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1437,1773044369.172286987,'{"timestamp": "2026-03-09T09:19:29.172287+0100", "flow_id": 458495340458124, "event_type": "alert", "src_ip": "101.0.104.38", "src_port": 5065, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 433, "bytes_toclient": 0, "start": "2026-03-09T09:19:29.172287+0100", "src_ip": "101.0.104.38", "dest_ip": "134.19.55.199", "src_port": 5065, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1438,1773044395.509852887,'{"timestamp": "2026-03-09T09:19:55.509853+0100", "flow_id": 1063902378216533, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42028, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28175, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T09:19:55.509853+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42028, "dest_port": 53}}'); INSERT INTO alerts VALUES(1439,1773044395.509852887,'{"timestamp": "2026-03-09T09:19:55.509853+0100", "flow_id": 1063904789710421, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34410, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48811, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T09:19:55.509853+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34410, "dest_port": 53}}'); INSERT INTO alerts VALUES(1440,1773044395.509852887,'{"timestamp": "2026-03-09T09:19:55.509853+0100", "flow_id": 1063904374895790, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3212, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T09:19:55.509853+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42102, "dest_port": 53}}'); INSERT INTO alerts VALUES(1441,1773044475.5512681,'{"timestamp": "2026-03-09T09:21:15.551268+0100", "flow_id": 960304235450066, "event_type": "alert", "src_ip": "198.235.24.247", "src_port": 50940, "dest_ip": "134.19.55.199", "dest_port": 20256, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:21:15.551268+0100", "src_ip": "198.235.24.247", "dest_ip": "134.19.55.199", "src_port": 50940, "dest_port": 20256}}'); INSERT INTO alerts VALUES(1442,1773044479.999998093,'{"timestamp": "2026-03-09T09:21:19.999998+0100", "flow_id": 2043161913295592, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 56387, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30892, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:21:19.999998+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 56387, "dest_port": 53}}'); INSERT INTO alerts VALUES(1443,1773044479.999999046,'{"timestamp": "2026-03-09T09:21:19.999999+0100", "flow_id": 2043163546959568, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36307, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53775, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:21:19.999999+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36307, "dest_port": 53}}'); INSERT INTO alerts VALUES(1444,1773044490.643320083,'{"timestamp": "2026-03-09T09:21:30.643320+0100", "flow_id": 792715016915541, "event_type": "alert", "src_ip": "91.224.92.177", "src_port": 37541, "dest_ip": "134.19.55.199", "dest_port": 4001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:21:30.643320+0100", "src_ip": "91.224.92.177", "dest_ip": "134.19.55.199", "src_port": 37541, "dest_port": 4001}}'); INSERT INTO alerts VALUES(1445,1773044502.888067008,'{"timestamp": "2026-03-09T09:21:42.888067+0100", "flow_id": 1843896224484720, "event_type": "alert", "src_ip": "64.62.197.191", "src_port": 49918, "dest_ip": "134.19.55.199", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:21:42.888067+0100", "src_ip": "64.62.197.191", "dest_ip": "134.19.55.199", "src_port": 49918, "dest_port": 8088}}'); INSERT INTO alerts VALUES(1446,1773044540.238090038,'{"timestamp": "2026-03-09T09:22:20.238090+0100", "flow_id": 1304067473423008, "event_type": "alert", "src_ip": "167.94.146.34", "src_port": 14786, "dest_ip": "134.19.55.199", "dest_port": 60037, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:22:20.238090+0100", "src_ip": "167.94.146.34", "dest_ip": "134.19.55.199", "src_port": 14786, "dest_port": 60037}}'); INSERT INTO alerts VALUES(1447,1773044565.264852046,'{"timestamp": "2026-03-09T09:22:45.264852+0100", "flow_id": 1419006472993875, "event_type": "alert", "src_ip": "46.19.137.194", "src_port": 33941, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:22:45.264852+0100", "src_ip": "46.19.137.194", "dest_ip": "134.19.55.199", "src_port": 33941, "dest_port": 5432}}'); INSERT INTO alerts VALUES(1448,1773044603.744714976,'{"timestamp": "2026-03-09T09:23:23.744715+0100", "flow_id": 946729307548218, "event_type": "alert", "src_ip": "195.184.76.169", "src_port": 14570, "dest_ip": "134.19.55.199", "dest_port": 5715, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:23:23.744715+0100", "src_ip": "195.184.76.169", "dest_ip": "134.19.55.199", "src_port": 14570, "dest_port": 5715}}'); INSERT INTO alerts VALUES(1449,1773044620.068018914,'{"timestamp": "2026-03-09T09:23:40.068019+0100", "flow_id": 1136567081836935, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44717, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25572, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:23:40.068019+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44717, "dest_port": 53}}'); INSERT INTO alerts VALUES(1450,1773044620.06873703,'{"timestamp": "2026-03-09T09:23:40.068737+0100", "flow_id": 1139651661978686, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 52527, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48640, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:23:40.068737+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 52527, "dest_port": 53}}'); INSERT INTO alerts VALUES(1451,1773044684.003392935,'{"timestamp": "2026-03-09T09:24:44.003393+0100", "flow_id": 1140474429737190, "event_type": "alert", "src_ip": "65.49.1.193", "src_port": 34897, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:24:44.003393+0100", "src_ip": "65.49.1.193", "dest_ip": "134.19.55.199", "src_port": 34897, "dest_port": 5555}}'); INSERT INTO alerts VALUES(1452,1773044700.124670028,'{"timestamp": "2026-03-09T09:25:00.124670+0100", "flow_id": 1379880349856355, "event_type": "alert", "src_ip": "198.235.24.162", "src_port": 52446, "dest_ip": "134.19.55.199", "dest_port": 8445, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:25:00.124670+0100", "src_ip": "198.235.24.162", "dest_ip": "134.19.55.199", "src_port": 52446, "dest_port": 8445}}'); INSERT INTO alerts VALUES(1453,1773044743.613816023,'{"timestamp": "2026-03-09T09:25:43.613816+0100", "flow_id": 2073369894975566, "event_type": "alert", "src_ip": "167.94.138.136", "src_port": 42476, "dest_ip": "134.19.55.199", "dest_port": 1099, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:25:43.613816+0100", "src_ip": "167.94.138.136", "dest_ip": "134.19.55.199", "src_port": 42476, "dest_port": 1099}}'); INSERT INTO alerts VALUES(1454,1773044760.151372909,'{"timestamp": "2026-03-09T09:26:00.151373+0100", "flow_id": 87193047255029, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57814, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25297, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:26:00.151373+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57814, "dest_port": 53}}'); INSERT INTO alerts VALUES(1455,1773044760.151372909,'{"timestamp": "2026-03-09T09:26:00.151373+0100", "flow_id": 87193809980613, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33729, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60361, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:26:00.151373+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33729, "dest_port": 53}}'); INSERT INTO alerts VALUES(1456,1773044762.199816943,'{"timestamp": "2026-03-09T09:26:02.199817+0100", "flow_id": 576736742323707, "event_type": "alert", "src_ip": "205.210.31.46", "src_port": 55904, "dest_ip": "134.19.55.199", "dest_port": 51200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:26:02.199817+0100", "src_ip": "205.210.31.46", "dest_ip": "134.19.55.199", "src_port": 55904, "dest_port": 51200}}'); INSERT INTO alerts VALUES(1457,1773044852.661552906,'{"timestamp": "2026-03-09T09:27:32.661553+0100", "flow_id": 1152499897246925, "event_type": "alert", "src_ip": "180.244.51.235", "src_port": 55240, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:27:32.661553+0100", "src_ip": "180.244.51.235", "dest_ip": "134.19.55.199", "src_port": 55240, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1458,1773044861.785300971,'{"timestamp": "2026-03-09T09:27:41.785301+0100", "flow_id": 1683992479039253, "event_type": "alert", "src_ip": "91.196.152.185", "src_port": 35395, "dest_ip": "134.19.55.199", "dest_port": 20042, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:27:41.785301+0100", "src_ip": "91.196.152.185", "dest_ip": "134.19.55.199", "src_port": 35395, "dest_port": 20042}}'); INSERT INTO alerts VALUES(1459,1773044898.52777791,'{"timestamp": "2026-03-09T09:28:18.527778+0100", "flow_id": 577941453365425, "event_type": "alert", "src_ip": "64.62.197.221", "src_port": 36163, "dest_ip": "134.19.55.199", "dest_port": 8013, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:28:18.527778+0100", "src_ip": "64.62.197.221", "dest_ip": "134.19.55.199", "src_port": 36163, "dest_port": 8013}}'); INSERT INTO alerts VALUES(1460,1773044900.221587897,'{"timestamp": "2026-03-09T09:28:20.221588+0100", "flow_id": 1233191928490477, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39806, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13658, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:28:20.221588+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39806, "dest_port": 53}}'); INSERT INTO alerts VALUES(1461,1773044900.221589088,'{"timestamp": "2026-03-09T09:28:20.221589+0100", "flow_id": 1233193978843483, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41537, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42886, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:28:20.221589+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41537, "dest_port": 53}}'); INSERT INTO alerts VALUES(1462,1773044919.415287972,'{"timestamp": "2026-03-09T09:28:39.415288+0100", "flow_id": 2065126116216962, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 58054, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27049, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T09:28:39.415288+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 58054, "dest_port": 53}}'); INSERT INTO alerts VALUES(1463,1773044919.415288925,'{"timestamp": "2026-03-09T09:28:39.415289+0100", "flow_id": 2065129347519441, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 45833, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53873, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T09:28:39.415289+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 45833, "dest_port": 53}}'); INSERT INTO alerts VALUES(1464,1773044919.415288925,'{"timestamp": "2026-03-09T09:28:39.415289+0100", "flow_id": 2065127670454905, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43560, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30084, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T09:28:39.415289+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43560, "dest_port": 53}}'); INSERT INTO alerts VALUES(1465,1773044923.942961931,'{"timestamp": "2026-03-09T09:28:43.942962+0100", "flow_id": 953768157983165, "event_type": "alert", "src_ip": "91.196.152.183", "src_port": 8192, "dest_ip": "134.19.55.199", "dest_port": 2015, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:28:43.942962+0100", "src_ip": "91.196.152.183", "dest_ip": "134.19.55.199", "src_port": 8192, "dest_port": 2015}}'); INSERT INTO alerts VALUES(1466,1773044949.709652901,'{"timestamp": "2026-03-09T09:29:09.709653+0100", "flow_id": 1640562830660161, "event_type": "alert", "src_ip": "198.235.24.78", "src_port": 25938, "dest_ip": "134.19.55.199", "dest_port": 12646, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T09:29:09.709653+0100", "src_ip": "198.235.24.78", "dest_ip": "134.19.55.199", "src_port": 25938, "dest_port": 12646}}'); INSERT INTO alerts VALUES(1467,1773045010.226201058,'{"timestamp": "2026-03-09T09:30:10.226201+0100", "flow_id": 690054284348577, "event_type": "alert", "src_ip": "65.49.1.229", "src_port": 56105, "dest_ip": "134.19.55.199", "dest_port": 51200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:30:10.226201+0100", "src_ip": "65.49.1.229", "dest_ip": "134.19.55.199", "src_port": 56105, "dest_port": 51200}}'); INSERT INTO alerts VALUES(1468,1773045040.244651079,'{"timestamp": "2026-03-09T09:30:40.244651+0100", "flow_id": 206343253426708, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36854, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22254, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:30:40.244651+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36854, "dest_port": 53}}'); INSERT INTO alerts VALUES(1469,1773045040.244651079,'{"timestamp": "2026-03-09T09:30:40.244651+0100", "flow_id": 206343994992522, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36139, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59902, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:30:40.244651+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36139, "dest_port": 53}}'); INSERT INTO alerts VALUES(1470,1773045080.225939035,'{"timestamp": "2026-03-09T09:31:20.225939+0100", "flow_id": 125977959126070, "event_type": "alert", "src_ip": "167.94.138.151", "src_port": 38028, "dest_ip": "134.19.55.199", "dest_port": 1963, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:31:20.225939+0100", "src_ip": "167.94.138.151", "dest_ip": "134.19.55.199", "src_port": 38028, "dest_port": 1963}}'); INSERT INTO alerts VALUES(1471,1773045081.253632068,'{"timestamp": "2026-03-09T09:31:21.253632+0100", "flow_id": 526392546874603, "event_type": "alert", "src_ip": "205.210.31.248", "src_port": 57033, "dest_ip": "134.19.55.199", "dest_port": 1194, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:31:21.253632+0100", "src_ip": "205.210.31.248", "dest_ip": "134.19.55.199", "src_port": 57033, "dest_port": 1194}}'); INSERT INTO alerts VALUES(1472,1773045180.293905019,'{"timestamp": "2026-03-09T09:33:00.293905+0100", "flow_id": 1262316300207058, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 54159, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61799, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:33:00.293905+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 54159, "dest_port": 53}}'); INSERT INTO alerts VALUES(1473,1773045180.294265032,'{"timestamp": "2026-03-09T09:33:00.294265+0100", "flow_id": 1263859867249012, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 37600, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19700, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:33:00.294265+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 37600, "dest_port": 53}}'); INSERT INTO alerts VALUES(1474,1773045193.660116911,'{"timestamp": "2026-03-09T09:33:13.660117+0100", "flow_id": 301909219085434, "event_type": "alert", "src_ip": "65.49.1.210", "src_port": 47895, "dest_ip": "134.19.55.199", "dest_port": 9643, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:33:13.660117+0100", "src_ip": "65.49.1.210", "dest_ip": "134.19.55.199", "src_port": 47895, "dest_port": 9643}}'); INSERT INTO alerts VALUES(1475,1773045198.348819971,'{"timestamp": "2026-03-09T09:33:18.348820+0100", "flow_id": 1779645965882323, "event_type": "alert", "src_ip": "176.65.139.31", "src_port": 61338, "dest_ip": "134.19.55.199", "dest_port": 389, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ldap", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-09T09:33:18.348820+0100", "src_ip": "176.65.139.31", "dest_ip": "134.19.55.199", "src_port": 61338, "dest_port": 389}}'); INSERT INTO alerts VALUES(1476,1773045278.472661018,'{"timestamp": "2026-03-09T09:34:38.472661+0100", "flow_id": 1748592173605967, "event_type": "alert", "src_ip": "45.153.34.187", "src_port": 52542, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:34:38.472661+0100", "src_ip": "45.153.34.187", "dest_ip": "134.19.55.199", "src_port": 52542, "dest_port": 80}}'); INSERT INTO alerts VALUES(1477,1773045309.715058089,'{"timestamp": "2026-03-09T09:35:09.715058+0100", "flow_id": 1663779436456008, "event_type": "alert", "src_ip": "195.184.76.91", "src_port": 45639, "dest_ip": "134.19.55.199", "dest_port": 7018, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:35:09.715058+0100", "src_ip": "195.184.76.91", "dest_ip": "134.19.55.199", "src_port": 45639, "dest_port": 7018}}'); INSERT INTO alerts VALUES(1478,1773045318.466763974,'{"timestamp": "2026-03-09T09:35:18.466764+0100", "flow_id": 1723264751270993, "event_type": "alert", "src_ip": "205.210.31.67", "src_port": 54577, "dest_ip": "134.19.55.199", "dest_port": 64719, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:35:18.466764+0100", "src_ip": "205.210.31.67", "dest_ip": "134.19.55.199", "src_port": 54577, "dest_port": 64719}}'); INSERT INTO alerts VALUES(1479,1773045320.345383883,'{"timestamp": "2026-03-09T09:35:20.345384+0100", "flow_id": 76038539851360, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 38696, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4520, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:35:20.345384+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 38696, "dest_port": 53}}'); INSERT INTO alerts VALUES(1480,1773045320.345383883,'{"timestamp": "2026-03-09T09:35:20.345384+0100", "flow_id": 76040961911204, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50489, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:35:20.345384+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50489, "dest_port": 53}}'); INSERT INTO alerts VALUES(1481,1773045322.583067894,'{"timestamp": "2026-03-09T09:35:22.583068+0100", "flow_id": 815411133503889, "event_type": "alert", "src_ip": "185.242.226.87", "src_port": 55903, "dest_ip": "134.19.55.199", "dest_port": 9003, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:35:22.583068+0100", "src_ip": "185.242.226.87", "dest_ip": "134.19.55.199", "src_port": 55903, "dest_port": 9003}}'); INSERT INTO alerts VALUES(1482,1773045367.761121034,'{"timestamp": "2026-03-09T09:36:07.761121+0100", "flow_id": 2143094151055263, "event_type": "alert", "src_ip": "176.65.139.41", "src_port": 50000, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:36:07.761121+0100", "src_ip": "176.65.139.41", "dest_ip": "134.19.55.199", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(1483,1773045373.114263057,'{"timestamp": "2026-03-09T09:36:13.114263+0100", "flow_id": 1616656691709882, "event_type": "alert", "src_ip": "65.49.1.185", "src_port": 57734, "dest_ip": "134.19.55.199", "dest_port": 63256, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:36:13.114263+0100", "src_ip": "65.49.1.185", "dest_ip": "134.19.55.199", "src_port": 57734, "dest_port": 63256}}'); INSERT INTO alerts VALUES(1484,1773045380.569093942,'{"timestamp": "2026-03-09T09:36:20.569094+0100", "flow_id": 1318341957709888, "event_type": "alert", "src_ip": "176.65.148.2", "src_port": 57175, "dest_ip": "134.19.55.199", "dest_port": 8089, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:36:20.569094+0100", "src_ip": "176.65.148.2", "dest_ip": "134.19.55.199", "src_port": 57175, "dest_port": 8089}}'); INSERT INTO alerts VALUES(1485,1773045380.569093942,'{"timestamp": "2026-03-09T09:36:20.569094+0100", "flow_id": 1318341957709888, "event_type": "alert", "src_ip": "176.65.148.2", "src_port": 57175, "dest_ip": "134.19.55.199", "dest_port": 8089, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:36:20.569094+0100", "src_ip": "176.65.148.2", "dest_ip": "134.19.55.199", "src_port": 57175, "dest_port": 8089}}'); INSERT INTO alerts VALUES(1486,1773045432.836966038,'{"timestamp": "2026-03-09T09:37:12.836966+0100", "flow_id": 217043164775572, "event_type": "alert", "src_ip": "65.49.1.171", "src_port": 50623, "dest_ip": "134.19.55.199", "dest_port": 541, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:37:12.836966+0100", "src_ip": "65.49.1.171", "dest_ip": "134.19.55.199", "src_port": 50623, "dest_port": 541}}'); INSERT INTO alerts VALUES(1487,1773045460.437838078,'{"timestamp": "2026-03-09T09:37:40.437838+0100", "flow_id": 1317551191523453, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36155, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54539, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:37:40.437838+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36155, "dest_port": 53}}'); INSERT INTO alerts VALUES(1488,1773045460.437838078,'{"timestamp": "2026-03-09T09:37:40.437838+0100", "flow_id": 1317552950757742, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43919, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7033, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:37:40.437838+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43919, "dest_port": 53}}'); INSERT INTO alerts VALUES(1489,1773045461.906254054,'{"timestamp": "2026-03-09T09:37:41.906254+0100", "flow_id": 1640532544028723, "event_type": "alert", "src_ip": "205.210.31.97", "src_port": 54559, "dest_ip": "134.19.55.199", "dest_port": 9002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:37:41.906254+0100", "src_ip": "205.210.31.97", "dest_ip": "134.19.55.199", "src_port": 54559, "dest_port": 9002}}'); INSERT INTO alerts VALUES(1490,1773045500.465656996,'{"timestamp": "2026-03-09T09:38:20.465657+0100", "flow_id": 1155559156896761, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 41489, "dest_ip": "134.19.55.199", "dest_port": 2222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:38:20.465657+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.55.199", "src_port": 41489, "dest_port": 2222}}'); INSERT INTO alerts VALUES(1491,1773045500.465656996,'{"timestamp": "2026-03-09T09:38:20.465657+0100", "flow_id": 1155559156896761, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 41489, "dest_ip": "134.19.55.199", "dest_port": 2222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:38:20.465657+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.55.199", "src_port": 41489, "dest_port": 2222}}'); INSERT INTO alerts VALUES(1492,1773045506.111042977,'{"timestamp": "2026-03-09T09:38:26.111043+0100", "flow_id": 758402003668203, "event_type": "alert", "src_ip": "205.210.31.238", "src_port": 51736, "dest_ip": "134.19.55.199", "dest_port": 9001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:38:26.111043+0100", "src_ip": "205.210.31.238", "dest_ip": "134.19.55.199", "src_port": 51736, "dest_port": 9001}}'); INSERT INTO alerts VALUES(1493,1773045512.172291995,'{"timestamp": "2026-03-09T09:38:32.172292+0100", "flow_id": 177040053908772, "event_type": "alert", "src_ip": "205.210.31.72", "src_port": 54627, "dest_ip": "134.19.55.199", "dest_port": 23956, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:38:32.172292+0100", "src_ip": "205.210.31.72", "dest_ip": "134.19.55.199", "src_port": 54627, "dest_port": 23956}}'); INSERT INTO alerts VALUES(1494,1773045519.465253115,'{"timestamp": "2026-03-09T09:38:39.465253+0100", "flow_id": 1998248612377660, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 45427, "dest_ip": "134.19.55.199", "dest_port": 23001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:38:39.465253+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 45427, "dest_port": 23001}}'); INSERT INTO alerts VALUES(1495,1773045600.491790057,'{"timestamp": "2026-03-09T09:40:00.491790+0100", "flow_id": 141900826779639, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39912, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31599, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:40:00.491790+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39912, "dest_port": 53}}'); INSERT INTO alerts VALUES(1496,1773045600.491790057,'{"timestamp": "2026-03-09T09:40:00.491790+0100", "flow_id": 141899994857605, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 37054, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33234, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:40:00.491790+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 37054, "dest_port": 53}}'); INSERT INTO alerts VALUES(1497,1773045628.538393021,'{"timestamp": "2026-03-09T09:40:28.538393+0100", "flow_id": 1186481906155152, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 49971, "dest_ip": "134.19.55.199", "dest_port": 9090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:40:28.538393+0100", "src_ip": "193.142.146.230", "dest_ip": "134.19.55.199", "src_port": 49971, "dest_port": 9090}}'); INSERT INTO alerts VALUES(1498,1773045633.58514595,'{"timestamp": "2026-03-09T09:40:33.585146+0100", "flow_id": 542860013858820, "event_type": "alert", "src_ip": "45.135.194.48", "src_port": 39745, "dest_ip": "134.19.55.199", "dest_port": 5901, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T09:40:33.585146+0100", "src_ip": "45.135.194.48", "dest_ip": "134.19.55.199", "src_port": 39745, "dest_port": 5901}}'); INSERT INTO alerts VALUES(1499,1773045707.602686883,'{"timestamp": "2026-03-09T09:41:47.602687+0100", "flow_id": 899675147179857, "event_type": "alert", "src_ip": "87.121.84.88", "src_port": 60000, "dest_ip": "134.19.55.199", "dest_port": 22144, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:41:47.602687+0100", "src_ip": "87.121.84.88", "dest_ip": "134.19.55.199", "src_port": 60000, "dest_port": 22144}}'); INSERT INTO alerts VALUES(1500,1773045717.587881089,'{"timestamp": "2026-03-09T09:41:57.587881+0100", "flow_id": 1680506001389342, "event_type": "alert", "src_ip": "64.62.156.164", "src_port": 38186, "dest_ip": "134.19.55.199", "dest_port": 8070, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:41:57.587881+0100", "src_ip": "64.62.156.164", "dest_ip": "134.19.55.199", "src_port": 38186, "dest_port": 8070}}'); INSERT INTO alerts VALUES(1501,1773045740.530745983,'{"timestamp": "2026-03-09T09:42:20.530746+0100", "flow_id": 1153640096745474, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42535, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34347, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:42:20.530746+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42535, "dest_port": 53}}'); INSERT INTO alerts VALUES(1502,1773045740.530746936,'{"timestamp": "2026-03-09T09:42:20.530747+0100", "flow_id": 1153644625821551, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50579, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42533, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:42:20.530747+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50579, "dest_port": 53}}'); INSERT INTO alerts VALUES(1503,1773045768.953814029,'{"timestamp": "2026-03-09T09:42:48.953814+0100", "flow_id": 155954380122745, "event_type": "alert", "src_ip": "176.65.148.95", "src_port": 55629, "dest_ip": "134.19.55.199", "dest_port": 13131, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:42:48.953814+0100", "src_ip": "176.65.148.95", "dest_ip": "134.19.55.199", "src_port": 55629, "dest_port": 13131}}'); INSERT INTO alerts VALUES(1504,1773045768.953814029,'{"timestamp": "2026-03-09T09:42:48.953814+0100", "flow_id": 155954380122745, "event_type": "alert", "src_ip": "176.65.148.95", "src_port": 55629, "dest_ip": "134.19.55.199", "dest_port": 13131, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:42:48.953814+0100", "src_ip": "176.65.148.95", "dest_ip": "134.19.55.199", "src_port": 55629, "dest_port": 13131}}'); INSERT INTO alerts VALUES(1505,1773045848.041843892,'{"timestamp": "2026-03-09T09:44:08.041844+0100", "flow_id": 179722264749397, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59710, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15548, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T09:44:08.041844+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59710, "dest_port": 53}}'); INSERT INTO alerts VALUES(1506,1773045848.041843892,'{"timestamp": "2026-03-09T09:44:08.041844+0100", "flow_id": 179722882176167, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40193, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T09:44:08.041844+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40193, "dest_port": 53}}'); INSERT INTO alerts VALUES(1507,1773045848.041845083,'{"timestamp": "2026-03-09T09:44:08.041845+0100", "flow_id": 179722999520322, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39011, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36740, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T09:44:08.041845+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39011, "dest_port": 53}}'); INSERT INTO alerts VALUES(1508,1773045880.578490972,'{"timestamp": "2026-03-09T09:44:40.578491+0100", "flow_id": 232803773882939, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49629, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50785, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:44:40.578491+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49629, "dest_port": 53}}'); INSERT INTO alerts VALUES(1509,1773045880.578871966,'{"timestamp": "2026-03-09T09:44:40.578872+0100", "flow_id": 234437840926383, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49655, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27164, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:44:40.578872+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49655, "dest_port": 53}}'); INSERT INTO alerts VALUES(1510,1773045885.916740894,'{"timestamp": "2026-03-09T09:44:45.916741+0100", "flow_id": 1685573372466714, "event_type": "alert", "src_ip": "205.210.31.177", "src_port": 56060, "dest_ip": "134.19.55.199", "dest_port": 10001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:44:45.916741+0100", "src_ip": "205.210.31.177", "dest_ip": "134.19.55.199", "src_port": 56060, "dest_port": 10001}}'); INSERT INTO alerts VALUES(1511,1773045921.65651393,'{"timestamp": "2026-03-09T09:45:21.656514+0100", "flow_id": 286433770308303, "event_type": "alert", "src_ip": "147.185.132.210", "src_port": 30153, "dest_ip": "134.19.55.199", "dest_port": 13746, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T09:45:21.656514+0100", "src_ip": "147.185.132.210", "dest_ip": "134.19.55.199", "src_port": 30153, "dest_port": 13746}}'); INSERT INTO alerts VALUES(1512,1773045922.362335921,'{"timestamp": "2026-03-09T09:45:22.362336+0100", "flow_id": 711798044549105, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 40426, "dest_ip": "134.19.55.199", "dest_port": 12259, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:45:22.362336+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 40426, "dest_port": 12259}}'); INSERT INTO alerts VALUES(1513,1773045976.143404007,'{"timestamp": "2026-03-09T09:46:16.143404+0100", "flow_id": 52967609337277, "event_type": "alert", "src_ip": "195.184.76.243", "src_port": 47889, "dest_ip": "134.19.55.199", "dest_port": 6013, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:46:16.143404+0100", "src_ip": "195.184.76.243", "dest_ip": "134.19.55.199", "src_port": 47889, "dest_port": 6013}}'); INSERT INTO alerts VALUES(1514,1773045997.731548071,'{"timestamp": "2026-03-09T09:46:37.731548+0100", "flow_id": 1453128050700273, "event_type": "alert", "src_ip": "185.156.73.182", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 6443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:46:37.731548+0100", "src_ip": "185.156.73.182", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 6443}}'); INSERT INTO alerts VALUES(1515,1773046020.635909081,'{"timestamp": "2026-03-09T09:47:00.635909+0100", "flow_id": 1323835807937908, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42474, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26682, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:47:00.635909+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42474, "dest_port": 53}}'); INSERT INTO alerts VALUES(1516,1773046020.636168003,'{"timestamp": "2026-03-09T09:47:00.636168+0100", "flow_id": 1324947642602969, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33269, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45898, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:47:00.636168+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33269, "dest_port": 53}}'); INSERT INTO alerts VALUES(1517,1773046042.285305976,'{"timestamp": "2026-03-09T09:47:22.285306+0100", "flow_id": 662432869666526, "event_type": "alert", "src_ip": "193.163.125.199", "src_port": 49778, "dest_ip": "134.19.55.199", "dest_port": 12032, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:47:22.285306+0100", "src_ip": "193.163.125.199", "dest_ip": "134.19.55.199", "src_port": 49778, "dest_port": 12032}}'); INSERT INTO alerts VALUES(1518,1773046074.778851986,'{"timestamp": "2026-03-09T09:47:54.778852+0100", "flow_id": 811870028411673, "event_type": "alert", "src_ip": "195.184.76.221", "src_port": 39802, "dest_ip": "134.19.55.199", "dest_port": 5161, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:47:54.778852+0100", "src_ip": "195.184.76.221", "dest_ip": "134.19.55.199", "src_port": 39802, "dest_port": 5161}}'); INSERT INTO alerts VALUES(1519,1773046110.645456076,'{"timestamp": "2026-03-09T09:48:30.645456+0100", "flow_id": 1927788591178018, "event_type": "alert", "src_ip": "65.49.1.144", "src_port": 55346, "dest_ip": "134.19.55.199", "dest_port": 5002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:48:30.645456+0100", "src_ip": "65.49.1.144", "dest_ip": "134.19.55.199", "src_port": 55346, "dest_port": 5002}}'); INSERT INTO alerts VALUES(1520,1773046120.272737026,'{"timestamp": "2026-03-09T09:48:40.272737+0100", "flow_id": 45496638072954, "event_type": "alert", "src_ip": "45.156.87.91", "src_port": 54595, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:48:40.272737+0100", "src_ip": "45.156.87.91", "dest_ip": "134.19.55.199", "src_port": 54595, "dest_port": 5555}}'); INSERT INTO alerts VALUES(1521,1773046128.248372077,'{"timestamp": "2026-03-09T09:48:48.248372+0100", "flow_id": 222327328122459, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 42790, "dest_ip": "134.19.55.199", "dest_port": 32860, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:48:48.248372+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 42790, "dest_port": 32860}}'); INSERT INTO alerts VALUES(1522,1773046149.336595058,'{"timestamp": "2026-03-09T09:49:09.336595+0100", "flow_id": 1445667814656038, "event_type": "alert", "src_ip": "64.62.197.240", "src_port": 38931, "dest_ip": "134.19.55.199", "dest_port": 4646, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:49:09.336595+0100", "src_ip": "64.62.197.240", "dest_ip": "134.19.55.199", "src_port": 38931, "dest_port": 4646}}'); INSERT INTO alerts VALUES(1523,1773046160.688671113,'{"timestamp": "2026-03-09T09:49:20.688671+0100", "flow_id": 143070397574035, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39269, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53171, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:49:20.688671+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39269, "dest_port": 53}}'); INSERT INTO alerts VALUES(1524,1773046160.688934088,'{"timestamp": "2026-03-09T09:49:20.688934+0100", "flow_id": 144199581553308, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42659, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30834, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:49:20.688934+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42659, "dest_port": 53}}'); INSERT INTO alerts VALUES(1525,1773046300.75632596,'{"timestamp": "2026-03-09T09:51:40.756326+0100", "flow_id": 1278074269586303, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41296, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40213, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:51:40.756326+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41296, "dest_port": 53}}'); INSERT INTO alerts VALUES(1526,1773046300.75632596,'{"timestamp": "2026-03-09T09:51:40.756326+0100", "flow_id": 1278071335415841, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43011, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:51:40.756326+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57876, "dest_port": 53}}'); INSERT INTO alerts VALUES(1527,1773046319.23921895,'{"timestamp": "2026-03-09T09:51:59.239219+0100", "flow_id": 2153338780884923, "event_type": "alert", "src_ip": "205.210.31.217", "src_port": 16260, "dest_ip": "134.19.55.199", "dest_port": 13446, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T09:51:59.239219+0100", "src_ip": "205.210.31.217", "dest_ip": "134.19.55.199", "src_port": 16260, "dest_port": 13446}}'); INSERT INTO alerts VALUES(1528,1773046352.239377021,'{"timestamp": "2026-03-09T09:52:32.239377+0100", "flow_id": 183692549405446, "event_type": "alert", "src_ip": "205.210.31.85", "src_port": 52997, "dest_ip": "134.19.55.199", "dest_port": 1883, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:52:32.239377+0100", "src_ip": "205.210.31.85", "dest_ip": "134.19.55.199", "src_port": 52997, "dest_port": 1883}}'); INSERT INTO alerts VALUES(1529,1773046433.905982972,'{"timestamp": "2026-03-09T09:53:53.905983+0100", "flow_id": 513468953859572, "event_type": "alert", "src_ip": "198.143.149.250", "src_port": 11281, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 433, "bytes_toclient": 0, "start": "2026-03-09T09:53:53.905983+0100", "src_ip": "198.143.149.250", "dest_ip": "134.19.55.199", "src_port": 11281, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1530,1773046433.905982972,'{"timestamp": "2026-03-09T09:53:53.905983+0100", "flow_id": 513468953859572, "event_type": "alert", "src_ip": "198.143.149.250", "src_port": 11281, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 433, "bytes_toclient": 0, "start": "2026-03-09T09:53:53.905983+0100", "src_ip": "198.143.149.250", "dest_ip": "134.19.55.199", "src_port": 11281, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1531,1773046440.809910058,'{"timestamp": "2026-03-09T09:54:00.809910+0100", "flow_id": 100840580881214, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46071, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40822, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:54:00.809910+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46071, "dest_port": 53}}'); INSERT INTO alerts VALUES(1532,1773046440.809910058,'{"timestamp": "2026-03-09T09:54:00.809910+0100", "flow_id": 100839574856715, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 37834, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26618, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:54:00.809910+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 37834, "dest_port": 53}}'); INSERT INTO alerts VALUES(1533,1773046477.0237391,'{"timestamp": "2026-03-09T09:54:37.023739+0100", "flow_id": 1509335673121219, "event_type": "alert", "src_ip": "193.163.125.183", "src_port": 44670, "dest_ip": "134.19.55.199", "dest_port": 8072, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T09:54:37.023739+0100", "src_ip": "193.163.125.183", "dest_ip": "134.19.55.199", "src_port": 44670, "dest_port": 8072}}'); INSERT INTO alerts VALUES(1534,1773046553.587918997,'{"timestamp": "2026-03-09T09:55:53.587919+0100", "flow_id": 554768475543565, "event_type": "alert", "src_ip": "64.62.156.29", "src_port": 50959, "dest_ip": "134.19.55.199", "dest_port": 20443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:55:53.587919+0100", "src_ip": "64.62.156.29", "dest_ip": "134.19.55.199", "src_port": 50959, "dest_port": 20443}}'); INSERT INTO alerts VALUES(1535,1773046567.46844101,'{"timestamp": "2026-03-09T09:56:07.468441+0100", "flow_id": 2011940763299188, "event_type": "alert", "src_ip": "64.62.197.94", "src_port": 49228, "dest_ip": "134.19.55.199", "dest_port": 2600, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:56:07.468441+0100", "src_ip": "64.62.197.94", "dest_ip": "134.19.55.199", "src_port": 49228, "dest_port": 2600}}'); INSERT INTO alerts VALUES(1536,1773046580.975898981,'{"timestamp": "2026-03-09T09:56:20.975899+0100", "flow_id": 1376708547159379, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44635, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32389, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:56:20.975899+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44635, "dest_port": 53}}'); INSERT INTO alerts VALUES(1537,1773046580.975898981,'{"timestamp": "2026-03-09T09:56:20.975899+0100", "flow_id": 1376704716385588, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46321, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8888, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:56:20.975899+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46321, "dest_port": 53}}'); INSERT INTO alerts VALUES(1538,1773046600.78478694,'{"timestamp": "2026-03-09T09:56:40.784787+0100", "flow_id": 274413992544441, "event_type": "alert", "src_ip": "195.184.76.19", "src_port": 17966, "dest_ip": "134.19.55.199", "dest_port": 52931, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T09:56:40.784787+0100", "src_ip": "195.184.76.19", "dest_ip": "134.19.55.199", "src_port": 17966, "dest_port": 52931}}'); INSERT INTO alerts VALUES(1539,1773046646.778529882,'{"timestamp": "2026-03-09T09:57:26.778530+0100", "flow_id": 1936389437529415, "event_type": "alert", "src_ip": "176.65.132.5", "src_port": 60136, "dest_ip": "134.19.55.199", "dest_port": 3160, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T09:57:26.778530+0100", "src_ip": "176.65.132.5", "dest_ip": "134.19.55.199", "src_port": 60136, "dest_port": 3160}}'); INSERT INTO alerts VALUES(1540,1773046664.031532049,'{"timestamp": "2026-03-09T09:57:44.031532+0100", "flow_id": 135431287138232, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 3002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:57:44.031532+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 3002}}'); INSERT INTO alerts VALUES(1541,1773046664.031532049,'{"timestamp": "2026-03-09T09:57:44.031532+0100", "flow_id": 135431287138232, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 3002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:57:44.031532+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 3002}}'); INSERT INTO alerts VALUES(1542,1773046693.390922069,'{"timestamp": "2026-03-09T09:58:13.390922+0100", "flow_id": 1679000704684018, "event_type": "alert", "src_ip": "65.49.1.12", "src_port": 52934, "dest_ip": "134.19.55.199", "dest_port": 5903, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:58:13.390922+0100", "src_ip": "65.49.1.12", "dest_ip": "134.19.55.199", "src_port": 52934, "dest_port": 5903}}'); INSERT INTO alerts VALUES(1543,1773046721.048439026,'{"timestamp": "2026-03-09T09:58:41.048439+0100", "flow_id": 489520157497724, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60207, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56905, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:58:41.048439+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60207, "dest_port": 53}}'); INSERT INTO alerts VALUES(1544,1773046721.048439026,'{"timestamp": "2026-03-09T09:58:41.048439+0100", "flow_id": 489520784584198, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 45631, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9524, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T09:58:41.048439+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 45631, "dest_port": 53}}'); INSERT INTO alerts VALUES(1545,1773046783.156860114,'{"timestamp": "2026-03-09T09:59:43.156860+0100", "flow_id": 2081087466749201, "event_type": "alert", "src_ip": "65.49.1.62", "src_port": 33620, "dest_ip": "134.19.55.199", "dest_port": 811, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T09:59:43.156860+0100", "src_ip": "65.49.1.62", "dest_ip": "134.19.55.199", "src_port": 33620, "dest_port": 811}}'); INSERT INTO alerts VALUES(1546,1773046805.680542946,'{"timestamp": "2026-03-09T10:00:05.680543+0100", "flow_id": 1515537807309065, "event_type": "alert", "src_ip": "167.94.146.44", "src_port": 62868, "dest_ip": "134.19.55.199", "dest_port": 3839, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:00:05.680543+0100", "src_ip": "167.94.146.44", "dest_ip": "134.19.55.199", "src_port": 62868, "dest_port": 3839}}'); INSERT INTO alerts VALUES(1547,1773046808.090229034,'{"timestamp": "2026-03-09T10:00:08.090229+0100", "flow_id": 106056514396857, "event_type": "alert", "src_ip": "114.97.190.36", "src_port": 27003, "dest_ip": "134.19.55.199", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:00:08.090229+0100", "src_ip": "114.97.190.36", "dest_ip": "134.19.55.199", "src_port": 27003, "dest_port": 1521}}'); INSERT INTO alerts VALUES(1548,1773046861.123709918,'{"timestamp": "2026-03-09T10:01:01.123710+0100", "flow_id": 1657234186960502, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 48360, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47033, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:01:01.123710+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 48360, "dest_port": 53}}'); INSERT INTO alerts VALUES(1549,1773046861.123709918,'{"timestamp": "2026-03-09T10:01:01.123710+0100", "flow_id": 1657231205573147, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42903, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24259, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:01:01.123710+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42903, "dest_port": 53}}'); INSERT INTO alerts VALUES(1550,1773046912.230146884,'{"timestamp": "2026-03-09T10:01:52.230147+0100", "flow_id": 144052111252447, "event_type": "alert", "src_ip": "66.132.153.147", "src_port": 34787, "dest_ip": "134.19.55.199", "dest_port": 1200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:01:52.230147+0100", "src_ip": "66.132.153.147", "dest_ip": "134.19.55.199", "src_port": 34787, "dest_port": 1200}}'); INSERT INTO alerts VALUES(1551,1773046949.654612064,'{"timestamp": "2026-03-09T10:02:29.654612+0100", "flow_id": 1685641036376739, "event_type": "alert", "src_ip": "185.242.226.68", "src_port": 38870, "dest_ip": "134.19.55.199", "dest_port": 7680, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-09T10:02:29.654612+0100", "src_ip": "185.242.226.68", "dest_ip": "134.19.55.199", "src_port": 38870, "dest_port": 7680}}'); INSERT INTO alerts VALUES(1552,1773046966.507800102,'{"timestamp": "2026-03-09T10:02:46.507800+0100", "flow_id": 1899511188251082, "event_type": "alert", "src_ip": "64.62.197.49", "src_port": 14504, "dest_ip": "134.19.55.199", "dest_port": 1434, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-09T10:02:46.507800+0100", "src_ip": "64.62.197.49", "dest_ip": "134.19.55.199", "src_port": 14504, "dest_port": 1434}}'); INSERT INTO alerts VALUES(1553,1773046982.918324948,'{"timestamp": "2026-03-09T10:03:02.918325+0100", "flow_id": 1692377304716007, "event_type": "alert", "src_ip": "167.94.146.33", "src_port": 56325, "dest_ip": "134.19.55.199", "dest_port": 63931, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:03:02.918325+0100", "src_ip": "167.94.146.33", "dest_ip": "134.19.55.199", "src_port": 56325, "dest_port": 63931}}'); INSERT INTO alerts VALUES(1554,1773046986.338845014,'{"timestamp": "2026-03-09T10:03:06.338845+0100", "flow_id": 610904917719197, "event_type": "alert", "src_ip": "178.20.210.152", "src_port": 59444, "dest_ip": "134.19.55.199", "dest_port": 2002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:03:06.338845+0100", "src_ip": "178.20.210.152", "dest_ip": "134.19.55.199", "src_port": 59444, "dest_port": 2002}}'); INSERT INTO alerts VALUES(1555,1773046987.318094968,'{"timestamp": "2026-03-09T10:03:07.318095+0100", "flow_id": 1084735254663166, "event_type": "alert", "src_ip": "185.169.4.141", "src_port": 59519, "dest_ip": "134.19.55.199", "dest_port": 8728, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:03:07.318095+0100", "src_ip": "185.169.4.141", "dest_ip": "134.19.55.199", "src_port": 59519, "dest_port": 8728}}'); INSERT INTO alerts VALUES(1556,1773047002.209131003,'{"timestamp": "2026-03-09T10:03:22.209131+0100", "flow_id": 616736688605070, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50530, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42046, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:03:22.209131+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50530, "dest_port": 53}}'); INSERT INTO alerts VALUES(1557,1773047002.209131003,'{"timestamp": "2026-03-09T10:03:22.209131+0100", "flow_id": 616739875274228, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46888, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17647, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:03:22.209131+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46888, "dest_port": 53}}'); INSERT INTO alerts VALUES(1558,1773047002.589485883,'{"timestamp": "2026-03-09T10:03:22.589486+0100", "flow_id": 842973726713736, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 53796, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4939, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T10:03:22.589486+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 53796, "dest_port": 53}}'); INSERT INTO alerts VALUES(1559,1773047002.589485883,'{"timestamp": "2026-03-09T10:03:22.589486+0100", "flow_id": 842976306574368, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 55734, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1272, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T10:03:22.589486+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 55734, "dest_port": 53}}'); INSERT INTO alerts VALUES(1560,1773047002.589487076,'{"timestamp": "2026-03-09T10:03:22.589487+0100", "flow_id": 842981694580905, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 32906, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 723, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T10:03:22.589487+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 32906, "dest_port": 53}}'); INSERT INTO alerts VALUES(1561,1773047009.542861938,'{"timestamp": "2026-03-09T10:03:29.542862+0100", "flow_id": 361252440503106, "event_type": "alert", "src_ip": "65.49.1.125", "src_port": 52276, "dest_ip": "134.19.55.199", "dest_port": 6516, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:03:29.542862+0100", "src_ip": "65.49.1.125", "dest_ip": "134.19.55.199", "src_port": 52276, "dest_port": 6516}}'); INSERT INTO alerts VALUES(1562,1773047024.931941986,'{"timestamp": "2026-03-09T10:03:44.931942+0100", "flow_id": 62014656768523, "event_type": "alert", "src_ip": "64.62.156.72", "src_port": 58356, "dest_ip": "134.19.55.199", "dest_port": 177, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 35, "bytes_toclient": 0, "start": "2026-03-09T10:03:44.931942+0100", "src_ip": "64.62.156.72", "dest_ip": "134.19.55.199", "src_port": 58356, "dest_port": 177}}'); INSERT INTO alerts VALUES(1563,1773047035.501630067,'{"timestamp": "2026-03-09T10:03:55.501630+0100", "flow_id": 1028586674633307, "event_type": "alert", "src_ip": "91.196.152.33", "src_port": 40084, "dest_ip": "134.19.55.199", "dest_port": 20034, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:03:55.501630+0100", "src_ip": "91.196.152.33", "dest_ip": "134.19.55.199", "src_port": 40084, "dest_port": 20034}}'); INSERT INTO alerts VALUES(1564,1773047087.427738904,'{"timestamp": "2026-03-09T10:04:47.427739+0100", "flow_id": 2118603191610006, "event_type": "alert", "src_ip": "167.94.138.155", "src_port": 40726, "dest_ip": "134.19.55.199", "dest_port": 445, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:04:47.427739+0100", "src_ip": "167.94.138.155", "dest_ip": "134.19.55.199", "src_port": 40726, "dest_port": 445}}'); INSERT INTO alerts VALUES(1565,1773047140.502829074,'{"timestamp": "2026-03-09T10:05:40.502829+0100", "flow_id": 1315212526022383, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 58842, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T10:05:40.502829+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 58842, "dest_port": 8545}}'); INSERT INTO alerts VALUES(1566,1773047140.502829074,'{"timestamp": "2026-03-09T10:05:40.502829+0100", "flow_id": 1315212526022383, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 58842, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T10:05:40.502829+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 58842, "dest_port": 8545}}'); INSERT INTO alerts VALUES(1567,1773047142.295564889,'{"timestamp": "2026-03-09T10:05:42.295565+0100", "flow_id": 1832392093059961, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 35596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61296, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:05:42.295565+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 35596, "dest_port": 53}}'); INSERT INTO alerts VALUES(1568,1773047142.295564889,'{"timestamp": "2026-03-09T10:05:42.295565+0100", "flow_id": 1832392664208110, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59881, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43721, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:05:42.295565+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59881, "dest_port": 53}}'); INSERT INTO alerts VALUES(1569,1773047215.702157021,'{"timestamp": "2026-03-09T10:06:55.702157+0100", "flow_id": 2171319436865402, "event_type": "alert", "src_ip": "65.49.1.74", "src_port": 60307, "dest_ip": "134.19.55.199", "dest_port": 10514, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:06:55.702157+0100", "src_ip": "65.49.1.74", "dest_ip": "134.19.55.199", "src_port": 60307, "dest_port": 10514}}'); INSERT INTO alerts VALUES(1570,1773047282.349611043,'{"timestamp": "2026-03-09T10:08:02.349611+0100", "flow_id": 657145314344851, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36371, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21391, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:08:02.349611+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36371, "dest_port": 53}}'); INSERT INTO alerts VALUES(1571,1773047282.349611998,'{"timestamp": "2026-03-09T10:08:02.349612+0100", "flow_id": 657148987551787, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 55504, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21339, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:08:02.349612+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 55504, "dest_port": 53}}'); INSERT INTO alerts VALUES(1572,1773047301.621393919,'{"timestamp": "2026-03-09T10:08:21.621394+0100", "flow_id": 1542970075144295, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 14501, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:08:21.621394+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 14501}}'); INSERT INTO alerts VALUES(1573,1773047391.645703078,'{"timestamp": "2026-03-09T10:09:51.645703+0100", "flow_id": 2210323889851720, "event_type": "alert", "src_ip": "64.62.197.148", "src_port": 50048, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:09:51.645703+0100", "src_ip": "64.62.197.148", "dest_ip": "134.19.55.199", "src_port": 50048, "dest_port": 23}}'); INSERT INTO alerts VALUES(1574,1773047422.406616926,'{"timestamp": "2026-03-09T10:10:22.406617+0100", "flow_id": 1746406879491717, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 35099, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59416, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:10:22.406617+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 35099, "dest_port": 53}}'); INSERT INTO alerts VALUES(1575,1773047422.406616926,'{"timestamp": "2026-03-09T10:10:22.406617+0100", "flow_id": 1746410581620465, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44041, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34001, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:10:22.406617+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44041, "dest_port": 53}}'); INSERT INTO alerts VALUES(1576,1773047544.304524898,'{"timestamp": "2026-03-09T10:12:24.304525+0100", "flow_id": 182026492685884, "event_type": "alert", "src_ip": "167.94.146.38", "src_port": 19524, "dest_ip": "134.19.55.199", "dest_port": 20778, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:12:24.304525+0100", "src_ip": "167.94.146.38", "dest_ip": "134.19.55.199", "src_port": 19524, "dest_port": 20778}}'); INSERT INTO alerts VALUES(1577,1773047562.485439062,'{"timestamp": "2026-03-09T10:12:42.485439+0100", "flow_id": 677571091029666, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59846, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35768, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:12:42.485439+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59846, "dest_port": 53}}'); INSERT INTO alerts VALUES(1578,1773047562.485439062,'{"timestamp": "2026-03-09T10:12:42.485439+0100", "flow_id": 677573391865421, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 37886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12440, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:12:42.485439+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 37886, "dest_port": 53}}'); INSERT INTO alerts VALUES(1579,1773047565.553478002,'{"timestamp": "2026-03-09T10:12:45.553478+0100", "flow_id": 1532745185871947, "event_type": "alert", "src_ip": "195.184.76.211", "src_port": 6644, "dest_ip": "134.19.55.199", "dest_port": 6064, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:12:45.553478+0100", "src_ip": "195.184.76.211", "dest_ip": "134.19.55.199", "src_port": 6644, "dest_port": 6064}}'); INSERT INTO alerts VALUES(1580,1773047603.718723059,'{"timestamp": "2026-03-09T10:13:23.718723+0100", "flow_id": 1116570104201019, "event_type": "alert", "src_ip": "64.95.96.69", "src_port": 5176, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-09T10:13:23.718723+0100", "src_ip": "64.95.96.69", "dest_ip": "134.19.55.199", "src_port": 5176, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1581,1773047603.718723059,'{"timestamp": "2026-03-09T10:13:23.718723+0100", "flow_id": 1116570104201019, "event_type": "alert", "src_ip": "64.95.96.69", "src_port": 5176, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-09T10:13:23.718723+0100", "src_ip": "64.95.96.69", "dest_ip": "134.19.55.199", "src_port": 5176, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1582,1773047638.463833093,'{"timestamp": "2026-03-09T10:13:58.463833+0100", "flow_id": 1710673437751297, "event_type": "alert", "src_ip": "64.95.96.68", "src_port": 5104, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-09T10:13:58.463833+0100", "src_ip": "64.95.96.68", "dest_ip": "134.19.55.199", "src_port": 5104, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1583,1773047638.463833093,'{"timestamp": "2026-03-09T10:13:58.463833+0100", "flow_id": 1710673437751297, "event_type": "alert", "src_ip": "64.95.96.68", "src_port": 5104, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-09T10:13:58.463833+0100", "src_ip": "64.95.96.68", "dest_ip": "134.19.55.199", "src_port": 5104, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1584,1773047702.5506289,'{"timestamp": "2026-03-09T10:15:02.550629+0100", "flow_id": 1801986272633660, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43539, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13803, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:15:02.550629+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43539, "dest_port": 53}}'); INSERT INTO alerts VALUES(1585,1773047702.5506289,'{"timestamp": "2026-03-09T10:15:02.550629+0100", "flow_id": 1801986168026698, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34361, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59458, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:15:02.550629+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34361, "dest_port": 53}}'); INSERT INTO alerts VALUES(1586,1773047704.848366023,'{"timestamp": "2026-03-09T10:15:04.848366+0100", "flow_id": 266008794336928, "event_type": "alert", "src_ip": "195.184.76.165", "src_port": 29714, "dest_ip": "134.19.55.199", "dest_port": 5677, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:15:04.848366+0100", "src_ip": "195.184.76.165", "dest_ip": "134.19.55.199", "src_port": 29714, "dest_port": 5677}}'); INSERT INTO alerts VALUES(1587,1773047780.702799082,'{"timestamp": "2026-03-09T10:16:20.702799+0100", "flow_id": 1329651587248642, "event_type": "alert", "src_ip": "65.49.1.10", "src_port": 44281, "dest_ip": "134.19.55.199", "dest_port": 4848, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:16:20.702799+0100", "src_ip": "65.49.1.10", "dest_ip": "134.19.55.199", "src_port": 44281, "dest_port": 4848}}'); INSERT INTO alerts VALUES(1588,1773047805.810791015,'{"timestamp": "2026-03-09T10:16:45.810791+0100", "flow_id": 1511998753740504, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 31875, "dest_ip": "134.19.55.199", "dest_port": 16260, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:16:45.810791+0100", "src_ip": "167.94.146.45", "dest_ip": "134.19.55.199", "src_port": 31875, "dest_port": 16260}}'); INSERT INTO alerts VALUES(1589,1773047834.741775036,'{"timestamp": "2026-03-09T10:17:14.741775+0100", "flow_id": 652627829795605, "event_type": "alert", "src_ip": "45.142.154.98", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 5000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:17:14.741775+0100", "src_ip": "45.142.154.98", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 5000}}'); INSERT INTO alerts VALUES(1590,1773047842.610960007,'{"timestamp": "2026-03-09T10:17:22.610960+0100", "flow_id": 653731508405872, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29754, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:17:22.610960+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51886, "dest_port": 53}}'); INSERT INTO alerts VALUES(1591,1773047842.613070012,'{"timestamp": "2026-03-09T10:17:22.613070+0100", "flow_id": 662793351960910, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 58818, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12221, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:17:22.613070+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 58818, "dest_port": 53}}'); INSERT INTO alerts VALUES(1592,1773047904.171711922,'{"timestamp": "2026-03-09T10:18:24.171712+0100", "flow_id": 174549746452517, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 47888, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:18:24.171712+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 47888, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1593,1773047904.171711922,'{"timestamp": "2026-03-09T10:18:24.171712+0100", "flow_id": 174549746452517, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 47888, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:18:24.171712+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 47888, "dest_port": 3306}}'); INSERT INTO alerts VALUES(1594,1773047907.802858115,'{"timestamp": "2026-03-09T10:18:27.802858+0100", "flow_id": 914976804462757, "event_type": "alert", "src_ip": "193.163.125.209", "src_port": 59788, "dest_ip": "134.19.55.199", "dest_port": 41879, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:18:27.802858+0100", "src_ip": "193.163.125.209", "dest_ip": "134.19.55.199", "src_port": 59788, "dest_port": 41879}}'); INSERT INTO alerts VALUES(1595,1773047982.745403052,'{"timestamp": "2026-03-09T10:19:42.745403+0100", "flow_id": 1794108888366162, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39517, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17755, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:19:42.745403+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39517, "dest_port": 53}}'); INSERT INTO alerts VALUES(1596,1773047982.745404005,'{"timestamp": "2026-03-09T10:19:42.745404+0100", "flow_id": 1794111344674444, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46411, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60093, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:19:42.745404+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46411, "dest_port": 53}}'); INSERT INTO alerts VALUES(1597,1773048042.806736946,'{"timestamp": "2026-03-09T10:20:42.806737+0100", "flow_id": 650160231131952, "event_type": "alert", "src_ip": "91.196.152.68", "src_port": 23713, "dest_ip": "134.19.55.199", "dest_port": 2154, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:20:42.806737+0100", "src_ip": "91.196.152.68", "dest_ip": "134.19.55.199", "src_port": 23713, "dest_port": 2154}}'); INSERT INTO alerts VALUES(1598,1773048083.725227117,'{"timestamp": "2026-03-09T10:21:23.725227+0100", "flow_id": 863029953551941, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 2259, "dest_ip": "134.19.55.199", "dest_port": 59884, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:21:23.725227+0100", "src_ip": "167.94.146.37", "dest_ip": "134.19.55.199", "src_port": 2259, "dest_port": 59884}}'); INSERT INTO alerts VALUES(1599,1773048112.784018993,'{"timestamp": "2026-03-09T10:21:52.784019+0100", "flow_id": 271111340276730, "event_type": "alert", "src_ip": "195.184.76.183", "src_port": 14431, "dest_ip": "134.19.55.199", "dest_port": 5162, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:21:52.784019+0100", "src_ip": "195.184.76.183", "dest_ip": "134.19.55.199", "src_port": 14431, "dest_port": 5162}}'); INSERT INTO alerts VALUES(1600,1773048122.920559883,'{"timestamp": "2026-03-09T10:22:02.920560+0100", "flow_id": 576079413367699, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59459, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41995, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:22:02.920560+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59459, "dest_port": 53}}'); INSERT INTO alerts VALUES(1601,1773048122.920559883,'{"timestamp": "2026-03-09T10:22:02.920560+0100", "flow_id": 576078739234521, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51283, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55090, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:22:02.920560+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51283, "dest_port": 53}}'); INSERT INTO alerts VALUES(1602,1773048141.561636924,'{"timestamp": "2026-03-09T10:22:21.561637+0100", "flow_id": 1567789539042064, "event_type": "alert", "src_ip": "45.156.87.24", "src_port": 44058, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:22:21.561637+0100", "src_ip": "45.156.87.24", "dest_ip": "134.19.55.199", "src_port": 44058, "dest_port": 5555}}'); INSERT INTO alerts VALUES(1603,1773048151.481229066,'{"timestamp": "2026-03-09T10:22:31.481229+0100", "flow_id": 2066863264880914, "event_type": "alert", "src_ip": "178.20.210.151", "src_port": 41269, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:22:31.481229+0100", "src_ip": "178.20.210.151", "dest_ip": "134.19.55.199", "src_port": 41269, "dest_port": 22}}'); INSERT INTO alerts VALUES(1604,1773048178.880294085,'{"timestamp": "2026-03-09T10:22:58.880294+0100", "flow_id": 684613367106058, "event_type": "alert", "src_ip": "87.121.84.85", "src_port": 35718, "dest_ip": "134.19.55.199", "dest_port": 2011, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:22:58.880294+0100", "src_ip": "87.121.84.85", "dest_ip": "134.19.55.199", "src_port": 35718, "dest_port": 2011}}'); INSERT INTO alerts VALUES(1605,1773048185.048448085,'{"timestamp": "2026-03-09T10:23:05.048448+0100", "flow_id": 489560912562704, "event_type": "alert", "src_ip": "167.94.146.39", "src_port": 57185, "dest_ip": "134.19.55.199", "dest_port": 46409, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:23:05.048448+0100", "src_ip": "167.94.146.39", "dest_ip": "134.19.55.199", "src_port": 57185, "dest_port": 46409}}'); INSERT INTO alerts VALUES(1606,1773048194.15605688,'{"timestamp": "2026-03-09T10:23:14.156057+0100", "flow_id": 670260878297622, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 35319, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 417, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T10:23:14.156057+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 35319, "dest_port": 53}}'); INSERT INTO alerts VALUES(1607,1773048194.15605688,'{"timestamp": "2026-03-09T10:23:14.156057+0100", "flow_id": 670260883433076, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49623, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T10:23:14.156057+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49623, "dest_port": 53}}'); INSERT INTO alerts VALUES(1608,1773048194.156058074,'{"timestamp": "2026-03-09T10:23:14.156058+0100", "flow_id": 670265309320155, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41373, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40153, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T10:23:14.156058+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41373, "dest_port": 53}}'); INSERT INTO alerts VALUES(1609,1773048194.423549891,'{"timestamp": "2026-03-09T10:23:14.423550+0100", "flow_id": 693237743421538, "event_type": "alert", "src_ip": "45.156.87.252", "src_port": 48118, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:23:14.423550+0100", "src_ip": "45.156.87.252", "dest_ip": "134.19.55.199", "src_port": 48118, "dest_port": 27017}}'); INSERT INTO alerts VALUES(1610,1773048243.882499933,'{"timestamp": "2026-03-09T10:24:03.882500+0100", "flow_id": 975562465043374, "event_type": "alert", "src_ip": "193.163.125.189", "src_port": 36442, "dest_ip": "134.19.55.199", "dest_port": 8027, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:24:03.882500+0100", "src_ip": "193.163.125.189", "dest_ip": "134.19.55.199", "src_port": 36442, "dest_port": 8027}}'); INSERT INTO alerts VALUES(1611,1773048263.199301958,'{"timestamp": "2026-03-09T10:24:23.199302+0100", "flow_id": 1981899629481140, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 35113, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10947, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:24:23.199302+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 35113, "dest_port": 53}}'); INSERT INTO alerts VALUES(1612,1773048263.20006299,'{"timestamp": "2026-03-09T10:24:23.200063+0100", "flow_id": 1985165753098459, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 37972, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9502, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:24:23.200063+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 37972, "dest_port": 53}}'); INSERT INTO alerts VALUES(1613,1773048303.086572885,'{"timestamp": "2026-03-09T10:25:03.086573+0100", "flow_id": 2060681699177639, "event_type": "alert", "src_ip": "193.163.125.190", "src_port": 58054, "dest_ip": "134.19.55.199", "dest_port": 10090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:25:03.086573+0100", "src_ip": "193.163.125.190", "dest_ip": "134.19.55.199", "src_port": 58054, "dest_port": 10090}}'); INSERT INTO alerts VALUES(1614,1773048323.492800952,'{"timestamp": "2026-03-09T10:25:23.492801+0100", "flow_id": 990666156312302, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 38841, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50029, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T10:25:23.492801+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 38841, "dest_port": 53}}'); INSERT INTO alerts VALUES(1615,1773048323.492800952,'{"timestamp": "2026-03-09T10:25:23.492801+0100", "flow_id": 990668412442209, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 48006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17100, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T10:25:23.492801+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 48006, "dest_port": 53}}'); INSERT INTO alerts VALUES(1616,1773048323.492801904,'{"timestamp": "2026-03-09T10:25:23.492802+0100", "flow_id": 990670543584928, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36913, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31469, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T10:25:23.492802+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36913, "dest_port": 53}}'); INSERT INTO alerts VALUES(1617,1773048330.82582593,'{"timestamp": "2026-03-09T10:25:30.825826+0100", "flow_id": 732146412758337, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 51177, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:25:30.825826+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 51177}}'); INSERT INTO alerts VALUES(1618,1773048330.82582593,'{"timestamp": "2026-03-09T10:25:30.825826+0100", "flow_id": 732146412758337, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 51177, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:25:30.825826+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 51177}}'); INSERT INTO alerts VALUES(1619,1773048403.350053072,'{"timestamp": "2026-03-09T10:26:43.350053+0100", "flow_id": 940516800713628, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41981, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14395, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:26:43.350053+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41981, "dest_port": 53}}'); INSERT INTO alerts VALUES(1620,1773048403.35033393,'{"timestamp": "2026-03-09T10:26:43.350334+0100", "flow_id": 941723961243749, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51108, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56686, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:26:43.350334+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51108, "dest_port": 53}}'); INSERT INTO alerts VALUES(1621,1773048510.888875962,'{"timestamp": "2026-03-09T10:28:30.888876+0100", "flow_id": 1847369966261158, "event_type": "alert", "src_ip": "144.31.11.68", "src_port": 55246, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2500008, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 5", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:28:30.888876+0100", "src_ip": "144.31.11.68", "dest_ip": "134.19.55.199", "src_port": 55246, "dest_port": 22}}'); INSERT INTO alerts VALUES(1622,1773048543.419111967,'{"timestamp": "2026-03-09T10:29:03.419112+0100", "flow_id": 2081550281640749, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50760, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33290, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:29:03.419112+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50760, "dest_port": 53}}'); INSERT INTO alerts VALUES(1623,1773048543.419112921,'{"timestamp": "2026-03-09T10:29:03.419113+0100", "flow_id": 2081552230090621, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50376, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55003, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:29:03.419113+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50376, "dest_port": 53}}'); INSERT INTO alerts VALUES(1624,1773048604.241071939,'{"timestamp": "2026-03-09T10:30:04.241072+0100", "flow_id": 1316873904133958, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 46000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:30:04.241072+0100", "src_ip": "88.210.63.69", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 46000}}'); INSERT INTO alerts VALUES(1625,1773048652.644376994,'{"timestamp": "2026-03-09T10:30:52.644377+0100", "flow_id": 1360207345401573, "event_type": "alert", "src_ip": "195.184.76.67", "src_port": 28443, "dest_ip": "134.19.55.199", "dest_port": 6076, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:30:52.644377+0100", "src_ip": "195.184.76.67", "dest_ip": "134.19.55.199", "src_port": 28443, "dest_port": 6076}}'); INSERT INTO alerts VALUES(1626,1773048683.446623086,'{"timestamp": "2026-03-09T10:31:23.446623+0100", "flow_id": 1073810455530087, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 38299, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6375, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:31:23.446623+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 38299, "dest_port": 53}}'); INSERT INTO alerts VALUES(1627,1773048683.44662404,'{"timestamp": "2026-03-09T10:31:23.446624+0100", "flow_id": 1073812115743047, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43783, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53724, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:31:23.446624+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43783, "dest_port": 53}}'); INSERT INTO alerts VALUES(1628,1773048772.454554081,'{"timestamp": "2026-03-09T10:32:52.454554+0100", "flow_id": 1389347784142814, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 8935, "dest_ip": "134.19.55.199", "dest_port": 60529, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:32:52.454554+0100", "src_ip": "167.94.146.32", "dest_ip": "134.19.55.199", "src_port": 8935, "dest_port": 60529}}'); INSERT INTO alerts VALUES(1629,1773048823.482712031,'{"timestamp": "2026-03-09T10:33:43.482712+0100", "flow_id": 2073233316318919, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 52616, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64812, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:33:43.482712+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 52616, "dest_port": 53}}'); INSERT INTO alerts VALUES(1630,1773048823.482712985,'{"timestamp": "2026-03-09T10:33:43.482713+0100", "flow_id": 2073237325562647, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36262, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55530, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:33:43.482713+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36262, "dest_port": 53}}'); INSERT INTO alerts VALUES(1631,1773048843.422605038,'{"timestamp": "2026-03-09T10:34:03.422605+0100", "flow_id": 970649940649178, "event_type": "alert", "src_ip": "91.196.152.219", "src_port": 8838, "dest_ip": "134.19.55.199", "dest_port": 20061, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:34:03.422605+0100", "src_ip": "91.196.152.219", "dest_ip": "134.19.55.199", "src_port": 8838, "dest_port": 20061}}'); INSERT INTO alerts VALUES(1632,1773048963.702445031,'{"timestamp": "2026-03-09T10:36:03.702445+0100", "flow_id": 1046655333149620, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44936, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2527, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:36:03.702445+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44936, "dest_port": 53}}'); INSERT INTO alerts VALUES(1633,1773048963.702445031,'{"timestamp": "2026-03-09T10:36:03.702445+0100", "flow_id": 1046655722623960, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41112, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2344, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:36:03.702445+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41112, "dest_port": 53}}'); INSERT INTO alerts VALUES(1634,1773048975.382505894,'{"timestamp": "2026-03-09T10:36:15.382506+0100", "flow_id": 2205804590316557, "event_type": "alert", "src_ip": "91.196.152.177", "src_port": 40145, "dest_ip": "134.19.55.199", "dest_port": 2016, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:36:15.382506+0100", "src_ip": "91.196.152.177", "dest_ip": "134.19.55.199", "src_port": 40145, "dest_port": 2016}}'); INSERT INTO alerts VALUES(1635,1773048995.655729056,'{"timestamp": "2026-03-09T10:36:35.655729+0100", "flow_id": 846012830103781, "event_type": "alert", "src_ip": "193.163.125.186", "src_port": 51194, "dest_ip": "134.19.55.199", "dest_port": 59869, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:36:35.655729+0100", "src_ip": "193.163.125.186", "dest_ip": "134.19.55.199", "src_port": 51194, "dest_port": 59869}}'); INSERT INTO alerts VALUES(1636,1773049011.685574055,'{"timestamp": "2026-03-09T10:36:51.685574+0100", "flow_id": 974193248230602, "event_type": "alert", "src_ip": "176.65.139.12", "src_port": 48882, "dest_ip": "134.19.55.199", "dest_port": 17000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:36:51.685574+0100", "src_ip": "176.65.139.12", "dest_ip": "134.19.55.199", "src_port": 48882, "dest_port": 17000}}'); INSERT INTO alerts VALUES(1637,1773049013.013097047,'{"timestamp": "2026-03-09T10:36:53.013097+0100", "flow_id": 1463628450380086, "event_type": "alert", "src_ip": "87.121.84.50", "src_port": 38801, "dest_ip": "134.19.55.199", "dest_port": 2082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:36:53.013097+0100", "src_ip": "87.121.84.50", "dest_ip": "134.19.55.199", "src_port": 38801, "dest_port": 2082}}'); INSERT INTO alerts VALUES(1638,1773049103.760550023,'{"timestamp": "2026-03-09T10:38:23.760550+0100", "flow_id": 2140639540878489, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46565, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36560, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:38:23.760550+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46565, "dest_port": 53}}'); INSERT INTO alerts VALUES(1639,1773049103.760550975,'{"timestamp": "2026-03-09T10:38:23.760551+0100", "flow_id": 2140641781239002, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43992, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38032, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:38:23.760551+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43992, "dest_port": 53}}'); INSERT INTO alerts VALUES(1640,1773049108.926924944,'{"timestamp": "2026-03-09T10:38:28.926925+0100", "flow_id": 1166365402369405, "event_type": "alert", "src_ip": "167.94.146.36", "src_port": 18151, "dest_ip": "134.19.55.199", "dest_port": 25780, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:38:28.926925+0100", "src_ip": "167.94.146.36", "dest_ip": "134.19.55.199", "src_port": 18151, "dest_port": 25780}}'); INSERT INTO alerts VALUES(1641,1773049117.978161097,'{"timestamp": "2026-03-09T10:38:37.978161+0100", "flow_id": 1667898946550220, "event_type": "alert", "src_ip": "193.163.125.206", "src_port": 47685, "dest_ip": "134.19.55.199", "dest_port": 2525, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:38:37.978161+0100", "src_ip": "193.163.125.206", "dest_ip": "134.19.55.199", "src_port": 47685, "dest_port": 2525}}'); INSERT INTO alerts VALUES(1642,1773049243.849636078,'{"timestamp": "2026-03-09T10:40:43.849636+0100", "flow_id": 1115886696536436, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43765, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38941, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:40:43.849636+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43765, "dest_port": 53}}'); INSERT INTO alerts VALUES(1643,1773049243.853250981,'{"timestamp": "2026-03-09T10:40:43.853251+0100", "flow_id": 849937338759255, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50059, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23093, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:40:43.853251+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50059, "dest_port": 53}}'); INSERT INTO alerts VALUES(1644,1773049273.940920114,'{"timestamp": "2026-03-09T10:41:13.940920+0100", "flow_id": 382046806313179, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 48226, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:41:13.940920+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 48226, "dest_port": 22}}'); INSERT INTO alerts VALUES(1645,1773049273.940920114,'{"timestamp": "2026-03-09T10:41:13.940920+0100", "flow_id": 382046806313179, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 48226, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:41:13.940920+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 48226, "dest_port": 22}}'); INSERT INTO alerts VALUES(1646,1773049297.336587906,'{"timestamp": "2026-03-09T10:41:37.336588+0100", "flow_id": 319738219390658, "event_type": "alert", "src_ip": "167.94.138.107", "src_port": 26565, "dest_ip": "134.19.55.199", "dest_port": 41588, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:41:37.336588+0100", "src_ip": "167.94.138.107", "dest_ip": "134.19.55.199", "src_port": 26565, "dest_port": 41588}}'); INSERT INTO alerts VALUES(1647,1773049298.851197004,'{"timestamp": "2026-03-09T10:41:38.851197+0100", "flow_id": 841115897906181, "event_type": "alert", "src_ip": "176.65.148.29", "src_port": 55201, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T10:41:38.851197+0100", "src_ip": "176.65.148.29", "dest_ip": "134.19.55.199", "src_port": 55201, "dest_port": 8545}}'); INSERT INTO alerts VALUES(1648,1773049298.851197004,'{"timestamp": "2026-03-09T10:41:38.851197+0100", "flow_id": 841115897906181, "event_type": "alert", "src_ip": "176.65.148.29", "src_port": 55201, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T10:41:38.851197+0100", "src_ip": "176.65.148.29", "dest_ip": "134.19.55.199", "src_port": 55201, "dest_port": 8545}}'); INSERT INTO alerts VALUES(1649,1773049308.641200066,'{"timestamp": "2026-03-09T10:41:48.641200+0100", "flow_id": 1346560941820335, "event_type": "alert", "src_ip": "172.94.9.253", "src_port": 47898, "dest_ip": "134.19.55.199", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400031, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 32", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:41:48.641200+0100", "src_ip": "172.94.9.253", "dest_ip": "134.19.55.199", "src_port": 47898, "dest_port": 443}}'); INSERT INTO alerts VALUES(1650,1773049364.507836104,'{"timestamp": "2026-03-09T10:42:44.507836+0100", "flow_id": 1336715383877210, "event_type": "alert", "src_ip": "195.184.76.133", "src_port": 2625, "dest_ip": "134.19.55.199", "dest_port": 7051, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:42:44.507836+0100", "src_ip": "195.184.76.133", "dest_ip": "134.19.55.199", "src_port": 2625, "dest_port": 7051}}'); INSERT INTO alerts VALUES(1651,1773049383.913630008,'{"timestamp": "2026-03-09T10:43:03.913630+0100", "flow_id": 2235163444133100, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49458, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9552, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:43:03.913630+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49458, "dest_port": 53}}'); INSERT INTO alerts VALUES(1652,1773049383.913630008,'{"timestamp": "2026-03-09T10:43:03.913630+0100", "flow_id": 2235161961650004, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44558, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12126, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:43:03.913630+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44558, "dest_port": 53}}'); INSERT INTO alerts VALUES(1653,1773049391.282182931,'{"timestamp": "2026-03-09T10:43:11.282183+0100", "flow_id": 2056393161300897, "event_type": "alert", "src_ip": "64.62.156.12", "src_port": 9070, "dest_ip": "134.19.55.199", "dest_port": 5351, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 30, "bytes_toclient": 0, "start": "2026-03-09T10:43:11.282183+0100", "src_ip": "64.62.156.12", "dest_ip": "134.19.55.199", "src_port": 9070, "dest_port": 5351}}'); INSERT INTO alerts VALUES(1654,1773049523.973975896,'{"timestamp": "2026-03-09T10:45:23.973976+0100", "flow_id": 1086972334408536, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43329, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23297, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:45:23.973976+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43329, "dest_port": 53}}'); INSERT INTO alerts VALUES(1655,1773049523.973977088,'{"timestamp": "2026-03-09T10:45:23.973977+0100", "flow_id": 1086978597294723, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39978, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21939, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:45:23.973977+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39978, "dest_port": 53}}'); INSERT INTO alerts VALUES(1656,1773049535.373044013,'{"timestamp": "2026-03-09T10:45:35.373044+0100", "flow_id": 2165162953352739, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 45427, "dest_ip": "134.19.55.199", "dest_port": 320, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:45:35.373044+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 45427, "dest_port": 320}}'); INSERT INTO alerts VALUES(1657,1773049542.825054884,'{"timestamp": "2026-03-09T10:45:42.825055+0100", "flow_id": 1854736574117271, "event_type": "alert", "src_ip": "176.65.132.93", "src_port": 49511, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:45:42.825055+0100", "src_ip": "176.65.132.93", "dest_ip": "134.19.55.199", "src_port": 49511, "dest_port": 27017}}'); INSERT INTO alerts VALUES(1658,1773049587.582078934,'{"timestamp": "2026-03-09T10:46:27.582079+0100", "flow_id": 1092635997964600, "event_type": "alert", "src_ip": "193.163.125.216", "src_port": 42968, "dest_ip": "134.19.55.199", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:46:27.582079+0100", "src_ip": "193.163.125.216", "dest_ip": "134.19.55.199", "src_port": 42968, "dest_port": 443}}'); INSERT INTO alerts VALUES(1659,1773049664.025759936,'{"timestamp": "2026-03-09T10:47:44.025760+0100", "flow_id": 110639442609020, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 47547, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47198, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:47:44.025760+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 47547, "dest_port": 53}}'); INSERT INTO alerts VALUES(1660,1773049664.026015997,'{"timestamp": "2026-03-09T10:47:44.026016+0100", "flow_id": 111741347565942, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33978, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16166, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:47:44.026016+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33978, "dest_port": 53}}'); INSERT INTO alerts VALUES(1661,1773049669.253529072,'{"timestamp": "2026-03-09T10:47:49.253529+0100", "flow_id": 1651850605082315, "event_type": "alert", "src_ip": "64.89.161.53", "src_port": 55000, "dest_ip": "134.19.55.199", "dest_port": 3737, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T10:47:49.253529+0100", "src_ip": "64.89.161.53", "dest_ip": "134.19.55.199", "src_port": 55000, "dest_port": 3737}}'); INSERT INTO alerts VALUES(1662,1773049712.792691947,'{"timestamp": "2026-03-09T10:48:32.792692+0100", "flow_id": 26889339667157, "event_type": "alert", "src_ip": "121.165.84.80", "src_port": 48151, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2500004, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 3", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:48:32.792692+0100", "src_ip": "121.165.84.80", "dest_ip": "134.19.55.199", "src_port": 48151, "dest_port": 22}}'); INSERT INTO alerts VALUES(1663,1773049753.834578037,'{"timestamp": "2026-03-09T10:49:13.834578+0100", "flow_id": 488264392990326, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 59389, "dest_ip": "134.19.55.199", "dest_port": 4040, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:49:13.834578+0100", "src_ip": "79.124.40.82", "dest_ip": "134.19.55.199", "src_port": 59389, "dest_port": 4040}}'); INSERT INTO alerts VALUES(1664,1773049804.077713012,'{"timestamp": "2026-03-09T10:50:04.077713+0100", "flow_id": 1178203872657913, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60695, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40149, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:50:04.077713+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60695, "dest_port": 53}}'); INSERT INTO alerts VALUES(1665,1773049804.077713966,'{"timestamp": "2026-03-09T10:50:04.077714+0100", "flow_id": 1178206180735089, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49119, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:50:04.077714+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49119, "dest_port": 53}}'); INSERT INTO alerts VALUES(1666,1773049819.756506919,'{"timestamp": "2026-03-09T10:50:19.756507+0100", "flow_id": 997373242615327, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 47937, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:50:19.756507+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 47937, "dest_port": 3389}}'); INSERT INTO alerts VALUES(1667,1773049944.127589941,'{"timestamp": "2026-03-09T10:52:24.127590+0100", "flow_id": 266523901732535, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 47936, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47146, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:52:24.127590+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 47936, "dest_port": 53}}'); INSERT INTO alerts VALUES(1668,1773049944.130403996,'{"timestamp": "2026-03-09T10:52:24.130404+0100", "flow_id": 278606325444202, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 56164, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9865, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:52:24.130404+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 56164, "dest_port": 53}}'); INSERT INTO alerts VALUES(1669,1773049989.773708105,'{"timestamp": "2026-03-09T10:53:09.773708+0100", "flow_id": 1634203893936485, "event_type": "alert", "src_ip": "185.156.73.180", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44363, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:53:09.773708+0100", "src_ip": "185.156.73.180", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44363}}'); INSERT INTO alerts VALUES(1670,1773050019.215183973,'{"timestamp": "2026-03-09T10:53:39.215184+0100", "flow_id": 924210303161380, "event_type": "alert", "src_ip": "195.184.76.37", "src_port": 43708, "dest_ip": "134.19.55.199", "dest_port": 61001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:53:39.215184+0100", "src_ip": "195.184.76.37", "dest_ip": "134.19.55.199", "src_port": 43708, "dest_port": 61001}}'); INSERT INTO alerts VALUES(1671,1773050084.189519882,'{"timestamp": "2026-03-09T10:54:44.189520+0100", "flow_id": 1376932317773264, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60092, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60681, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:54:44.189520+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60092, "dest_port": 53}}'); INSERT INTO alerts VALUES(1672,1773050084.189519882,'{"timestamp": "2026-03-09T10:54:44.189520+0100", "flow_id": 1376936076906900, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 55154, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42484, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:54:44.189520+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 55154, "dest_port": 53}}'); INSERT INTO alerts VALUES(1673,1773050138.783289909,'{"timestamp": "2026-03-09T10:55:38.783290+0100", "flow_id": 830932249830603, "event_type": "alert", "src_ip": "195.184.76.177", "src_port": 27022, "dest_ip": "134.19.55.199", "dest_port": 5165, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:55:38.783290+0100", "src_ip": "195.184.76.177", "dest_ip": "134.19.55.199", "src_port": 27022, "dest_port": 5165}}'); INSERT INTO alerts VALUES(1674,1773050224.305903911,'{"timestamp": "2026-03-09T10:57:04.305904+0100", "flow_id": 1851686068780612, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 2, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 2, "id": 16081, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 1, "bytes_toserver": 148, "bytes_toclient": 164, "start": "2026-03-09T10:54:46.168985+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46272, "dest_port": 53}}'); INSERT INTO alerts VALUES(1675,1773050224.305905104,'{"timestamp": "2026-03-09T10:57:04.305905+0100", "flow_id": 187952478148424, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57474, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40371, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:57:04.305905+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57474, "dest_port": 53}}'); INSERT INTO alerts VALUES(1676,1773050249.632204055,'{"timestamp": "2026-03-09T10:57:29.632204+0100", "flow_id": 463497292553962, "event_type": "alert", "src_ip": "167.94.138.145", "src_port": 28936, "dest_ip": "134.19.55.199", "dest_port": 8443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T10:57:29.632204+0100", "src_ip": "167.94.138.145", "dest_ip": "134.19.55.199", "src_port": 28936, "dest_port": 8443}}'); INSERT INTO alerts VALUES(1677,1773050253.538275004,'{"timestamp": "2026-03-09T10:57:33.538275+0100", "flow_id": 1467452060145948, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 49197, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T10:57:33.538275+0100", "src_ip": "87.121.84.57", "dest_ip": "134.19.55.199", "src_port": 49197, "dest_port": 80}}'); INSERT INTO alerts VALUES(1678,1773050364.365561009,'{"timestamp": "2026-03-09T10:59:24.365561+0100", "flow_id": 1288601819206244, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 48161, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23999, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:59:24.365561+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 48161, "dest_port": 53}}'); INSERT INTO alerts VALUES(1679,1773050364.365561009,'{"timestamp": "2026-03-09T10:59:24.365561+0100", "flow_id": 1288598435048786, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44608, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T10:59:24.365561+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44608, "dest_port": 53}}'); INSERT INTO alerts VALUES(1680,1773050389.923811912,'{"timestamp": "2026-03-09T10:59:49.923812+0100", "flow_id": 1434471791855519, "event_type": "alert", "src_ip": "176.65.139.41", "src_port": 50000, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T10:59:49.923812+0100", "src_ip": "176.65.139.41", "dest_ip": "134.19.55.199", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(1681,1773050506.663136005,'{"timestamp": "2026-03-09T11:01:46.663136+0100", "flow_id": 596349684867792, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 54396, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32148, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:01:46.663136+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 54396, "dest_port": 53}}'); INSERT INTO alerts VALUES(1682,1773050506.664115906,'{"timestamp": "2026-03-09T11:01:46.664116+0100", "flow_id": 600557899991585, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34425, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31075, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:01:46.664116+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34425, "dest_port": 53}}'); INSERT INTO alerts VALUES(1683,1773050524.545308114,'{"timestamp": "2026-03-09T11:02:04.545308+0100", "flow_id": 1216182231741632, "event_type": "alert", "src_ip": "64.62.156.199", "src_port": 43975, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:02:04.545308+0100", "src_ip": "64.62.156.199", "dest_ip": "134.19.55.199", "src_port": 43975, "dest_port": 8080}}'); INSERT INTO alerts VALUES(1684,1773050553.432238101,'{"timestamp": "2026-03-09T11:02:33.432238+0100", "flow_id": 449075290321148, "event_type": "alert", "src_ip": "64.62.156.66", "src_port": 64744, "dest_ip": "134.19.55.199", "dest_port": 19, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-09T11:02:33.432238+0100", "src_ip": "64.62.156.66", "dest_ip": "134.19.55.199", "src_port": 64744, "dest_port": 19}}'); INSERT INTO alerts VALUES(1685,1773050574.226356029,'{"timestamp": "2026-03-09T11:02:54.226356+0100", "flow_id": 1816617002303522, "event_type": "alert", "src_ip": "64.62.156.190", "src_port": 37127, "dest_ip": "134.19.55.199", "dest_port": 4840, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:02:54.226356+0100", "src_ip": "64.62.156.190", "dest_ip": "134.19.55.199", "src_port": 37127, "dest_port": 4840}}'); INSERT INTO alerts VALUES(1686,1773050589.190619945,'{"timestamp": "2026-03-09T11:03:09.190620+0100", "flow_id": 1663133442141123, "event_type": "alert", "src_ip": "195.184.76.117", "src_port": 64646, "dest_ip": "134.19.55.199", "dest_port": 5500, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:03:09.190620+0100", "src_ip": "195.184.76.117", "dest_ip": "134.19.55.199", "src_port": 64646, "dest_port": 5500}}'); INSERT INTO alerts VALUES(1687,1773050591.364845038,'{"timestamp": "2026-03-09T11:03:11.364845+0100", "flow_id": 2129951124423714, "event_type": "alert", "src_ip": "43.228.157.18", "src_port": 45143, "dest_ip": "134.19.55.199", "dest_port": 61616, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:03:11.364845+0100", "src_ip": "43.228.157.18", "dest_ip": "134.19.55.199", "src_port": 45143, "dest_port": 61616}}'); INSERT INTO alerts VALUES(1688,1773050599.305510997,'{"timestamp": "2026-03-09T11:03:19.305511+0100", "flow_id": 2156584941480165, "event_type": "alert", "src_ip": "66.132.153.153", "src_port": 1406, "dest_ip": "134.19.55.199", "dest_port": 427, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:03:19.305511+0100", "src_ip": "66.132.153.153", "dest_ip": "134.19.55.199", "src_port": 1406, "dest_port": 427}}'); INSERT INTO alerts VALUES(1689,1773050646.724963903,'{"timestamp": "2026-03-09T11:04:06.724964+0100", "flow_id": 1706322026695415, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44002, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43458, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:04:06.724964+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44002, "dest_port": 53}}'); INSERT INTO alerts VALUES(1690,1773050646.724963903,'{"timestamp": "2026-03-09T11:04:06.724964+0100", "flow_id": 1706323245219066, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44356, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9511, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:04:06.724964+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44356, "dest_port": 53}}'); INSERT INTO alerts VALUES(1691,1773050678.920459986,'{"timestamp": "2026-03-09T11:04:38.920460+0100", "flow_id": 1701549733861503, "event_type": "alert", "src_ip": "91.224.92.177", "src_port": 34714, "dest_ip": "134.19.55.199", "dest_port": 3001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:04:38.920460+0100", "src_ip": "91.224.92.177", "dest_ip": "134.19.55.199", "src_port": 34714, "dest_port": 3001}}'); INSERT INTO alerts VALUES(1692,1773050716.898384095,'{"timestamp": "2026-03-09T11:05:16.898384+0100", "flow_id": 1325256865139169, "event_type": "alert", "src_ip": "64.62.156.90", "src_port": 43378, "dest_ip": "134.19.55.199", "dest_port": 10443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:05:16.898384+0100", "src_ip": "64.62.156.90", "dest_ip": "134.19.55.199", "src_port": 43378, "dest_port": 10443}}'); INSERT INTO alerts VALUES(1693,1773050761.726828098,'{"timestamp": "2026-03-09T11:06:01.726828+0100", "flow_id": 306955836540592, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 38213, "dest_ip": "134.19.55.199", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:06:01.726828+0100", "src_ip": "193.142.146.230", "dest_ip": "134.19.55.199", "src_port": 38213, "dest_port": 8888}}'); INSERT INTO alerts VALUES(1694,1773050786.793303013,'{"timestamp": "2026-03-09T11:06:26.793303+0100", "flow_id": 592463289586676, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 35638, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3065, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:06:26.793303+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 35638, "dest_port": 53}}'); INSERT INTO alerts VALUES(1695,1773050786.793303013,'{"timestamp": "2026-03-09T11:06:26.793303+0100", "flow_id": 592460773474530, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36062, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61727, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:06:26.793303+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36062, "dest_port": 53}}'); INSERT INTO alerts VALUES(1696,1773050802.283921957,'{"timestamp": "2026-03-09T11:06:42.283922+0100", "flow_id": 656487950278660, "event_type": "alert", "src_ip": "167.94.138.143", "src_port": 49401, "dest_ip": "134.19.55.199", "dest_port": 18082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:06:42.283922+0100", "src_ip": "167.94.138.143", "dest_ip": "134.19.55.199", "src_port": 49401, "dest_port": 18082}}'); INSERT INTO alerts VALUES(1697,1773050832.211601972,'{"timestamp": "2026-03-09T11:07:12.211602+0100", "flow_id": 64401138663431, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 57202, "dest_ip": "134.19.55.199", "dest_port": 3443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:07:12.211602+0100", "src_ip": "45.142.193.7", "dest_ip": "134.19.55.199", "src_port": 57202, "dest_port": 3443}}'); INSERT INTO alerts VALUES(1698,1773050877.442115069,'{"timestamp": "2026-03-09T11:07:57.442115+0100", "flow_id": 1617396881488023, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 47188, "dest_ip": "134.19.55.199", "dest_port": 53559, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:07:57.442115+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 47188, "dest_port": 53559}}'); INSERT INTO alerts VALUES(1699,1773050925.813654899,'{"timestamp": "2026-03-09T11:08:45.813655+0100", "flow_id": 1524299904066914, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 11923, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:08:45.813655+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 11923}}'); INSERT INTO alerts VALUES(1700,1773050926.92840004,'{"timestamp": "2026-03-09T11:08:46.928400+0100", "flow_id": 1735649949274315, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43224, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17205, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:08:46.928400+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43224, "dest_port": 53}}'); INSERT INTO alerts VALUES(1701,1773050926.928400993,'{"timestamp": "2026-03-09T11:08:46.928401+0100", "flow_id": 1735653186344688, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57976, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5429, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:08:46.928401+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57976, "dest_port": 53}}'); INSERT INTO alerts VALUES(1702,1773050942.185431004,'{"timestamp": "2026-03-09T11:09:02.185431+0100", "flow_id": 1922320039082686, "event_type": "alert", "src_ip": "167.94.138.134", "src_port": 59485, "dest_ip": "134.19.55.199", "dest_port": 10000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:09:02.185431+0100", "src_ip": "167.94.138.134", "dest_ip": "134.19.55.199", "src_port": 59485, "dest_port": 10000}}'); INSERT INTO alerts VALUES(1703,1773050965.09180808,'{"timestamp": "2026-03-09T11:09:25.091808+0100", "flow_id": 1520213455061067, "event_type": "alert", "src_ip": "64.62.156.106", "src_port": 55582, "dest_ip": "134.19.55.199", "dest_port": 8001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:09:25.091808+0100", "src_ip": "64.62.156.106", "dest_ip": "134.19.55.199", "src_port": 55582, "dest_port": 8001}}'); INSERT INTO alerts VALUES(1704,1773051032.384591103,'{"timestamp": "2026-03-09T11:10:32.384591+0100", "flow_id": 244431387104509, "event_type": "alert", "src_ip": "193.163.125.200", "src_port": 41620, "dest_ip": "134.19.55.199", "dest_port": 21330, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:10:32.384591+0100", "src_ip": "193.163.125.200", "dest_ip": "134.19.55.199", "src_port": 41620, "dest_port": 21330}}'); INSERT INTO alerts VALUES(1705,1773051044.044703961,'{"timestamp": "2026-03-09T11:10:44.044704+0100", "flow_id": 1317902793353174, "event_type": "alert", "src_ip": "91.196.152.123", "src_port": 6904, "dest_ip": "134.19.55.199", "dest_port": 20043, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:10:44.044704+0100", "src_ip": "91.196.152.123", "dest_ip": "134.19.55.199", "src_port": 6904, "dest_port": 20043}}'); INSERT INTO alerts VALUES(1706,1773051066.748941898,'{"timestamp": "2026-03-09T11:11:06.748942+0100", "flow_id": 683410533409153, "event_type": "alert", "src_ip": "64.62.156.174", "src_port": 45208, "dest_ip": "134.19.55.199", "dest_port": 8001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:11:06.748942+0100", "src_ip": "64.62.156.174", "dest_ip": "134.19.55.199", "src_port": 45208, "dest_port": 8001}}'); INSERT INTO alerts VALUES(1707,1773051067.015927076,'{"timestamp": "2026-03-09T11:11:07.015927+0100", "flow_id": 912831113880420, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60117, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22535, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:11:07.015927+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60117, "dest_port": 53}}'); INSERT INTO alerts VALUES(1708,1773051067.015927076,'{"timestamp": "2026-03-09T11:11:07.015927+0100", "flow_id": 912832484582919, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 45964, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1866, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:11:07.015927+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 45964, "dest_port": 53}}'); INSERT INTO alerts VALUES(1709,1773051093.725223065,'{"timestamp": "2026-03-09T11:11:33.725223+0100", "flow_id": 1425962590708150, "event_type": "alert", "src_ip": "193.163.125.213", "src_port": 53128, "dest_ip": "134.19.55.199", "dest_port": 3006, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:11:33.725223+0100", "src_ip": "193.163.125.213", "dest_ip": "134.19.55.199", "src_port": 53128, "dest_port": 3006}}'); INSERT INTO alerts VALUES(1710,1773051122.796925068,'{"timestamp": "2026-03-09T11:12:02.796925+0100", "flow_id": 608019286064719, "event_type": "alert", "src_ip": "195.184.76.236", "src_port": 8463, "dest_ip": "134.19.55.199", "dest_port": 8020, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:12:02.796925+0100", "src_ip": "195.184.76.236", "dest_ip": "134.19.55.199", "src_port": 8463, "dest_port": 8020}}'); INSERT INTO alerts VALUES(1711,1773051124.906116962,'{"timestamp": "2026-03-09T11:12:04.906117+0100", "flow_id": 1358468296301849, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 47699, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:12:04.906117+0100", "src_ip": "130.12.180.174", "dest_ip": "134.19.55.199", "src_port": 47699, "dest_port": 23}}'); INSERT INTO alerts VALUES(1712,1773051124.906116962,'{"timestamp": "2026-03-09T11:12:04.906117+0100", "flow_id": 1358468296301849, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 47699, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:12:04.906117+0100", "src_ip": "130.12.180.174", "dest_ip": "134.19.55.199", "src_port": 47699, "dest_port": 23}}'); INSERT INTO alerts VALUES(1713,1773051131.84306693,'{"timestamp": "2026-03-09T11:12:11.843067+0100", "flow_id": 1087671449236543, "event_type": "alert", "src_ip": "167.94.146.41", "src_port": 51977, "dest_ip": "134.19.55.199", "dest_port": 29698, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:12:11.843067+0100", "src_ip": "167.94.146.41", "dest_ip": "134.19.55.199", "src_port": 51977, "dest_port": 29698}}'); INSERT INTO alerts VALUES(1714,1773051159.628410101,'{"timestamp": "2026-03-09T11:12:39.628410+0100", "flow_id": 2136051686513908, "event_type": "alert", "src_ip": "198.235.24.108", "src_port": 52339, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:12:39.628410+0100", "src_ip": "198.235.24.108", "dest_ip": "134.19.55.199", "src_port": 52339, "dest_port": 3389}}'); INSERT INTO alerts VALUES(1715,1773051197.081610919,'{"timestamp": "2026-03-09T11:13:17.081611+0100", "flow_id": 1476418953306956, "event_type": "alert", "src_ip": "176.65.148.204", "src_port": 42722, "dest_ip": "134.19.55.199", "dest_port": 25571, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:13:17.081611+0100", "src_ip": "176.65.148.204", "dest_ip": "134.19.55.199", "src_port": 42722, "dest_port": 25571}}'); INSERT INTO alerts VALUES(1716,1773051197.081610919,'{"timestamp": "2026-03-09T11:13:17.081611+0100", "flow_id": 1476418953306956, "event_type": "alert", "src_ip": "176.65.148.204", "src_port": 42722, "dest_ip": "134.19.55.199", "dest_port": 25571, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:13:17.081611+0100", "src_ip": "176.65.148.204", "dest_ip": "134.19.55.199", "src_port": 42722, "dest_port": 25571}}'); INSERT INTO alerts VALUES(1717,1773051207.071574927,'{"timestamp": "2026-03-09T11:13:27.071575+0100", "flow_id": 1996263223753485, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34682, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32636, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:13:27.071575+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34682, "dest_port": 53}}'); INSERT INTO alerts VALUES(1718,1773051207.071574927,'{"timestamp": "2026-03-09T11:13:27.071575+0100", "flow_id": 1996263683487790, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 38160, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:13:27.071575+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 38160, "dest_port": 53}}'); INSERT INTO alerts VALUES(1719,1773051347.120975018,'{"timestamp": "2026-03-09T11:15:47.120975+0100", "flow_id": 1082534540570190, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 55474, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19417, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:15:47.120975+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 55474, "dest_port": 53}}'); INSERT INTO alerts VALUES(1720,1773051347.120975018,'{"timestamp": "2026-03-09T11:15:47.120975+0100", "flow_id": 1082536481246373, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44433, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14729, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:15:47.120975+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44433, "dest_port": 53}}'); INSERT INTO alerts VALUES(1721,1773051425.19550395,'{"timestamp": "2026-03-09T11:17:05.195504+0100", "flow_id": 558210192507454, "event_type": "alert", "src_ip": "167.94.146.34", "src_port": 43600, "dest_ip": "134.19.55.199", "dest_port": 52353, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:17:05.195504+0100", "src_ip": "167.94.146.34", "dest_ip": "134.19.55.199", "src_port": 43600, "dest_port": 52353}}'); INSERT INTO alerts VALUES(1722,1773051450.617250919,'{"timestamp": "2026-03-09T11:17:30.617251+0100", "flow_id": 680748391395794, "event_type": "alert", "src_ip": "64.89.163.130", "src_port": 51318, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:17:30.617251+0100", "src_ip": "64.89.163.130", "dest_ip": "134.19.55.199", "src_port": 51318, "dest_port": 27017}}'); INSERT INTO alerts VALUES(1723,1773051481.576647996,'{"timestamp": "2026-03-09T11:18:01.576648+0100", "flow_id": 506359616971007, "event_type": "alert", "src_ip": "64.62.156.172", "src_port": 39583, "dest_ip": "134.19.55.199", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:18:01.576648+0100", "src_ip": "64.62.156.172", "dest_ip": "134.19.55.199", "src_port": 39583, "dest_port": 8888}}'); INSERT INTO alerts VALUES(1724,1773051487.181991101,'{"timestamp": "2026-03-09T11:18:07.181991+0100", "flow_id": 2189022547361214, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43100, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32269, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:18:07.181991+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43100, "dest_port": 53}}'); INSERT INTO alerts VALUES(1725,1773051487.181991101,'{"timestamp": "2026-03-09T11:18:07.181991+0100", "flow_id": 2189021190213872, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41984, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54347, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:18:07.181991+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41984, "dest_port": 53}}'); INSERT INTO alerts VALUES(1726,1773051573.981916905,'{"timestamp": "2026-03-09T11:19:33.981917+0100", "flow_id": 1684028073995931, "event_type": "alert", "src_ip": "195.184.76.141", "src_port": 8335, "dest_ip": "134.19.55.199", "dest_port": 6074, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:19:33.981917+0100", "src_ip": "195.184.76.141", "dest_ip": "134.19.55.199", "src_port": 8335, "dest_port": 6074}}'); INSERT INTO alerts VALUES(1727,1773051582.377022981,'{"timestamp": "2026-03-09T11:19:42.377023+0100", "flow_id": 1900776661495760, "event_type": "alert", "src_ip": "167.94.146.77", "src_port": 44324, "dest_ip": "134.19.55.199", "dest_port": 31740, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:19:42.377023+0100", "src_ip": "167.94.146.77", "dest_ip": "134.19.55.199", "src_port": 44324, "dest_port": 31740}}'); INSERT INTO alerts VALUES(1728,1773051627.242048025,'{"timestamp": "2026-03-09T11:20:27.242048+0100", "flow_id": 1039590530832566, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51929, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2071, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:20:27.242048+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51929, "dest_port": 53}}'); INSERT INTO alerts VALUES(1729,1773051627.242048979,'{"timestamp": "2026-03-09T11:20:27.242049+0100", "flow_id": 1039594740214630, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 58329, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7277, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:20:27.242049+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 58329, "dest_port": 53}}'); INSERT INTO alerts VALUES(1730,1773051671.333532095,'{"timestamp": "2026-03-09T11:21:11.333532+0100", "flow_id": 1995462795438615, "event_type": "alert", "src_ip": "65.49.1.220", "src_port": 49756, "dest_ip": "134.19.55.199", "dest_port": 2031, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:21:11.333532+0100", "src_ip": "65.49.1.220", "dest_ip": "134.19.55.199", "src_port": 49756, "dest_port": 2031}}'); INSERT INTO alerts VALUES(1731,1773051690.244424105,'{"timestamp": "2026-03-09T11:21:30.244424+0100", "flow_id": 768318469225365, "event_type": "alert", "src_ip": "64.62.197.31", "src_port": 45032, "dest_ip": "134.19.55.199", "dest_port": 2087, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:21:30.244424+0100", "src_ip": "64.62.197.31", "dest_ip": "134.19.55.199", "src_port": 45032, "dest_port": 2087}}'); INSERT INTO alerts VALUES(1732,1773051702.600467921,'{"timestamp": "2026-03-09T11:21:42.600468+0100", "flow_id": 1734569028155891, "event_type": "alert", "src_ip": "91.196.152.108", "src_port": 20505, "dest_ip": "134.19.55.199", "dest_port": 2077, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:21:42.600468+0100", "src_ip": "91.196.152.108", "dest_ip": "134.19.55.199", "src_port": 20505, "dest_port": 2077}}'); INSERT INTO alerts VALUES(1733,1773051708.535520076,'{"timestamp": "2026-03-09T11:21:48.535520+0100", "flow_id": 1174141875830629, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 4449, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:21:48.535520+0100", "src_ip": "185.156.73.181", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 4449}}'); INSERT INTO alerts VALUES(1734,1773051732.126230956,'{"timestamp": "2026-03-09T11:22:12.126231+0100", "flow_id": 1386584117502495, "event_type": "alert", "src_ip": "91.196.152.92", "src_port": 62668, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:22:12.126231+0100", "src_ip": "91.196.152.92", "dest_ip": "134.19.55.199", "src_port": 62668, "dest_port": 3000}}'); INSERT INTO alerts VALUES(1735,1773051768.868603944,'{"timestamp": "2026-03-09T11:22:48.868604+0100", "flow_id": 71455356011885, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60341, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23128, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:22:48.868604+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60341, "dest_port": 53}}'); INSERT INTO alerts VALUES(1736,1773051768.868603944,'{"timestamp": "2026-03-09T11:22:48.868604+0100", "flow_id": 71451930452807, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 58756, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21184, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:22:48.868604+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 58756, "dest_port": 53}}'); INSERT INTO alerts VALUES(1737,1773051794.419936895,'{"timestamp": "2026-03-09T11:23:14.419937+0100", "flow_id": 677718150897433, "event_type": "alert", "src_ip": "64.62.197.5", "src_port": 45800, "dest_ip": "134.19.55.199", "dest_port": 808, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:23:14.419937+0100", "src_ip": "64.62.197.5", "dest_ip": "134.19.55.199", "src_port": 45800, "dest_port": 808}}'); INSERT INTO alerts VALUES(1738,1773051907.937355041,'{"timestamp": "2026-03-09T11:25:07.937355+0100", "flow_id": 929686389874479, "event_type": "alert", "src_ip": "193.163.125.194", "src_port": 47221, "dest_ip": "134.19.55.199", "dest_port": 42476, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:25:07.937355+0100", "src_ip": "193.163.125.194", "dest_ip": "134.19.55.199", "src_port": 47221, "dest_port": 42476}}'); INSERT INTO alerts VALUES(1739,1773051908.942480088,'{"timestamp": "2026-03-09T11:25:08.942480+0100", "flow_id": 1233172692689267, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60476, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56448, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:25:08.942480+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60476, "dest_port": 53}}'); INSERT INTO alerts VALUES(1740,1773051908.942480088,'{"timestamp": "2026-03-09T11:25:08.942480+0100", "flow_id": 1233172865027821, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36179, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21568, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:25:08.942480+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36179, "dest_port": 53}}'); INSERT INTO alerts VALUES(1741,1773051918.94164896,'{"timestamp": "2026-03-09T11:25:18.941649+0100", "flow_id": 1792553643828327, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 3003, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:25:18.941649+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 3003}}'); INSERT INTO alerts VALUES(1742,1773051918.94164896,'{"timestamp": "2026-03-09T11:25:18.941649+0100", "flow_id": 1792553643828327, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 3003, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:25:18.941649+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 3003}}'); INSERT INTO alerts VALUES(1743,1773051939.873825073,'{"timestamp": "2026-03-09T11:25:39.873825+0100", "flow_id": 938303811466367, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 54474, "dest_ip": "134.19.55.199", "dest_port": 19626, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:25:39.873825+0100", "src_ip": "167.94.146.45", "dest_ip": "134.19.55.199", "src_port": 54474, "dest_port": 19626}}'); INSERT INTO alerts VALUES(1744,1773052049.03217101,'{"timestamp": "2026-03-09T11:27:29.032171+0100", "flow_id": 419652228367522, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51837, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44423, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:27:29.032171+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51837, "dest_port": 53}}'); INSERT INTO alerts VALUES(1745,1773052049.03217101,'{"timestamp": "2026-03-09T11:27:29.032171+0100", "flow_id": 419652474851357, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42217, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9814, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:27:29.032171+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42217, "dest_port": 53}}'); INSERT INTO alerts VALUES(1746,1773052053.419589043,'{"timestamp": "2026-03-09T11:27:33.419589+0100", "flow_id": 1520647243678386, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 40023, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:27:33.419589+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 40023}}'); INSERT INTO alerts VALUES(1747,1773052053.419589043,'{"timestamp": "2026-03-09T11:27:33.419589+0100", "flow_id": 1520647243678386, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 40023, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:27:33.419589+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 40023}}'); INSERT INTO alerts VALUES(1748,1773052129.081671953,'{"timestamp": "2026-03-09T11:28:49.081672+0100", "flow_id": 350779894824087, "event_type": "alert", "src_ip": "167.94.138.124", "src_port": 31970, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:28:49.081672+0100", "src_ip": "167.94.138.124", "dest_ip": "134.19.55.199", "src_port": 31970, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1749,1773052154.82562995,'{"timestamp": "2026-03-09T11:29:14.825630+0100", "flow_id": 731305352786829, "event_type": "alert", "src_ip": "91.196.152.100", "src_port": 20748, "dest_ip": "134.19.55.199", "dest_port": 2078, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:29:14.825630+0100", "src_ip": "91.196.152.100", "dest_ip": "134.19.55.199", "src_port": 20748, "dest_port": 2078}}'); INSERT INTO alerts VALUES(1750,1773052155.321155072,'{"timestamp": "2026-03-09T11:29:15.321155+0100", "flow_id": 1097877477904743, "event_type": "alert", "src_ip": "195.184.76.219", "src_port": 8768, "dest_ip": "134.19.55.199", "dest_port": 5192, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:29:15.321155+0100", "src_ip": "195.184.76.219", "dest_ip": "134.19.55.199", "src_port": 8768, "dest_port": 5192}}'); INSERT INTO alerts VALUES(1751,1773052189.095248937,'{"timestamp": "2026-03-09T11:29:49.095249+0100", "flow_id": 1534991852708771, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41758, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61396, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:29:49.095249+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41758, "dest_port": 53}}'); INSERT INTO alerts VALUES(1752,1773052189.095248937,'{"timestamp": "2026-03-09T11:29:49.095249+0100", "flow_id": 1534993063063634, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34245, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57042, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:29:49.095249+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34245, "dest_port": 53}}'); INSERT INTO alerts VALUES(1753,1773052196.297488927,'{"timestamp": "2026-03-09T11:29:56.297489+0100", "flow_id": 1277709734649365, "event_type": "alert", "src_ip": "64.62.156.120", "src_port": 56607, "dest_ip": "134.19.55.199", "dest_port": 25, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:29:56.297489+0100", "src_ip": "64.62.156.120", "dest_ip": "134.19.55.199", "src_port": 56607, "dest_port": 25}}'); INSERT INTO alerts VALUES(1754,1773052329.149957895,'{"timestamp": "2026-03-09T11:32:09.149958+0100", "flow_id": 362592447668750, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 35611, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16755, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:32:09.149958+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 35611, "dest_port": 53}}'); INSERT INTO alerts VALUES(1755,1773052329.149957895,'{"timestamp": "2026-03-09T11:32:09.149958+0100", "flow_id": 362590577642461, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33120, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30735, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:32:09.149958+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33120, "dest_port": 53}}'); INSERT INTO alerts VALUES(1756,1773052350.686193943,'{"timestamp": "2026-03-09T11:32:30.686194+0100", "flow_id": 1821281017013128, "event_type": "alert", "src_ip": "64.62.197.237", "src_port": 6754, "dest_ip": "134.19.55.199", "dest_port": 3702, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 33, "bytes_toclient": 0, "start": "2026-03-09T11:32:30.686194+0100", "src_ip": "64.62.197.237", "dest_ip": "134.19.55.199", "src_port": 6754, "dest_port": 3702}}'); INSERT INTO alerts VALUES(1757,1773052365.842319012,'{"timestamp": "2026-03-09T11:32:45.842319+0100", "flow_id": 1647409221440017, "event_type": "alert", "src_ip": "162.217.98.180", "src_port": 44568, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 413, "bytes_toclient": 0, "start": "2026-03-09T11:32:45.842319+0100", "src_ip": "162.217.98.180", "dest_ip": "134.19.55.199", "src_port": 44568, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1758,1773052388.980459929,'{"timestamp": "2026-03-09T11:33:08.980460+0100", "flow_id": 1396297820550884, "event_type": "alert", "src_ip": "185.242.226.71", "src_port": 58908, "dest_ip": "134.19.55.199", "dest_port": 49200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:33:08.980460+0100", "src_ip": "185.242.226.71", "dest_ip": "134.19.55.199", "src_port": 58908, "dest_port": 49200}}'); INSERT INTO alerts VALUES(1759,1773052401.007097959,'{"timestamp": "2026-03-09T11:33:21.007098+0100", "flow_id": 311963637757948, "event_type": "alert", "src_ip": "64.89.163.104", "src_port": 55652, "dest_ip": "134.19.55.199", "dest_port": 1935, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:33:21.007098+0100", "src_ip": "64.89.163.104", "dest_ip": "134.19.55.199", "src_port": 55652, "dest_port": 1935}}'); INSERT INTO alerts VALUES(1760,1773052453.381269932,'{"timestamp": "2026-03-09T11:34:13.381270+0100", "flow_id": 1637545993826051, "event_type": "alert", "src_ip": "193.163.125.205", "src_port": 52557, "dest_ip": "134.19.55.199", "dest_port": 8079, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:34:13.381270+0100", "src_ip": "193.163.125.205", "dest_ip": "134.19.55.199", "src_port": 52557, "dest_port": 8079}}'); INSERT INTO alerts VALUES(1761,1773052469.216433049,'{"timestamp": "2026-03-09T11:34:29.216433+0100", "flow_id": 1492526159651080, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51081, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54200, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:34:29.216433+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51081, "dest_port": 53}}'); INSERT INTO alerts VALUES(1762,1773052469.21972394,'{"timestamp": "2026-03-09T11:34:29.219724+0100", "flow_id": 1506658342749692, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42433, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53454, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:34:29.219724+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42433, "dest_port": 53}}'); INSERT INTO alerts VALUES(1763,1773052503.188996077,'{"timestamp": "2026-03-09T11:35:03.188996+0100", "flow_id": 2219110119766475, "event_type": "alert", "src_ip": "167.94.146.33", "src_port": 8626, "dest_ip": "134.19.55.199", "dest_port": 53424, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:35:03.188996+0100", "src_ip": "167.94.146.33", "dest_ip": "134.19.55.199", "src_port": 8626, "dest_port": 53424}}'); INSERT INTO alerts VALUES(1764,1773052609.292243003,'{"timestamp": "2026-03-09T11:36:49.292243+0100", "flow_id": 410751610702053, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46541, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42428, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:36:49.292243+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46541, "dest_port": 53}}'); INSERT INTO alerts VALUES(1765,1773052609.292243958,'{"timestamp": "2026-03-09T11:36:49.292244+0100", "flow_id": 410757269224594, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49076, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42598, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:36:49.292244+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49076, "dest_port": 53}}'); INSERT INTO alerts VALUES(1766,1773052671.502420903,'{"timestamp": "2026-03-09T11:37:51.502421+0100", "flow_id": 2157881951141872, "event_type": "alert", "src_ip": "195.184.76.173", "src_port": 53686, "dest_ip": "134.19.55.199", "dest_port": 6109, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:37:51.502421+0100", "src_ip": "195.184.76.173", "dest_ip": "134.19.55.199", "src_port": 53686, "dest_port": 6109}}'); INSERT INTO alerts VALUES(1767,1773052749.349332094,'{"timestamp": "2026-03-09T11:39:09.349332+0100", "flow_id": 1500370603220539, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45148, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:39:09.349332+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34632, "dest_port": 53}}'); INSERT INTO alerts VALUES(1768,1773052749.349333047,'{"timestamp": "2026-03-09T11:39:09.349333+0100", "flow_id": 1500377989172042, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39251, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:39:09.349333+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39251, "dest_port": 53}}'); INSERT INTO alerts VALUES(1769,1773052753.991156102,'{"timestamp": "2026-03-09T11:39:13.991156+0100", "flow_id": 316335094183866, "event_type": "alert", "src_ip": "64.62.197.209", "src_port": 60198, "dest_ip": "134.19.55.199", "dest_port": 7777, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:39:13.991156+0100", "src_ip": "64.62.197.209", "dest_ip": "134.19.55.199", "src_port": 60198, "dest_port": 7777}}'); INSERT INTO alerts VALUES(1770,1773052804.630593061,'{"timestamp": "2026-03-09T11:40:04.630593+0100", "flow_id": 1301002449548804, "event_type": "alert", "src_ip": "193.163.125.193", "src_port": 48180, "dest_ip": "134.19.55.199", "dest_port": 18789, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:40:04.630593+0100", "src_ip": "193.163.125.193", "dest_ip": "134.19.55.199", "src_port": 48180, "dest_port": 18789}}'); INSERT INTO alerts VALUES(1771,1773052818.590946912,'{"timestamp": "2026-03-09T11:40:18.590947+0100", "flow_id": 567776325950050, "event_type": "alert", "src_ip": "167.94.146.44", "src_port": 37280, "dest_ip": "134.19.55.199", "dest_port": 8119, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:40:18.590947+0100", "src_ip": "167.94.146.44", "dest_ip": "134.19.55.199", "src_port": 37280, "dest_port": 8119}}'); INSERT INTO alerts VALUES(1772,1773052847.977611064,'{"timestamp": "2026-03-09T11:40:47.977611+0100", "flow_id": 2228483177998077, "event_type": "alert", "src_ip": "91.196.152.189", "src_port": 56059, "dest_ip": "134.19.55.199", "dest_port": 20063, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:40:47.977611+0100", "src_ip": "91.196.152.189", "dest_ip": "134.19.55.199", "src_port": 56059, "dest_port": 20063}}'); INSERT INTO alerts VALUES(1773,1773052889.410063982,'{"timestamp": "2026-03-09T11:41:29.410064+0100", "flow_id": 353839584237741, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44447, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2893, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:41:29.410064+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44447, "dest_port": 53}}'); INSERT INTO alerts VALUES(1774,1773052889.410064935,'{"timestamp": "2026-03-09T11:41:29.410065+0100", "flow_id": 353845134887812, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 56697, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11625, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:41:29.410065+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 56697, "dest_port": 53}}'); INSERT INTO alerts VALUES(1775,1773052907.015396118,'{"timestamp": "2026-03-09T11:41:47.015396+0100", "flow_id": 910552975933919, "event_type": "alert", "src_ip": "65.49.1.39", "src_port": 35110, "dest_ip": "134.19.55.199", "dest_port": 8040, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:41:47.015396+0100", "src_ip": "65.49.1.39", "dest_ip": "134.19.55.199", "src_port": 35110, "dest_port": 8040}}'); INSERT INTO alerts VALUES(1776,1773052958.085747003,'{"timestamp": "2026-03-09T11:42:38.085747+0100", "flow_id": 1775657675827674, "event_type": "alert", "src_ip": "178.20.210.152", "src_port": 51126, "dest_ip": "134.19.55.199", "dest_port": 830, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:42:38.085747+0100", "src_ip": "178.20.210.152", "dest_ip": "134.19.55.199", "src_port": 51126, "dest_port": 830}}'); INSERT INTO alerts VALUES(1777,1773053003.427575111,'{"timestamp": "2026-03-09T11:43:23.427575+0100", "flow_id": 991998397312087, "event_type": "alert", "src_ip": "91.196.152.211", "src_port": 48334, "dest_ip": "134.19.55.199", "dest_port": 2081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:43:23.427575+0100", "src_ip": "91.196.152.211", "dest_ip": "134.19.55.199", "src_port": 48334, "dest_port": 2081}}'); INSERT INTO alerts VALUES(1778,1773053009.578465939,'{"timestamp": "2026-03-09T11:43:29.578466+0100", "flow_id": 514169289289716, "event_type": "alert", "src_ip": "167.94.146.69", "src_port": 18567, "dest_ip": "134.19.55.199", "dest_port": 39014, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:43:29.578466+0100", "src_ip": "167.94.146.69", "dest_ip": "134.19.55.199", "src_port": 18567, "dest_port": 39014}}'); INSERT INTO alerts VALUES(1779,1773053029.473799943,'{"timestamp": "2026-03-09T11:43:49.473800+0100", "flow_id": 1472008236251369, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 45755, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22100, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:43:49.473800+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 45755, "dest_port": 53}}'); INSERT INTO alerts VALUES(1780,1773053029.473799943,'{"timestamp": "2026-03-09T11:43:49.473800+0100", "flow_id": 1472008687485433, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44513, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64638, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:43:49.473800+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44513, "dest_port": 53}}'); INSERT INTO alerts VALUES(1781,1773053059.387099028,'{"timestamp": "2026-03-09T11:44:19.387099+0100", "flow_id": 1099630313702092, "event_type": "alert", "src_ip": "195.184.76.228", "src_port": 52489, "dest_ip": "134.19.55.199", "dest_port": 8008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:44:19.387099+0100", "src_ip": "195.184.76.228", "dest_ip": "134.19.55.199", "src_port": 52489, "dest_port": 8008}}'); INSERT INTO alerts VALUES(1782,1773053101.87656498,'{"timestamp": "2026-03-09T11:45:01.876565+0100", "flow_id": 1513021726273552, "event_type": "alert", "src_ip": "65.49.1.90", "src_port": 34320, "dest_ip": "134.19.55.199", "dest_port": 8015, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:45:01.876565+0100", "src_ip": "65.49.1.90", "dest_ip": "134.19.55.199", "src_port": 34320, "dest_port": 8015}}'); INSERT INTO alerts VALUES(1783,1773053162.206281901,'{"timestamp": "2026-03-09T11:46:02.206282+0100", "flow_id": 604502446289918, "event_type": "alert", "src_ip": "51.91.168.77", "src_port": 5108, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 431, "bytes_toclient": 0, "start": "2026-03-09T11:46:02.206282+0100", "src_ip": "51.91.168.77", "dest_ip": "134.19.55.199", "src_port": 5108, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1784,1773053162.708756924,'{"timestamp": "2026-03-09T11:46:02.708757+0100", "flow_id": 792289013888937, "event_type": "alert", "src_ip": "65.49.1.180", "src_port": 44022, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:46:02.708757+0100", "src_ip": "65.49.1.180", "dest_ip": "134.19.55.199", "src_port": 44022, "dest_port": 22}}'); INSERT INTO alerts VALUES(1785,1773053169.589688063,'{"timestamp": "2026-03-09T11:46:09.589688+0100", "flow_id": 562366375809356, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 48905, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26789, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:46:09.589688+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 48905, "dest_port": 53}}'); INSERT INTO alerts VALUES(1786,1773053169.589688063,'{"timestamp": "2026-03-09T11:46:09.589688+0100", "flow_id": 562367664683326, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 45173, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58640, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:46:09.589688+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 45173, "dest_port": 53}}'); INSERT INTO alerts VALUES(1787,1773053201.253277064,'{"timestamp": "2026-03-09T11:46:41.253277+0100", "flow_id": 524870283003286, "event_type": "alert", "src_ip": "64.62.156.213", "src_port": 40862, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:46:41.253277+0100", "src_ip": "64.62.156.213", "dest_ip": "134.19.55.199", "src_port": 40862, "dest_port": 22}}'); INSERT INTO alerts VALUES(1788,1773053220.074605941,'{"timestamp": "2026-03-09T11:47:00.074606+0100", "flow_id": 1164858271621602, "event_type": "alert", "src_ip": "64.62.197.117", "src_port": 58357, "dest_ip": "134.19.55.199", "dest_port": 5988, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:47:00.074606+0100", "src_ip": "64.62.197.117", "dest_ip": "134.19.55.199", "src_port": 58357, "dest_port": 5988}}'); INSERT INTO alerts VALUES(1789,1773053309.658463001,'{"timestamp": "2026-03-09T11:48:29.658463+0100", "flow_id": 1420702329290038, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42800, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44576, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:48:29.658463+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42800, "dest_port": 53}}'); INSERT INTO alerts VALUES(1790,1773053309.658463001,'{"timestamp": "2026-03-09T11:48:29.658463+0100", "flow_id": 1420703415506485, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40889, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49351, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:48:29.658463+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40889, "dest_port": 53}}'); INSERT INTO alerts VALUES(1791,1773053331.345979928,'{"timestamp": "2026-03-09T11:48:51.345980+0100", "flow_id": 923024625652658, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44394, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:48:51.345980+0100", "src_ip": "88.210.63.69", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44394}}'); INSERT INTO alerts VALUES(1792,1773053333.346348047,'{"timestamp": "2026-03-09T11:48:53.346348+0100", "flow_id": 1487555443506326, "event_type": "alert", "src_ip": "193.163.125.216", "src_port": 58591, "dest_ip": "134.19.55.199", "dest_port": 11711, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:48:53.346348+0100", "src_ip": "193.163.125.216", "dest_ip": "134.19.55.199", "src_port": 58591, "dest_port": 11711}}'); INSERT INTO alerts VALUES(1793,1773053336.145482063,'{"timestamp": "2026-03-09T11:48:56.145482+0100", "flow_id": 61890722429857, "event_type": "alert", "src_ip": "64.62.156.27", "src_port": 54411, "dest_ip": "134.19.55.199", "dest_port": 50000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:48:56.145482+0100", "src_ip": "64.62.156.27", "dest_ip": "134.19.55.199", "src_port": 54411, "dest_port": 50000}}'); INSERT INTO alerts VALUES(1794,1773053428.90840292,'{"timestamp": "2026-03-09T11:50:28.908403+0100", "flow_id": 1368288857695245, "event_type": "alert", "src_ip": "195.184.76.108", "src_port": 60913, "dest_ip": "134.19.55.199", "dest_port": 8015, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:50:28.908403+0100", "src_ip": "195.184.76.108", "dest_ip": "134.19.55.199", "src_port": 60913, "dest_port": 8015}}'); INSERT INTO alerts VALUES(1795,1773053449.710846901,'{"timestamp": "2026-03-09T11:50:49.710847+0100", "flow_id": 519791863392562, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46724, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:50:49.710847+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46724, "dest_port": 53}}'); INSERT INTO alerts VALUES(1796,1773053449.710846901,'{"timestamp": "2026-03-09T11:50:49.710847+0100", "flow_id": 519791376324670, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39276, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20520, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:50:49.710847+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39276, "dest_port": 53}}'); INSERT INTO alerts VALUES(1797,1773053455.730978966,'{"timestamp": "2026-03-09T11:50:55.730979+0100", "flow_id": 2013631055300699, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 56933, "dest_ip": "134.19.55.199", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T11:50:55.730979+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 56933, "dest_port": 8332}}'); INSERT INTO alerts VALUES(1798,1773053455.730978966,'{"timestamp": "2026-03-09T11:50:55.730979+0100", "flow_id": 2013631055300699, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 56933, "dest_ip": "134.19.55.199", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T11:50:55.730979+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 56933, "dest_port": 8332}}'); INSERT INTO alerts VALUES(1799,1773053464.333169937,'{"timestamp": "2026-03-09T11:51:04.333170+0100", "flow_id": 23582625526104, "event_type": "alert", "src_ip": "65.49.1.126", "src_port": 34316, "dest_ip": "134.19.55.199", "dest_port": 8020, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:51:04.333170+0100", "src_ip": "65.49.1.126", "dest_ip": "134.19.55.199", "src_port": 34316, "dest_port": 8020}}'); INSERT INTO alerts VALUES(1800,1773053525.017122031,'{"timestamp": "2026-03-09T11:52:05.017122+0100", "flow_id": 1480914954279648, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 53096, "dest_ip": "134.19.55.199", "dest_port": 41402, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:52:05.017122+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 53096, "dest_port": 41402}}'); INSERT INTO alerts VALUES(1801,1773053530.511739016,'{"timestamp": "2026-03-09T11:52:10.511739+0100", "flow_id": 790528627836953, "event_type": "alert", "src_ip": "199.195.254.152", "src_port": 37287, "dest_ip": "134.19.55.199", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101616, "rev": 9, "signature": "GPL DNS named version attempt", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_07_26"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-09T11:52:10.511739+0100", "src_ip": "199.195.254.152", "dest_ip": "134.19.55.199", "src_port": 37287, "dest_port": 53}}'); INSERT INTO alerts VALUES(1802,1773053589.815201044,'{"timestamp": "2026-03-09T11:53:09.815201+0100", "flow_id": 1530940659715587, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 38707, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37487, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:53:09.815201+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 38707, "dest_port": 53}}'); INSERT INTO alerts VALUES(1803,1773053589.815201998,'{"timestamp": "2026-03-09T11:53:09.815202+0100", "flow_id": 1530944699907570, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 56749, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56530, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:53:09.815202+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 56749, "dest_port": 53}}'); INSERT INTO alerts VALUES(1804,1773053596.368505954,'{"timestamp": "2026-03-09T11:53:16.368506+0100", "flow_id": 1301249090874131, "event_type": "alert", "src_ip": "51.38.211.50", "src_port": 5185, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 436, "bytes_toclient": 0, "start": "2026-03-09T11:53:16.368506+0100", "src_ip": "51.38.211.50", "dest_ip": "134.19.55.199", "src_port": 5185, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1805,1773053596.368505954,'{"timestamp": "2026-03-09T11:53:16.368506+0100", "flow_id": 1301249090874131, "event_type": "alert", "src_ip": "51.38.211.50", "src_port": 5185, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 436, "bytes_toclient": 0, "start": "2026-03-09T11:53:16.368506+0100", "src_ip": "51.38.211.50", "dest_ip": "134.19.55.199", "src_port": 5185, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1806,1773053630.45739293,'{"timestamp": "2026-03-09T11:53:50.457393+0100", "flow_id": 1964492083531142, "event_type": "alert", "src_ip": "147.185.132.72", "src_port": 56772, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:53:50.457393+0100", "src_ip": "147.185.132.72", "dest_ip": "134.19.55.199", "src_port": 56772, "dest_port": 22}}'); INSERT INTO alerts VALUES(1807,1773053655.201066017,'{"timestamp": "2026-03-09T11:54:15.201066+0100", "flow_id": 1989474606625678, "event_type": "alert", "src_ip": "193.163.125.195", "src_port": 34506, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:54:15.201066+0100", "src_ip": "193.163.125.195", "dest_ip": "134.19.55.199", "src_port": 34506, "dest_port": 5432}}'); INSERT INTO alerts VALUES(1808,1773053655.201066017,'{"timestamp": "2026-03-09T11:54:15.201066+0100", "flow_id": 1989474606625678, "event_type": "alert", "src_ip": "193.163.125.195", "src_port": 34506, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:54:15.201066+0100", "src_ip": "193.163.125.195", "dest_ip": "134.19.55.199", "src_port": 34506, "dest_port": 5432}}'); INSERT INTO alerts VALUES(1809,1773053682.192908048,'{"timestamp": "2026-03-09T11:54:42.192908+0100", "flow_id": 828534644211476, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 1173, "dest_ip": "134.19.55.199", "dest_port": 31129, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T11:54:42.192908+0100", "src_ip": "167.94.146.40", "dest_ip": "134.19.55.199", "src_port": 1173, "dest_port": 31129}}'); INSERT INTO alerts VALUES(1810,1773053698.889659882,'{"timestamp": "2026-03-09T11:54:58.889660+0100", "flow_id": 724836575637930, "event_type": "alert", "src_ip": "65.49.1.189", "src_port": 60291, "dest_ip": "134.19.55.199", "dest_port": 8060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:54:58.889660+0100", "src_ip": "65.49.1.189", "dest_ip": "134.19.55.199", "src_port": 60291, "dest_port": 8060}}'); INSERT INTO alerts VALUES(1811,1773053729.897667884,'{"timestamp": "2026-03-09T11:55:29.897668+0100", "flow_id": 477757611572122, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33430, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63093, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:55:29.897668+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33430, "dest_port": 53}}'); INSERT INTO alerts VALUES(1812,1773053729.897667884,'{"timestamp": "2026-03-09T11:55:29.897668+0100", "flow_id": 477757177147506, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 58406, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39525, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:55:29.897668+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 58406, "dest_port": 53}}'); INSERT INTO alerts VALUES(1813,1773053754.486963987,'{"timestamp": "2026-03-09T11:55:54.486964+0100", "flow_id": 684122804812070, "event_type": "alert", "src_ip": "64.62.156.20", "src_port": 58382, "dest_ip": "134.19.55.199", "dest_port": 5080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:55:54.486964+0100", "src_ip": "64.62.156.20", "dest_ip": "134.19.55.199", "src_port": 58382, "dest_port": 5080}}'); INSERT INTO alerts VALUES(1814,1773053758.177715063,'{"timestamp": "2026-03-09T11:55:58.177715+0100", "flow_id": 1889182529809831, "event_type": "alert", "src_ip": "45.142.154.87", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 3117, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:55:58.177715+0100", "src_ip": "45.142.154.87", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 3117}}'); INSERT INTO alerts VALUES(1815,1773053771.367361068,'{"timestamp": "2026-03-09T11:56:11.367361+0100", "flow_id": 1014855572438709, "event_type": "alert", "src_ip": "193.163.125.196", "src_port": 34506, "dest_ip": "134.19.55.199", "dest_port": 52060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:56:11.367361+0100", "src_ip": "193.163.125.196", "dest_ip": "134.19.55.199", "src_port": 34506, "dest_port": 52060}}'); INSERT INTO alerts VALUES(1816,1773053801.648895025,'{"timestamp": "2026-03-09T11:56:41.648895+0100", "flow_id": 535184169543730, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 50697, "dest_ip": "134.19.55.199", "dest_port": 48170, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:56:41.648895+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 50697, "dest_port": 48170}}'); INSERT INTO alerts VALUES(1817,1773053837.763952017,'{"timestamp": "2026-03-09T11:57:17.763952+0100", "flow_id": 1592303142581669, "event_type": "alert", "src_ip": "64.62.197.90", "src_port": 52409, "dest_ip": "134.19.55.199", "dest_port": 4081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:57:17.763952+0100", "src_ip": "64.62.197.90", "dest_ip": "134.19.55.199", "src_port": 52409, "dest_port": 4081}}'); INSERT INTO alerts VALUES(1818,1773053870.054090023,'{"timestamp": "2026-03-09T11:57:50.054090+0100", "flow_id": 1921167990984988, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 38996, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62448, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:57:50.054090+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 38996, "dest_port": 53}}'); INSERT INTO alerts VALUES(1819,1773053870.054090977,'{"timestamp": "2026-03-09T11:57:50.054091+0100", "flow_id": 1921170679865573, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50221, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48805, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T11:57:50.054091+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50221, "dest_port": 53}}'); INSERT INTO alerts VALUES(1820,1773053875.057512998,'{"timestamp": "2026-03-09T11:57:55.057513+0100", "flow_id": 1091442943139195, "event_type": "alert", "src_ip": "176.65.139.38", "src_port": 50000, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T11:57:55.057513+0100", "src_ip": "176.65.139.38", "dest_ip": "134.19.55.199", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(1821,1773053938.251368999,'{"timestamp": "2026-03-09T11:58:58.251369+0100", "flow_id": 798148393318656, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49028, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47154, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T11:58:58.251369+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49028, "dest_port": 53}}'); INSERT INTO alerts VALUES(1822,1773053938.252145052,'{"timestamp": "2026-03-09T11:58:58.252145+0100", "flow_id": 801483795922146, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 32817, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39529, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T11:58:58.252145+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 32817, "dest_port": 53}}'); INSERT INTO alerts VALUES(1823,1773053938.252145052,'{"timestamp": "2026-03-09T11:58:58.252145+0100", "flow_id": 801479907537274, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34881, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31911, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T11:58:58.252145+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34881, "dest_port": 53}}'); INSERT INTO alerts VALUES(1824,1773053947.145062923,'{"timestamp": "2026-03-09T11:59:07.145063+0100", "flow_id": 904516465320733, "event_type": "alert", "src_ip": "65.49.1.72", "src_port": 38387, "dest_ip": "134.19.55.199", "dest_port": 6081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:59:07.145063+0100", "src_ip": "65.49.1.72", "dest_ip": "134.19.55.199", "src_port": 38387, "dest_port": 6081}}'); INSERT INTO alerts VALUES(1825,1773053990.549494028,'{"timestamp": "2026-03-09T11:59:50.549494+0100", "flow_id": 1797112876069476, "event_type": "alert", "src_ip": "185.156.73.182", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44395, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T11:59:50.549494+0100", "src_ip": "185.156.73.182", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44395}}'); INSERT INTO alerts VALUES(1826,1773054010.106441975,'{"timestamp": "2026-03-09T12:00:10.106442+0100", "flow_id": 738640627384694, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33301, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40444, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:00:10.106442+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33301, "dest_port": 53}}'); INSERT INTO alerts VALUES(1827,1773054010.106441975,'{"timestamp": "2026-03-09T12:00:10.106442+0100", "flow_id": 738640592258698, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 55762, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:00:10.106442+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 55762, "dest_port": 53}}'); INSERT INTO alerts VALUES(1828,1773054094.403666973,'{"timestamp": "2026-03-09T12:01:34.403667+0100", "flow_id": 1733738419807337, "event_type": "alert", "src_ip": "167.94.138.135", "src_port": 2275, "dest_ip": "134.19.55.199", "dest_port": 2004, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:01:34.403667+0100", "src_ip": "167.94.138.135", "dest_ip": "134.19.55.199", "src_port": 2275, "dest_port": 2004}}'); INSERT INTO alerts VALUES(1829,1773054103.019649028,'{"timestamp": "2026-03-09T12:01:43.019649+0100", "flow_id": 2054718326934964, "event_type": "alert", "src_ip": "91.196.152.116", "src_port": 16531, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:01:43.019649+0100", "src_ip": "91.196.152.116", "dest_ip": "134.19.55.199", "src_port": 16531, "dest_port": 23}}'); INSERT INTO alerts VALUES(1830,1773054150.166250945,'{"timestamp": "2026-03-09T12:02:30.166251+0100", "flow_id": 1839942859762950, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60760, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9161, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:02:30.166251+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60760, "dest_port": 53}}'); INSERT INTO alerts VALUES(1831,1773054150.166251897,'{"timestamp": "2026-03-09T12:02:30.166252+0100", "flow_id": 1839948002317068, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 54881, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5273, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:02:30.166252+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 54881, "dest_port": 53}}'); INSERT INTO alerts VALUES(1832,1773054162.07557106,'{"timestamp": "2026-03-09T12:02:42.075571+0100", "flow_id": 606051460336752, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33171, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6321, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T12:02:42.075571+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33171, "dest_port": 53}}'); INSERT INTO alerts VALUES(1833,1773054162.07557106,'{"timestamp": "2026-03-09T12:02:42.075571+0100", "flow_id": 606050885947447, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42970, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T12:02:42.075571+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42970, "dest_port": 53}}'); INSERT INTO alerts VALUES(1834,1773054162.07557106,'{"timestamp": "2026-03-09T12:02:42.075571+0100", "flow_id": 606050547838864, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33501, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39384, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T12:02:42.075571+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33501, "dest_port": 53}}'); INSERT INTO alerts VALUES(1835,1773054168.475538015,'{"timestamp": "2026-03-09T12:02:48.475538+0100", "flow_id": 72096155575288, "event_type": "alert", "src_ip": "195.184.76.181", "src_port": 64824, "dest_ip": "134.19.55.199", "dest_port": 5194, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:02:48.475538+0100", "src_ip": "195.184.76.181", "dest_ip": "134.19.55.199", "src_port": 64824, "dest_port": 5194}}'); INSERT INTO alerts VALUES(1836,1773054210.974282026,'{"timestamp": "2026-03-09T12:03:30.974282+0100", "flow_id": 806810841650034, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 51000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:03:30.974282+0100", "src_ip": "185.156.73.86", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 51000}}'); INSERT INTO alerts VALUES(1837,1773054277.896748065,'{"timestamp": "2026-03-09T12:04:37.896748+0100", "flow_id": 1599704378958597, "event_type": "alert", "src_ip": "87.121.84.35", "src_port": 60001, "dest_ip": "134.19.55.199", "dest_port": 22129, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:04:37.896748+0100", "src_ip": "87.121.84.35", "dest_ip": "134.19.55.199", "src_port": 60001, "dest_port": 22129}}'); INSERT INTO alerts VALUES(1838,1773054290.261749983,'{"timestamp": "2026-03-09T12:04:50.261750+0100", "flow_id": 842733153060436, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41435, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21801, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:04:50.261750+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41435, "dest_port": 53}}'); INSERT INTO alerts VALUES(1839,1773054290.261749983,'{"timestamp": "2026-03-09T12:04:50.261750+0100", "flow_id": 842735668688127, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50177, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54515, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:04:50.261750+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50177, "dest_port": 53}}'); INSERT INTO alerts VALUES(1840,1773054314.5435009,'{"timestamp": "2026-03-09T12:05:14.543501+0100", "flow_id": 645469287416000, "event_type": "alert", "src_ip": "167.94.138.109", "src_port": 4577, "dest_ip": "134.19.55.199", "dest_port": 53697, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:05:14.543501+0100", "src_ip": "167.94.138.109", "dest_ip": "134.19.55.199", "src_port": 4577, "dest_port": 53697}}'); INSERT INTO alerts VALUES(1841,1773054315.693397999,'{"timestamp": "2026-03-09T12:05:15.693398+0100", "flow_id": 1007797955559532, "event_type": "alert", "src_ip": "192.253.248.14", "src_port": 60096, "dest_ip": "134.19.55.199", "dest_port": 110, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:05:15.693398+0100", "src_ip": "192.253.248.14", "dest_ip": "134.19.55.199", "src_port": 60096, "dest_port": 110}}'); INSERT INTO alerts VALUES(1842,1773054325.587197066,'{"timestamp": "2026-03-09T12:05:25.587197+0100", "flow_id": 1677567658080007, "event_type": "alert", "src_ip": "87.121.84.67", "src_port": 49639, "dest_ip": "134.19.55.199", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:05:25.587197+0100", "src_ip": "87.121.84.67", "dest_ip": "134.19.55.199", "src_port": 49639, "dest_port": 5900}}'); INSERT INTO alerts VALUES(1843,1773054345.191463947,'{"timestamp": "2026-03-09T12:05:45.191464+0100", "flow_id": 540858426007295, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34165, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T12:05:45.191464+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33048, "dest_port": 53}}'); INSERT INTO alerts VALUES(1844,1773054345.192009926,'{"timestamp": "2026-03-09T12:05:45.192010+0100", "flow_id": 543204973128258, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46122, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23271, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T12:05:45.192010+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46122, "dest_port": 53}}'); INSERT INTO alerts VALUES(1845,1773054345.192687035,'{"timestamp": "2026-03-09T12:05:45.192687+0100", "flow_id": 546111675917038, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59961, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40151, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T12:05:45.192687+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59961, "dest_port": 53}}'); INSERT INTO alerts VALUES(1846,1773054350.163925886,'{"timestamp": "2026-03-09T12:05:50.163926+0100", "flow_id": 1829959138193718, "event_type": "alert", "src_ip": "167.94.146.43", "src_port": 38016, "dest_ip": "134.19.55.199", "dest_port": 987, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:05:50.163926+0100", "src_ip": "167.94.146.43", "dest_ip": "134.19.55.199", "src_port": 38016, "dest_port": 987}}'); INSERT INTO alerts VALUES(1847,1773054353.712904931,'{"timestamp": "2026-03-09T12:05:53.712905+0100", "flow_id": 528631596023601, "event_type": "alert", "src_ip": "193.163.125.211", "src_port": 34169, "dest_ip": "134.19.55.199", "dest_port": 40004, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:05:53.712905+0100", "src_ip": "193.163.125.211", "dest_ip": "134.19.55.199", "src_port": 34169, "dest_port": 40004}}'); INSERT INTO alerts VALUES(1848,1773054366.073162078,'{"timestamp": "2026-03-09T12:06:06.073162+0100", "flow_id": 1721605714863009, "event_type": "alert", "src_ip": "65.49.1.137", "src_port": 45094, "dest_ip": "134.19.55.199", "dest_port": 11443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:06:06.073162+0100", "src_ip": "65.49.1.137", "dest_ip": "134.19.55.199", "src_port": 45094, "dest_port": 11443}}'); INSERT INTO alerts VALUES(1849,1773054380.726785898,'{"timestamp": "2026-03-09T12:06:20.726786+0100", "flow_id": 1151201030489068, "event_type": "alert", "src_ip": "45.156.87.91", "src_port": 54038, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:06:20.726786+0100", "src_ip": "45.156.87.91", "dest_ip": "134.19.55.199", "src_port": 54038, "dest_port": 5555}}'); INSERT INTO alerts VALUES(1850,1773054399.537935019,'{"timestamp": "2026-03-09T12:06:39.537935+0100", "flow_id": 2028942402865691, "event_type": "alert", "src_ip": "64.62.197.68", "src_port": 36280, "dest_ip": "134.19.55.199", "dest_port": 33443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:06:39.537935+0100", "src_ip": "64.62.197.68", "dest_ip": "134.19.55.199", "src_port": 36280, "dest_port": 33443}}'); INSERT INTO alerts VALUES(1851,1773054408.435178996,'{"timestamp": "2026-03-09T12:06:48.435179+0100", "flow_id": 180233827451902, "event_type": "alert", "src_ip": "195.184.76.124", "src_port": 46379, "dest_ip": "134.19.55.199", "dest_port": 7000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:06:48.435179+0100", "src_ip": "195.184.76.124", "dest_ip": "134.19.55.199", "src_port": 46379, "dest_port": 7000}}'); INSERT INTO alerts VALUES(1852,1773054411.451179027,'{"timestamp": "2026-03-09T12:06:51.451179+0100", "flow_id": 1093377414944234, "event_type": "alert", "src_ip": "65.49.1.50", "src_port": 44263, "dest_ip": "134.19.55.199", "dest_port": 14443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:06:51.451179+0100", "src_ip": "65.49.1.50", "dest_ip": "134.19.55.199", "src_port": 44263, "dest_port": 14443}}'); INSERT INTO alerts VALUES(1853,1773054416.294599057,'{"timestamp": "2026-03-09T12:06:56.294599+0100", "flow_id": 139396931855680, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 5443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:06:56.294599+0100", "src_ip": "204.76.203.73", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 5443}}'); INSERT INTO alerts VALUES(1854,1773054416.294599057,'{"timestamp": "2026-03-09T12:06:56.294599+0100", "flow_id": 139396931855680, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 5443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:06:56.294599+0100", "src_ip": "204.76.203.73", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 5443}}'); INSERT INTO alerts VALUES(1855,1773054430.33140111,'{"timestamp": "2026-03-09T12:07:10.331401+0100", "flow_id": 1704833203320250, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 37801, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9176, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:07:10.331401+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 37801, "dest_port": 53}}'); INSERT INTO alerts VALUES(1856,1773054430.332340956,'{"timestamp": "2026-03-09T12:07:10.332341+0100", "flow_id": 1708871326869297, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 58976, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59623, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:07:10.332341+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 58976, "dest_port": 53}}'); INSERT INTO alerts VALUES(1857,1773054488.4632051,'{"timestamp": "2026-03-09T12:08:08.463205+0100", "flow_id": 19126036316893, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 58749, "dest_ip": "134.19.55.199", "dest_port": 2375, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:08:08.463205+0100", "src_ip": "193.142.146.230", "dest_ip": "134.19.55.199", "src_port": 58749, "dest_port": 2375}}'); INSERT INTO alerts VALUES(1858,1773054494.317073107,'{"timestamp": "2026-03-09T12:08:14.317073+0100", "flow_id": 1924771500836930, "event_type": "alert", "src_ip": "88.210.63.191", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 4000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:08:14.317073+0100", "src_ip": "88.210.63.191", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 4000}}'); INSERT INTO alerts VALUES(1859,1773054515.968307018,'{"timestamp": "2026-03-09T12:08:35.968307+0100", "flow_id": 1062626393197989, "event_type": "alert", "src_ip": "176.65.139.46", "src_port": 55353, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:08:35.968307+0100", "src_ip": "176.65.139.46", "dest_ip": "134.19.55.199", "src_port": 55353, "dest_port": 8080}}'); INSERT INTO alerts VALUES(1860,1773054526.544164896,'{"timestamp": "2026-03-09T12:08:46.544165+0100", "flow_id": 1774221077151159, "event_type": "alert", "src_ip": "88.210.63.193", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:08:46.544165+0100", "src_ip": "88.210.63.193", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 22}}'); INSERT INTO alerts VALUES(1861,1773054570.527811051,'{"timestamp": "2026-03-09T12:09:30.527811+0100", "flow_id": 578082552462606, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49551, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39369, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:09:30.527811+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49551, "dest_port": 53}}'); INSERT INTO alerts VALUES(1862,1773054570.527811051,'{"timestamp": "2026-03-09T12:09:30.527811+0100", "flow_id": 578082932010889, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 55722, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53970, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:09:30.527811+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 55722, "dest_port": 53}}'); INSERT INTO alerts VALUES(1863,1773054570.709961892,'{"timestamp": "2026-03-09T12:09:30.709962+0100", "flow_id": 797464708400476, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 12882, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:09:30.709962+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 12882}}'); INSERT INTO alerts VALUES(1864,1773054642.368019105,'{"timestamp": "2026-03-09T12:10:42.368019+0100", "flow_id": 736204740505366, "event_type": "alert", "src_ip": "64.62.197.57", "src_port": 36721, "dest_ip": "134.19.55.199", "dest_port": 12654, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:10:42.368019+0100", "src_ip": "64.62.197.57", "dest_ip": "134.19.55.199", "src_port": 36721, "dest_port": 12654}}'); INSERT INTO alerts VALUES(1865,1773054643.994036913,'{"timestamp": "2026-03-09T12:10:43.994037+0100", "flow_id": 891660461647436, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 35104, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:10:43.994037+0100", "src_ip": "87.121.84.57", "dest_ip": "134.19.55.199", "src_port": 35104, "dest_port": 8080}}'); INSERT INTO alerts VALUES(1866,1773054651.245398999,'{"timestamp": "2026-03-09T12:10:51.245399+0100", "flow_id": 1053981785393499, "event_type": "alert", "src_ip": "65.49.1.238", "src_port": 38406, "dest_ip": "134.19.55.199", "dest_port": 12654, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:10:51.245399+0100", "src_ip": "65.49.1.238", "dest_ip": "134.19.55.199", "src_port": 38406, "dest_port": 12654}}'); INSERT INTO alerts VALUES(1867,1773054676.659837007,'{"timestamp": "2026-03-09T12:11:16.659837+0100", "flow_id": 1145132456953556, "event_type": "alert", "src_ip": "172.94.9.6", "src_port": 36870, "dest_ip": "134.19.55.199", "dest_port": 110, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400031, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 32", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:11:16.659837+0100", "src_ip": "172.94.9.6", "dest_ip": "134.19.55.199", "src_port": 36870, "dest_port": 110}}'); INSERT INTO alerts VALUES(1868,1773054710.585968018,'{"timestamp": "2026-03-09T12:11:50.585968+0100", "flow_id": 1953765489094434, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60098, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18229, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:11:50.585968+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60098, "dest_port": 53}}'); INSERT INTO alerts VALUES(1869,1773054710.585968971,'{"timestamp": "2026-03-09T12:11:50.585969+0100", "flow_id": 1953771082683656, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40792, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61316, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:11:50.585969+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40792, "dest_port": 53}}'); INSERT INTO alerts VALUES(1870,1773054775.243752957,'{"timestamp": "2026-03-09T12:12:55.243753+0100", "flow_id": 2172812529935774, "event_type": "alert", "src_ip": "64.89.160.135", "src_port": 58000, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:12:55.243753+0100", "src_ip": "64.89.160.135", "dest_ip": "134.19.55.199", "src_port": 58000, "dest_port": 22}}'); INSERT INTO alerts VALUES(1871,1773054795.81895399,'{"timestamp": "2026-03-09T12:13:15.818954+0100", "flow_id": 984105976372767, "event_type": "alert", "src_ip": "91.196.152.164", "src_port": 32680, "dest_ip": "134.19.55.199", "dest_port": 1701, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:13:15.818954+0100", "src_ip": "91.196.152.164", "dest_ip": "134.19.55.199", "src_port": 32680, "dest_port": 1701}}'); INSERT INTO alerts VALUES(1872,1773054808.998775006,'{"timestamp": "2026-03-09T12:13:28.998775+0100", "flow_id": 67583081274158, "event_type": "alert", "src_ip": "65.49.1.21", "src_port": 30669, "dest_ip": "134.19.55.199", "dest_port": 37, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-09T12:13:28.998775+0100", "src_ip": "65.49.1.21", "dest_ip": "134.19.55.199", "src_port": 30669, "dest_port": 37}}'); INSERT INTO alerts VALUES(1873,1773054818.344679118,'{"timestamp": "2026-03-09T12:13:38.344679+0100", "flow_id": 635961408700478, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 53946, "dest_ip": "134.19.55.199", "dest_port": 5165, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:13:38.344679+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 53946, "dest_port": 5165}}'); INSERT INTO alerts VALUES(1874,1773054819.224076032,'{"timestamp": "2026-03-09T12:13:39.224076+0100", "flow_id": 962401739336007, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42340, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48540, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T12:13:39.224076+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42340, "dest_port": 53}}'); INSERT INTO alerts VALUES(1875,1773054819.224545002,'{"timestamp": "2026-03-09T12:13:39.224545+0100", "flow_id": 964416580311374, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43524, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57322, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T12:13:39.224545+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43524, "dest_port": 53}}'); INSERT INTO alerts VALUES(1876,1773054819.224545002,'{"timestamp": "2026-03-09T12:13:39.224545+0100", "flow_id": 964416143680168, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46557, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25446, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T12:13:39.224545+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46557, "dest_port": 53}}'); INSERT INTO alerts VALUES(1877,1773054850.663024902,'{"timestamp": "2026-03-09T12:14:10.663025+0100", "flow_id": 595872946576121, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 56679, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19368, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:14:10.663025+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 56679, "dest_port": 53}}'); INSERT INTO alerts VALUES(1878,1773054850.663026095,'{"timestamp": "2026-03-09T12:14:10.663026+0100", "flow_id": 595878203001972, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59971, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9771, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:14:10.663026+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59971, "dest_port": 53}}'); INSERT INTO alerts VALUES(1879,1773054860.778809071,'{"timestamp": "2026-03-09T12:14:20.778809+0100", "flow_id": 1374638141205167, "event_type": "alert", "src_ip": "209.141.53.162", "src_port": 50683, "dest_ip": "134.19.55.199", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101616, "rev": 9, "signature": "GPL DNS named version attempt", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_07_26"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-09T12:14:20.778809+0100", "src_ip": "209.141.53.162", "dest_ip": "134.19.55.199", "src_port": 50683, "dest_port": 53}}'); INSERT INTO alerts VALUES(1880,1773054908.902682066,'{"timestamp": "2026-03-09T12:15:08.902682+0100", "flow_id": 1343719098350828, "event_type": "alert", "src_ip": "64.62.156.28", "src_port": 52795, "dest_ip": "134.19.55.199", "dest_port": 9060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:15:08.902682+0100", "src_ip": "64.62.156.28", "dest_ip": "134.19.55.199", "src_port": 52795, "dest_port": 9060}}'); INSERT INTO alerts VALUES(1881,1773054917.755266904,'{"timestamp": "2026-03-09T12:15:17.755267+0100", "flow_id": 1555000299911835, "event_type": "alert", "src_ip": "167.94.138.131", "src_port": 3449, "dest_ip": "134.19.55.199", "dest_port": 8089, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:15:17.755267+0100", "src_ip": "167.94.138.131", "dest_ip": "134.19.55.199", "src_port": 3449, "dest_port": 8089}}'); INSERT INTO alerts VALUES(1882,1773054990.732769967,'{"timestamp": "2026-03-09T12:16:30.732770+0100", "flow_id": 1739849192292205, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50765, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33295, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:16:30.732770+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50765, "dest_port": 53}}'); INSERT INTO alerts VALUES(1883,1773054990.732770919,'{"timestamp": "2026-03-09T12:16:30.732771+0100", "flow_id": 1739855740783749, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43388, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46390, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:16:30.732771+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43388, "dest_port": 53}}'); INSERT INTO alerts VALUES(1884,1773055020.768841028,'{"timestamp": "2026-03-09T12:17:00.768841+0100", "flow_id": 1331822734283107, "event_type": "alert", "src_ip": "64.62.197.116", "src_port": 54162, "dest_ip": "134.19.55.199", "dest_port": 7900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:17:00.768841+0100", "src_ip": "64.62.197.116", "dest_ip": "134.19.55.199", "src_port": 54162, "dest_port": 7900}}'); INSERT INTO alerts VALUES(1885,1773055025.790169954,'{"timestamp": "2026-03-09T12:17:05.790170+0100", "flow_id": 297533469764435, "event_type": "alert", "src_ip": "167.94.146.34", "src_port": 56757, "dest_ip": "134.19.55.199", "dest_port": 46785, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:17:05.790170+0100", "src_ip": "167.94.146.34", "dest_ip": "134.19.55.199", "src_port": 56757, "dest_port": 46785}}'); INSERT INTO alerts VALUES(1886,1773055070.833909989,'{"timestamp": "2026-03-09T12:17:50.833910+0100", "flow_id": 1892769670743377, "event_type": "alert", "src_ip": "177.70.2.220", "src_port": 35221, "dest_ip": "134.19.55.199", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2500018, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:17:50.833910+0100", "src_ip": "177.70.2.220", "dest_ip": "134.19.55.199", "src_port": 35221, "dest_port": 443}}'); INSERT INTO alerts VALUES(1887,1773055088.826188087,'{"timestamp": "2026-03-09T12:18:08.826188+0100", "flow_id": 170751084423483, "event_type": "alert", "src_ip": "91.196.152.37", "src_port": 48888, "dest_ip": "134.19.55.199", "dest_port": 20047, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:18:08.826188+0100", "src_ip": "91.196.152.37", "dest_ip": "134.19.55.199", "src_port": 48888, "dest_port": 20047}}'); INSERT INTO alerts VALUES(1888,1773055123.08761096,'{"timestamp": "2026-03-09T12:18:43.087611+0100", "flow_id": 939238198655977, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 49696, "dest_ip": "134.19.55.199", "dest_port": 10399, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:18:43.087611+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.55.199", "src_port": 49696, "dest_port": 10399}}'); INSERT INTO alerts VALUES(1889,1773055123.08761096,'{"timestamp": "2026-03-09T12:18:43.087611+0100", "flow_id": 939238198655977, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 49696, "dest_ip": "134.19.55.199", "dest_port": 10399, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:18:43.087611+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.55.199", "src_port": 49696, "dest_port": 10399}}'); INSERT INTO alerts VALUES(1890,1773055130.799025059,'{"timestamp": "2026-03-09T12:18:50.799025+0100", "flow_id": 617039785739017, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 58659, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60403, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:18:50.799025+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 58659, "dest_port": 53}}'); INSERT INTO alerts VALUES(1891,1773055130.799026012,'{"timestamp": "2026-03-09T12:18:50.799026+0100", "flow_id": 617042675494083, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 48080, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:18:50.799026+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 48080, "dest_port": 53}}'); INSERT INTO alerts VALUES(1892,1773055187.706504107,'{"timestamp": "2026-03-09T12:19:47.706504+0100", "flow_id": 1064089390154618, "event_type": "alert", "src_ip": "45.142.154.86", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 8865, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:19:47.706504+0100", "src_ip": "45.142.154.86", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 8865}}'); INSERT INTO alerts VALUES(1893,1773055200.931930066,'{"timestamp": "2026-03-09T12:20:00.931930+0100", "flow_id": 61959248655004, "event_type": "alert", "src_ip": "64.62.156.68", "src_port": 52791, "dest_ip": "134.19.55.199", "dest_port": 9593, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:20:00.931930+0100", "src_ip": "64.62.156.68", "dest_ip": "134.19.55.199", "src_port": 52791, "dest_port": 9593}}'); INSERT INTO alerts VALUES(1894,1773055203.269386053,'{"timestamp": "2026-03-09T12:20:03.269386+0100", "flow_id": 875530779074663, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 52653, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58235, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T12:20:03.269386+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 52653, "dest_port": 53}}'); INSERT INTO alerts VALUES(1895,1773055203.269686938,'{"timestamp": "2026-03-09T12:20:03.269687+0100", "flow_id": 876824577170494, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57983, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4137, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T12:20:03.269687+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57983, "dest_port": 53}}'); INSERT INTO alerts VALUES(1896,1773055203.269686938,'{"timestamp": "2026-03-09T12:20:03.269687+0100", "flow_id": 876824977867405, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33719, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45721, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T12:20:03.269687+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33719, "dest_port": 53}}'); INSERT INTO alerts VALUES(1897,1773055249.278254986,'{"timestamp": "2026-03-09T12:20:49.278255+0100", "flow_id": 350675084523103, "event_type": "alert", "src_ip": "64.62.156.229", "src_port": 52533, "dest_ip": "134.19.55.199", "dest_port": 20000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:20:49.278255+0100", "src_ip": "64.62.156.229", "dest_ip": "134.19.55.199", "src_port": 52533, "dest_port": 20000}}'); INSERT INTO alerts VALUES(1898,1773055266.700862885,'{"timestamp": "2026-03-09T12:21:06.700863+0100", "flow_id": 758385701593347, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 57202, "dest_ip": "134.19.55.199", "dest_port": 3442, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:21:06.700863+0100", "src_ip": "45.142.193.7", "dest_ip": "134.19.55.199", "src_port": 57202, "dest_port": 3442}}'); INSERT INTO alerts VALUES(1899,1773055365.78667903,'{"timestamp": "2026-03-09T12:22:45.786679+0100", "flow_id": 1408436660816301, "event_type": "alert", "src_ip": "91.224.92.177", "src_port": 43258, "dest_ip": "134.19.55.199", "dest_port": 4001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:22:45.786679+0100", "src_ip": "91.224.92.177", "dest_ip": "134.19.55.199", "src_port": 43258, "dest_port": 4001}}'); INSERT INTO alerts VALUES(1900,1773055397.354908943,'{"timestamp": "2026-03-09T12:23:17.354909+0100", "flow_id": 1524325140801658, "event_type": "alert", "src_ip": "167.94.138.100", "src_port": 31666, "dest_ip": "134.19.55.199", "dest_port": 9890, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:23:17.354909+0100", "src_ip": "167.94.138.100", "dest_ip": "134.19.55.199", "src_port": 31666, "dest_port": 9890}}'); INSERT INTO alerts VALUES(1901,1773055403.47142911,'{"timestamp": "2026-03-09T12:23:23.471429+0100", "flow_id": 898873441746602, "event_type": "alert", "src_ip": "167.94.146.46", "src_port": 19634, "dest_ip": "134.19.55.199", "dest_port": 37667, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:23:23.471429+0100", "src_ip": "167.94.146.46", "dest_ip": "134.19.55.199", "src_port": 19634, "dest_port": 37667}}'); INSERT INTO alerts VALUES(1902,1773055410.152617932,'{"timestamp": "2026-03-09T12:23:30.152618+0100", "flow_id": 655492676830318, "event_type": "alert", "src_ip": "79.124.62.53", "src_port": 44331, "dest_ip": "134.19.55.199", "dest_port": 3390, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:23:30.152618+0100", "src_ip": "79.124.62.53", "dest_ip": "134.19.55.199", "src_port": 44331, "dest_port": 3390}}'); INSERT INTO alerts VALUES(1903,1773055430.519668103,'{"timestamp": "2026-03-09T12:23:50.519668+0100", "flow_id": 1950483495243201, "event_type": "alert", "src_ip": "167.94.138.150", "src_port": 26889, "dest_ip": "134.19.55.199", "dest_port": 2087, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:23:50.519668+0100", "src_ip": "167.94.138.150", "dest_ip": "134.19.55.199", "src_port": 26889, "dest_port": 2087}}'); INSERT INTO alerts VALUES(1904,1773055458.353045941,'{"timestamp": "2026-03-09T12:24:18.353046+0100", "flow_id": 671896600530362, "event_type": "alert", "src_ip": "167.94.138.103", "src_port": 52348, "dest_ip": "134.19.55.199", "dest_port": 62670, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:24:18.353046+0100", "src_ip": "167.94.138.103", "dest_ip": "134.19.55.199", "src_port": 52348, "dest_port": 62670}}'); INSERT INTO alerts VALUES(1905,1773055470.051871061,'{"timestamp": "2026-03-09T12:24:30.051871+0100", "flow_id": 1911637752585371, "event_type": "alert", "src_ip": "167.94.138.151", "src_port": 41191, "dest_ip": "134.19.55.199", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:24:30.051871+0100", "src_ip": "167.94.138.151", "dest_ip": "134.19.55.199", "src_port": 41191, "dest_port": 8088}}'); INSERT INTO alerts VALUES(1906,1773055541.429800987,'{"timestamp": "2026-03-09T12:25:41.429801+0100", "flow_id": 1564510226151621, "event_type": "alert", "src_ip": "176.65.149.180", "src_port": 59116, "dest_ip": "134.19.55.199", "dest_port": 8265, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:25:41.429801+0100", "src_ip": "176.65.149.180", "dest_ip": "134.19.55.199", "src_port": 59116, "dest_port": 8265}}'); INSERT INTO alerts VALUES(1907,1773055545.356668949,'{"timestamp": "2026-03-09T12:25:45.356669+0100", "flow_id": 405985302558140, "event_type": "alert", "src_ip": "167.94.138.129", "src_port": 52427, "dest_ip": "134.19.55.199", "dest_port": 5938, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:25:45.356669+0100", "src_ip": "167.94.138.129", "dest_ip": "134.19.55.199", "src_port": 52427, "dest_port": 5938}}'); INSERT INTO alerts VALUES(1908,1773055564.880234957,'{"timestamp": "2026-03-09T12:26:04.880235+0100", "flow_id": 1247309004147676, "event_type": "alert", "src_ip": "65.49.1.159", "src_port": 44468, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:26:04.880235+0100", "src_ip": "65.49.1.159", "dest_ip": "134.19.55.199", "src_port": 44468, "dest_port": 8080}}'); INSERT INTO alerts VALUES(1909,1773055609.058306932,'{"timestamp": "2026-03-09T12:26:49.058307+0100", "flow_id": 531904516799131, "event_type": "alert", "src_ip": "64.62.197.109", "src_port": 52467, "dest_ip": "134.19.55.199", "dest_port": 6001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:26:49.058307+0100", "src_ip": "64.62.197.109", "dest_ip": "134.19.55.199", "src_port": 52467, "dest_port": 6001}}'); INSERT INTO alerts VALUES(1910,1773055705.126470089,'{"timestamp": "2026-03-09T12:28:25.126470+0100", "flow_id": 543188391297621, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 59389, "dest_ip": "134.19.55.199", "dest_port": 6060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:28:25.126470+0100", "src_ip": "79.124.40.82", "dest_ip": "134.19.55.199", "src_port": 59389, "dest_port": 6060}}'); INSERT INTO alerts VALUES(1911,1773055802.32884097,'{"timestamp": "2026-03-09T12:30:02.328841+0100", "flow_id": 567936861735223, "event_type": "alert", "src_ip": "178.62.87.89", "src_port": 35406, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:30:02.328841+0100", "src_ip": "178.62.87.89", "dest_ip": "134.19.55.199", "src_port": 35406, "dest_port": 5432}}'); INSERT INTO alerts VALUES(1912,1773055803.328660011,'{"timestamp": "2026-03-09T12:30:03.328660+0100", "flow_id": 567936861735223, "event_type": "alert", "src_ip": "178.62.87.89", "src_port": 35406, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 120, "bytes_toclient": 0, "start": "2026-03-09T12:30:02.328841+0100", "src_ip": "178.62.87.89", "dest_ip": "134.19.55.199", "src_port": 35406, "dest_port": 5432}}'); INSERT INTO alerts VALUES(1913,1773055908.576206922,'{"timestamp": "2026-03-09T12:31:48.576207+0100", "flow_id": 1348891051887653, "event_type": "alert", "src_ip": "176.65.149.76", "src_port": 55575, "dest_ip": "134.19.55.199", "dest_port": 8070, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:31:48.576207+0100", "src_ip": "176.65.149.76", "dest_ip": "134.19.55.199", "src_port": 55575, "dest_port": 8070}}'); INSERT INTO alerts VALUES(1914,1773055908.956743955,'{"timestamp": "2026-03-09T12:31:48.956744+0100", "flow_id": 1294438337415127, "event_type": "alert", "src_ip": "176.65.149.194", "src_port": 48498, "dest_ip": "134.19.55.199", "dest_port": 5005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:31:48.956744+0100", "src_ip": "176.65.149.194", "dest_ip": "134.19.55.199", "src_port": 48498, "dest_port": 5005}}'); INSERT INTO alerts VALUES(1915,1773055917.925342083,'{"timestamp": "2026-03-09T12:31:57.925342+0100", "flow_id": 1441038871776761, "event_type": "alert", "src_ip": "64.62.197.46", "src_port": 47729, "dest_ip": "134.19.55.199", "dest_port": 24056, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:31:57.925342+0100", "src_ip": "64.62.197.46", "dest_ip": "134.19.55.199", "src_port": 47729, "dest_port": 24056}}'); INSERT INTO alerts VALUES(1916,1773056045.693222046,'{"timestamp": "2026-03-09T12:34:05.693222+0100", "flow_id": 1569993156802308, "event_type": "alert", "src_ip": "66.132.153.147", "src_port": 46476, "dest_ip": "134.19.55.199", "dest_port": 1963, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:34:05.693222+0100", "src_ip": "66.132.153.147", "dest_ip": "134.19.55.199", "src_port": 46476, "dest_port": 1963}}'); INSERT INTO alerts VALUES(1917,1773056084.898264884,'{"timestamp": "2026-03-09T12:34:44.898265+0100", "flow_id": 1324746533070658, "event_type": "alert", "src_ip": "109.123.250.12", "src_port": 58970, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:34:44.898265+0100", "src_ip": "109.123.250.12", "dest_ip": "134.19.55.199", "src_port": 58970, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1918,1773056153.169653893,'{"timestamp": "2026-03-09T12:35:53.169654+0100", "flow_id": 447186100760843, "event_type": "alert", "src_ip": "167.94.146.41", "src_port": 8960, "dest_ip": "134.19.55.199", "dest_port": 34049, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:35:53.169654+0100", "src_ip": "167.94.146.41", "dest_ip": "134.19.55.199", "src_port": 8960, "dest_port": 34049}}'); INSERT INTO alerts VALUES(1919,1773056169.644619942,'{"timestamp": "2026-03-09T12:36:09.644620+0100", "flow_id": 516825619300880, "event_type": "alert", "src_ip": "66.132.153.156", "src_port": 28651, "dest_ip": "134.19.55.199", "dest_port": 832, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:36:09.644620+0100", "src_ip": "66.132.153.156", "dest_ip": "134.19.55.199", "src_port": 28651, "dest_port": 832}}'); INSERT INTO alerts VALUES(1920,1773056174.993212938,'{"timestamp": "2026-03-09T12:36:14.993213+0100", "flow_id": 1732543598411086, "event_type": "alert", "src_ip": "195.184.76.223", "src_port": 23134, "dest_ip": "134.19.55.199", "dest_port": 5197, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:36:14.993213+0100", "src_ip": "195.184.76.223", "dest_ip": "134.19.55.199", "src_port": 23134, "dest_port": 5197}}'); INSERT INTO alerts VALUES(1921,1773056373.879057885,'{"timestamp": "2026-03-09T12:39:33.879058+0100", "flow_id": 1523727192274561, "event_type": "alert", "src_ip": "193.163.125.206", "src_port": 39998, "dest_ip": "134.19.55.199", "dest_port": 3138, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:39:33.879058+0100", "src_ip": "193.163.125.206", "dest_ip": "134.19.55.199", "src_port": 39998, "dest_port": 3138}}'); INSERT INTO alerts VALUES(1922,1773056397.740523099,'{"timestamp": "2026-03-09T12:39:57.740523+0100", "flow_id": 1491674860609510, "event_type": "alert", "src_ip": "5.135.94.29", "src_port": 5118, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 430, "bytes_toclient": 0, "start": "2026-03-09T12:39:57.740523+0100", "src_ip": "5.135.94.29", "dest_ip": "134.19.55.199", "src_port": 5118, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1923,1773056452.2497859,'{"timestamp": "2026-03-09T12:40:52.249786+0100", "flow_id": 1354297980705443, "event_type": "alert", "src_ip": "64.62.156.13", "src_port": 30830, "dest_ip": "134.19.55.199", "dest_port": 5683, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 32, "bytes_toclient": 0, "start": "2026-03-09T12:40:52.249786+0100", "src_ip": "64.62.156.13", "dest_ip": "134.19.55.199", "src_port": 30830, "dest_port": 5683}}'); INSERT INTO alerts VALUES(1924,1773056520.423598052,'{"timestamp": "2026-03-09T12:42:00.423598+0100", "flow_id": 130493593598085, "event_type": "alert", "src_ip": "64.89.163.142", "src_port": 56346, "dest_ip": "134.19.55.199", "dest_port": 3307, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:42:00.423598+0100", "src_ip": "64.89.163.142", "dest_ip": "134.19.55.199", "src_port": 56346, "dest_port": 3307}}'); INSERT INTO alerts VALUES(1925,1773056539.679240943,'{"timestamp": "2026-03-09T12:42:19.679241+0100", "flow_id": 946994328434342, "event_type": "alert", "src_ip": "193.163.125.191", "src_port": 38529, "dest_ip": "134.19.55.199", "dest_port": 1522, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:42:19.679241+0100", "src_ip": "193.163.125.191", "dest_ip": "134.19.55.199", "src_port": 38529, "dest_port": 1522}}'); INSERT INTO alerts VALUES(1926,1773056680.370282889,'{"timestamp": "2026-03-09T12:44:40.370283+0100", "flow_id": 182979398895234, "event_type": "alert", "src_ip": "185.242.3.196", "src_port": 34107, "dest_ip": "134.19.55.199", "dest_port": 4096, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:44:40.370283+0100", "src_ip": "185.242.3.196", "dest_ip": "134.19.55.199", "src_port": 34107, "dest_port": 4096}}'); INSERT INTO alerts VALUES(1927,1773056807.78784895,'{"timestamp": "2026-03-09T12:46:47.787849+0100", "flow_id": 1976410996929502, "event_type": "alert", "src_ip": "193.163.125.204", "src_port": 56173, "dest_ip": "134.19.55.199", "dest_port": 49172, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:46:47.787849+0100", "src_ip": "193.163.125.204", "dest_ip": "134.19.55.199", "src_port": 56173, "dest_port": 49172}}'); INSERT INTO alerts VALUES(1928,1773056829.062226058,'{"timestamp": "2026-03-09T12:47:09.062226+0100", "flow_id": 1674634671048642, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 56463, "dest_ip": "134.19.55.199", "dest_port": 11000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:47:09.062226+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 56463, "dest_port": 11000}}'); INSERT INTO alerts VALUES(1929,1773056829.062226058,'{"timestamp": "2026-03-09T12:47:09.062226+0100", "flow_id": 1674634671048642, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 56463, "dest_ip": "134.19.55.199", "dest_port": 11000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:47:09.062226+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 56463, "dest_port": 11000}}'); INSERT INTO alerts VALUES(1930,1773056854.407788992,'{"timestamp": "2026-03-09T12:47:34.407789+0100", "flow_id": 1751441964501941, "event_type": "alert", "src_ip": "64.62.197.74", "src_port": 55745, "dest_ip": "134.19.55.199", "dest_port": 49669, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:47:34.407789+0100", "src_ip": "64.62.197.74", "dest_ip": "134.19.55.199", "src_port": 55745, "dest_port": 49669}}'); INSERT INTO alerts VALUES(1931,1773056893.72439003,'{"timestamp": "2026-03-09T12:48:13.724390+0100", "flow_id": 1422384114699044, "event_type": "alert", "src_ip": "198.143.149.250", "src_port": 12203, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 434, "bytes_toclient": 0, "start": "2026-03-09T12:48:13.724390+0100", "src_ip": "198.143.149.250", "dest_ip": "134.19.55.199", "src_port": 12203, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1932,1773056893.72439003,'{"timestamp": "2026-03-09T12:48:13.724390+0100", "flow_id": 1422384114699044, "event_type": "alert", "src_ip": "198.143.149.250", "src_port": 12203, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 434, "bytes_toclient": 0, "start": "2026-03-09T12:48:13.724390+0100", "src_ip": "198.143.149.250", "dest_ip": "134.19.55.199", "src_port": 12203, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1933,1773056938.190857888,'{"timestamp": "2026-03-09T12:48:58.190858+0100", "flow_id": 819732900877515, "event_type": "alert", "src_ip": "167.94.138.133", "src_port": 2236, "dest_ip": "134.19.55.199", "dest_port": 47808, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 45, "bytes_toclient": 0, "start": "2026-03-09T12:48:58.190858+0100", "src_ip": "167.94.138.133", "dest_ip": "134.19.55.199", "src_port": 2236, "dest_port": 47808}}'); INSERT INTO alerts VALUES(1934,1773056954.834173918,'{"timestamp": "2026-03-09T12:49:14.834174+0100", "flow_id": 768002844570864, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 35358, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8707, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:49:14.834174+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 35358, "dest_port": 53}}'); INSERT INTO alerts VALUES(1935,1773056954.834438086,'{"timestamp": "2026-03-09T12:49:14.834438+0100", "flow_id": 769138297131494, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50617, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46026, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:49:14.834438+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50617, "dest_port": 53}}'); INSERT INTO alerts VALUES(1936,1773056987.132555962,'{"timestamp": "2026-03-09T12:49:47.132556+0100", "flow_id": 850798822789159, "event_type": "alert", "src_ip": "167.94.138.145", "src_port": 62478, "dest_ip": "134.19.55.199", "dest_port": 500, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ike", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 364, "bytes_toclient": 0, "start": "2026-03-09T12:49:47.132556+0100", "src_ip": "167.94.138.145", "dest_ip": "134.19.55.199", "src_port": 62478, "dest_port": 500}}'); INSERT INTO alerts VALUES(1937,1773057059.479758978,'{"timestamp": "2026-03-09T12:50:59.479759+0100", "flow_id": 934652056196293, "event_type": "alert", "src_ip": "91.196.152.181", "src_port": 6465, "dest_ip": "134.19.55.199", "dest_port": 21000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:50:59.479759+0100", "src_ip": "91.196.152.181", "dest_ip": "134.19.55.199", "src_port": 6465, "dest_port": 21000}}'); INSERT INTO alerts VALUES(1938,1773057094.892642975,'{"timestamp": "2026-03-09T12:51:34.892643+0100", "flow_id": 1863548772027154, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42245, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50784, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:51:34.892643+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42245, "dest_port": 53}}'); INSERT INTO alerts VALUES(1939,1773057094.892642975,'{"timestamp": "2026-03-09T12:51:34.892643+0100", "flow_id": 1863547897643252, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33165, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8892, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T12:51:34.892643+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33165, "dest_port": 53}}'); INSERT INTO alerts VALUES(1940,1773057187.59276104,'{"timestamp": "2026-03-09T12:53:07.592761+0100", "flow_id": 857042407624706, "event_type": "alert", "src_ip": "64.62.197.47", "src_port": 27636, "dest_ip": "134.19.55.199", "dest_port": 2152, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:53:07.592761+0100", "src_ip": "64.62.197.47", "dest_ip": "134.19.55.199", "src_port": 27636, "dest_port": 2152}}'); INSERT INTO alerts VALUES(1941,1773057209.966610909,'{"timestamp": "2026-03-09T12:53:29.966611+0100", "flow_id": 492391976765340, "event_type": "alert", "src_ip": "167.94.146.35", "src_port": 61028, "dest_ip": "134.19.55.199", "dest_port": 29268, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:53:29.966611+0100", "src_ip": "167.94.146.35", "dest_ip": "134.19.55.199", "src_port": 61028, "dest_port": 29268}}'); INSERT INTO alerts VALUES(1942,1773057233.302345991,'{"timestamp": "2026-03-09T12:53:53.302346+0100", "flow_id": 454144197418223, "event_type": "alert", "src_ip": "167.94.145.22", "src_port": 25419, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T12:53:53.302346+0100", "src_ip": "167.94.145.22", "dest_ip": "134.19.55.199", "src_port": 25419, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1943,1773057253.912406922,'{"timestamp": "2026-03-09T12:54:13.912407+0100", "flow_id": 1666960878464761, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 53112, "dest_ip": "134.19.55.199", "dest_port": 4530, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:54:13.912407+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 53112, "dest_port": 4530}}'); INSERT INTO alerts VALUES(1944,1773057267.937963008,'{"timestamp": "2026-03-09T12:54:27.937963+0100", "flow_id": 932296382825115, "event_type": "alert", "src_ip": "185.156.73.180", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 14430, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:54:27.937963+0100", "src_ip": "185.156.73.180", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 14430}}'); INSERT INTO alerts VALUES(1945,1773057325.681243897,'{"timestamp": "2026-03-09T12:55:25.681244+0100", "flow_id": 1518549355595660, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 7878, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:55:25.681244+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 7878}}'); INSERT INTO alerts VALUES(1946,1773057325.681243897,'{"timestamp": "2026-03-09T12:55:25.681244+0100", "flow_id": 1518549355595660, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 7878, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:55:25.681244+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 7878}}'); INSERT INTO alerts VALUES(1947,1773057441.370500088,'{"timestamp": "2026-03-09T12:57:21.370500+0100", "flow_id": 465389475350238, "event_type": "alert", "src_ip": "193.163.125.203", "src_port": 51898, "dest_ip": "134.19.55.199", "dest_port": 50996, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T12:57:21.370500+0100", "src_ip": "193.163.125.203", "dest_ip": "134.19.55.199", "src_port": 51898, "dest_port": 50996}}'); INSERT INTO alerts VALUES(1948,1773057508.795098067,'{"timestamp": "2026-03-09T12:58:28.795098+0100", "flow_id": 1163123548983255, "event_type": "alert", "src_ip": "167.94.138.167", "src_port": 9284, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 290, "bytes_toclient": 0, "start": "2026-03-09T12:58:28.795098+0100", "src_ip": "167.94.138.167", "dest_ip": "134.19.55.199", "src_port": 9284, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1949,1773057535.361695051,'{"timestamp": "2026-03-09T12:58:55.361695+0100", "flow_id": 2116420699737879, "event_type": "alert", "src_ip": "64.62.156.89", "src_port": 59281, "dest_ip": "134.19.55.199", "dest_port": 5901, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T12:58:55.361695+0100", "src_ip": "64.62.156.89", "dest_ip": "134.19.55.199", "src_port": 59281, "dest_port": 5901}}'); INSERT INTO alerts VALUES(1950,1773057629.54797697,'{"timestamp": "2026-03-09T13:00:29.547977+0100", "flow_id": 1509119098983443, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 3004, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:00:29.547977+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 3004}}'); INSERT INTO alerts VALUES(1951,1773057629.54797697,'{"timestamp": "2026-03-09T13:00:29.547977+0100", "flow_id": 1509119098983443, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 3004, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:00:29.547977+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 3004}}'); INSERT INTO alerts VALUES(1952,1773057821.115458012,'{"timestamp": "2026-03-09T13:03:41.115458+0100", "flow_id": 1621788801122217, "event_type": "alert", "src_ip": "167.94.146.39", "src_port": 24100, "dest_ip": "134.19.55.199", "dest_port": 52954, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:03:41.115458+0100", "src_ip": "167.94.146.39", "dest_ip": "134.19.55.199", "src_port": 24100, "dest_port": 52954}}'); INSERT INTO alerts VALUES(1953,1773057827.268202066,'{"timestamp": "2026-03-09T13:03:47.268202+0100", "flow_id": 870445100299001, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 56011, "dest_ip": "134.19.55.199", "dest_port": 50840, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:03:47.268202+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 56011, "dest_port": 50840}}'); INSERT INTO alerts VALUES(1954,1773057924.217677116,'{"timestamp": "2026-03-09T13:05:24.217677+0100", "flow_id": 1216390766823145, "event_type": "alert", "src_ip": "65.49.1.122", "src_port": 54559, "dest_ip": "134.19.55.199", "dest_port": 49152, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:05:24.217677+0100", "src_ip": "65.49.1.122", "dest_ip": "134.19.55.199", "src_port": 54559, "dest_port": 49152}}'); INSERT INTO alerts VALUES(1955,1773057952.824521064,'{"timestamp": "2026-03-09T13:05:52.824521+0100", "flow_id": 163595176722392, "event_type": "alert", "src_ip": "65.49.1.207", "src_port": 58332, "dest_ip": "134.19.55.199", "dest_port": 53282, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:05:52.824521+0100", "src_ip": "65.49.1.207", "dest_ip": "134.19.55.199", "src_port": 58332, "dest_port": 53282}}'); INSERT INTO alerts VALUES(1956,1773057953.454735994,'{"timestamp": "2026-03-09T13:05:53.454736+0100", "flow_id": 545703099099199, "event_type": "alert", "src_ip": "192.109.200.81", "src_port": 41543, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400037, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 38", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T13:05:53.454736+0100", "src_ip": "192.109.200.81", "dest_ip": "134.19.55.199", "src_port": 41543, "dest_port": 3000}}'); INSERT INTO alerts VALUES(1957,1773058026.684968949,'{"timestamp": "2026-03-09T13:07:06.684969+0100", "flow_id": 690120381167484, "event_type": "alert", "src_ip": "167.94.138.158", "src_port": 20965, "dest_ip": "134.19.55.199", "dest_port": 17184, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 92, "bytes_toclient": 0, "start": "2026-03-09T13:07:06.684969+0100", "src_ip": "167.94.138.158", "dest_ip": "134.19.55.199", "src_port": 20965, "dest_port": 17184}}'); INSERT INTO alerts VALUES(1958,1773058030.888895034,'{"timestamp": "2026-03-09T13:07:10.888895+0100", "flow_id": 1847451152383918, "event_type": "alert", "src_ip": "64.62.156.179", "src_port": 60151, "dest_ip": "134.19.55.199", "dest_port": 830, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:07:10.888895+0100", "src_ip": "64.62.156.179", "dest_ip": "134.19.55.199", "src_port": 60151, "dest_port": 830}}'); INSERT INTO alerts VALUES(1959,1773058103.300693035,'{"timestamp": "2026-03-09T13:08:23.300693+0100", "flow_id": 2135893093567027, "event_type": "alert", "src_ip": "176.65.148.150", "src_port": 40707, "dest_ip": "134.19.55.199", "dest_port": 6060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:08:23.300693+0100", "src_ip": "176.65.148.150", "dest_ip": "134.19.55.199", "src_port": 40707, "dest_port": 6060}}'); INSERT INTO alerts VALUES(1960,1773058103.300693035,'{"timestamp": "2026-03-09T13:08:23.300693+0100", "flow_id": 2135893093567027, "event_type": "alert", "src_ip": "176.65.148.150", "src_port": 40707, "dest_ip": "134.19.55.199", "dest_port": 6060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:08:23.300693+0100", "src_ip": "176.65.148.150", "dest_ip": "134.19.55.199", "src_port": 40707, "dest_port": 6060}}'); INSERT INTO alerts VALUES(1961,1773058144.083278894,'{"timestamp": "2026-03-09T13:09:04.083279+0100", "flow_id": 76207682790413, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 62000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:09:04.083279+0100", "src_ip": "185.156.73.181", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 62000}}'); INSERT INTO alerts VALUES(1962,1773058190.023242951,'{"timestamp": "2026-03-09T13:09:50.023243+0100", "flow_id": 1788677815289799, "event_type": "alert", "src_ip": "195.184.76.217", "src_port": 32247, "dest_ip": "134.19.55.199", "dest_port": 5203, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:09:50.023243+0100", "src_ip": "195.184.76.217", "dest_ip": "134.19.55.199", "src_port": 32247, "dest_port": 5203}}'); INSERT INTO alerts VALUES(1963,1773058201.683161021,'{"timestamp": "2026-03-09T13:10:01.683161+0100", "flow_id": 400880712840937, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 13919, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:10:01.683161+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 13919}}'); INSERT INTO alerts VALUES(1964,1773058264.853189945,'{"timestamp": "2026-03-09T13:11:04.853190+0100", "flow_id": 5250484768948, "event_type": "alert", "src_ip": "64.62.197.96", "src_port": 56463, "dest_ip": "134.19.55.199", "dest_port": 500, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ike", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 220, "bytes_toclient": 0, "start": "2026-03-09T13:11:04.853190+0100", "src_ip": "64.62.197.96", "dest_ip": "134.19.55.199", "src_port": 56463, "dest_port": 500}}'); INSERT INTO alerts VALUES(1965,1773058285.621587991,'{"timestamp": "2026-03-09T13:11:25.621588+0100", "flow_id": 1543803806939451, "event_type": "alert", "src_ip": "91.196.152.84", "src_port": 12390, "dest_ip": "134.19.55.199", "dest_port": 3256, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:11:25.621588+0100", "src_ip": "91.196.152.84", "dest_ip": "134.19.55.199", "src_port": 12390, "dest_port": 3256}}'); INSERT INTO alerts VALUES(1966,1773058351.07198,'{"timestamp": "2026-03-09T13:12:31.071980+0100", "flow_id": 1998003732573256, "event_type": "alert", "src_ip": "185.242.226.93", "src_port": 60203, "dest_ip": "134.19.55.199", "dest_port": 20201, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:12:31.071980+0100", "src_ip": "185.242.226.93", "dest_ip": "134.19.55.199", "src_port": 60203, "dest_port": 20201}}'); INSERT INTO alerts VALUES(1967,1773058409.843255997,'{"timestamp": "2026-03-09T13:13:29.843256+0100", "flow_id": 525534186762774, "event_type": "alert", "src_ip": "167.94.146.43", "src_port": 51306, "dest_ip": "134.19.55.199", "dest_port": 17666, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:13:29.843256+0100", "src_ip": "167.94.146.43", "dest_ip": "134.19.55.199", "src_port": 51306, "dest_port": 17666}}'); INSERT INTO alerts VALUES(1968,1773058424.546869039,'{"timestamp": "2026-03-09T13:13:44.546869+0100", "flow_id": 96987943153804, "event_type": "alert", "src_ip": "101.0.104.38", "src_port": 5065, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 435, "bytes_toclient": 0, "start": "2026-03-09T13:13:44.546869+0100", "src_ip": "101.0.104.38", "dest_ip": "134.19.55.199", "src_port": 5065, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1969,1773058424.546869039,'{"timestamp": "2026-03-09T13:13:44.546869+0100", "flow_id": 96987943153804, "event_type": "alert", "src_ip": "101.0.104.38", "src_port": 5065, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 435, "bytes_toclient": 0, "start": "2026-03-09T13:13:44.546869+0100", "src_ip": "101.0.104.38", "dest_ip": "134.19.55.199", "src_port": 5065, "dest_port": 5060}}'); INSERT INTO alerts VALUES(1970,1773058477.178553104,'{"timestamp": "2026-03-09T13:14:37.178553+0100", "flow_id": 1611308081169684, "event_type": "alert", "src_ip": "178.20.210.151", "src_port": 58229, "dest_ip": "134.19.55.199", "dest_port": 9022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:14:37.178553+0100", "src_ip": "178.20.210.151", "dest_ip": "134.19.55.199", "src_port": 58229, "dest_port": 9022}}'); INSERT INTO alerts VALUES(1971,1773058487.92147994,'{"timestamp": "2026-03-09T13:14:47.921480+0100", "flow_id": 1987402198903693, "event_type": "alert", "src_ip": "91.196.152.76", "src_port": 1188, "dest_ip": "134.19.55.199", "dest_port": 20202, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:14:47.921480+0100", "src_ip": "91.196.152.76", "dest_ip": "134.19.55.199", "src_port": 1188, "dest_port": 20202}}'); INSERT INTO alerts VALUES(1972,1773058505.046456098,'{"timestamp": "2026-03-09T13:15:05.046456+0100", "flow_id": 481005264195512, "event_type": "alert", "src_ip": "88.210.63.190", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 24436, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:15:05.046456+0100", "src_ip": "88.210.63.190", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 24436}}'); INSERT INTO alerts VALUES(1973,1773058531.96499896,'{"timestamp": "2026-03-09T13:15:31.964999+0100", "flow_id": 1048416728532732, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 53946, "dest_ip": "134.19.55.199", "dest_port": 43038, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:15:31.964999+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 53946, "dest_port": 43038}}'); INSERT INTO alerts VALUES(1974,1773058539.641057969,'{"timestamp": "2026-03-09T13:15:39.641058+0100", "flow_id": 1064474935650420, "event_type": "alert", "src_ip": "125.74.215.47", "src_port": 39140, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:15:39.641058+0100", "src_ip": "125.74.215.47", "dest_ip": "134.19.55.199", "src_port": 39140, "dest_port": 5432}}'); INSERT INTO alerts VALUES(1975,1773058540.643112898,'{"timestamp": "2026-03-09T13:15:40.643113+0100", "flow_id": 1064474935650420, "event_type": "alert", "src_ip": "125.74.215.47", "src_port": 39140, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 120, "bytes_toclient": 0, "start": "2026-03-09T13:15:39.641058+0100", "src_ip": "125.74.215.47", "dest_ip": "134.19.55.199", "src_port": 39140, "dest_port": 5432}}'); INSERT INTO alerts VALUES(1976,1773058550.706612111,'{"timestamp": "2026-03-09T13:15:50.706612+0100", "flow_id": 1908975940341172, "event_type": "alert", "src_ip": "185.242.226.10", "src_port": 37650, "dest_ip": "134.19.55.199", "dest_port": 12110, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:15:50.706612+0100", "src_ip": "185.242.226.10", "dest_ip": "134.19.55.199", "src_port": 37650, "dest_port": 12110}}'); INSERT INTO alerts VALUES(1977,1773058598.703553915,'{"timestamp": "2026-03-09T13:16:38.703554+0100", "flow_id": 1895842933307629, "event_type": "alert", "src_ip": "176.65.148.243", "src_port": 47726, "dest_ip": "134.19.55.199", "dest_port": 19132, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 61, "bytes_toclient": 0, "start": "2026-03-09T13:16:38.703554+0100", "src_ip": "176.65.148.243", "dest_ip": "134.19.55.199", "src_port": 47726, "dest_port": 19132}}'); INSERT INTO alerts VALUES(1978,1773058598.703553915,'{"timestamp": "2026-03-09T13:16:38.703554+0100", "flow_id": 1895842933307629, "event_type": "alert", "src_ip": "176.65.148.243", "src_port": 47726, "dest_ip": "134.19.55.199", "dest_port": 19132, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 61, "bytes_toclient": 0, "start": "2026-03-09T13:16:38.703554+0100", "src_ip": "176.65.148.243", "dest_ip": "134.19.55.199", "src_port": 47726, "dest_port": 19132}}'); INSERT INTO alerts VALUES(1979,1773058600.158126115,'{"timestamp": "2026-03-09T13:16:40.158126+0100", "flow_id": 116198897200511, "event_type": "alert", "src_ip": "65.49.1.235", "src_port": 33812, "dest_ip": "134.19.55.199", "dest_port": 445, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:16:40.158126+0100", "src_ip": "65.49.1.235", "dest_ip": "134.19.55.199", "src_port": 33812, "dest_port": 445}}'); INSERT INTO alerts VALUES(1980,1773058603.378181934,'{"timestamp": "2026-03-09T13:16:43.378182+0100", "flow_id": 1061329715305808, "event_type": "alert", "src_ip": "64.62.156.74", "src_port": 48936, "dest_ip": "134.19.55.199", "dest_port": 623, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 51, "bytes_toclient": 0, "start": "2026-03-09T13:16:43.378182+0100", "src_ip": "64.62.156.74", "dest_ip": "134.19.55.199", "src_port": 48936, "dest_port": 623}}'); INSERT INTO alerts VALUES(1981,1773058614.165121078,'{"timestamp": "2026-03-09T13:16:54.165121+0100", "flow_id": 1835089354046476, "event_type": "alert", "src_ip": "167.94.138.106", "src_port": 38274, "dest_ip": "134.19.55.199", "dest_port": 27074, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:16:54.165121+0100", "src_ip": "167.94.138.106", "dest_ip": "134.19.55.199", "src_port": 38274, "dest_port": 27074}}'); INSERT INTO alerts VALUES(1982,1773058666.778072118,'{"timestamp": "2026-03-09T13:17:46.778072+0100", "flow_id": 808522302823793, "event_type": "alert", "src_ip": "182.10.97.218", "src_port": 1311, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T13:17:46.778072+0100", "src_ip": "182.10.97.218", "dest_ip": "134.19.55.199", "src_port": 1311, "dest_port": 1433}}'); INSERT INTO alerts VALUES(1983,1773058707.358598947,'{"timestamp": "2026-03-09T13:18:27.358599+0100", "flow_id": 977221776629908, "event_type": "alert", "src_ip": "176.65.132.93", "src_port": 58538, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:18:27.358599+0100", "src_ip": "176.65.132.93", "dest_ip": "134.19.55.199", "src_port": 58538, "dest_port": 27017}}'); INSERT INTO alerts VALUES(1984,1773058738.691514016,'{"timestamp": "2026-03-09T13:18:58.691514+0100", "flow_id": 718231970005553, "event_type": "alert", "src_ip": "66.132.153.159", "src_port": 62150, "dest_ip": "134.19.55.199", "dest_port": 5349, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 150, "bytes_toclient": 0, "start": "2026-03-09T13:18:58.691514+0100", "src_ip": "66.132.153.159", "dest_ip": "134.19.55.199", "src_port": 62150, "dest_port": 5349}}'); INSERT INTO alerts VALUES(1985,1773058742.621628999,'{"timestamp": "2026-03-09T13:19:02.621629+0100", "flow_id": 1825452193616251, "event_type": "alert", "src_ip": "65.49.1.150", "src_port": 52035, "dest_ip": "134.19.55.199", "dest_port": 789, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:19:02.621629+0100", "src_ip": "65.49.1.150", "dest_ip": "134.19.55.199", "src_port": 52035, "dest_port": 789}}'); INSERT INTO alerts VALUES(1986,1773058779.867777109,'{"timestamp": "2026-03-09T13:19:39.867777+0100", "flow_id": 912325419763754, "event_type": "alert", "src_ip": "64.62.156.136", "src_port": 58003, "dest_ip": "134.19.55.199", "dest_port": 1200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:19:39.867777+0100", "src_ip": "64.62.156.136", "dest_ip": "134.19.55.199", "src_port": 58003, "dest_port": 1200}}'); INSERT INTO alerts VALUES(1987,1773058813.192101002,'{"timestamp": "2026-03-09T13:20:13.192101+0100", "flow_id": 1669494785746668, "event_type": "alert", "src_ip": "65.49.1.95", "src_port": 52108, "dest_ip": "134.19.55.199", "dest_port": 1962, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:20:13.192101+0100", "src_ip": "65.49.1.95", "dest_ip": "134.19.55.199", "src_port": 52108, "dest_port": 1962}}'); INSERT INTO alerts VALUES(1988,1773058859.955015898,'{"timestamp": "2026-03-09T13:20:59.955016+0100", "flow_id": 1005540559452477, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 53528, "dest_ip": "134.19.55.199", "dest_port": 1337, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:20:59.955016+0100", "src_ip": "167.94.146.32", "dest_ip": "134.19.55.199", "src_port": 53528, "dest_port": 1337}}'); INSERT INTO alerts VALUES(1989,1773058909.00393796,'{"timestamp": "2026-03-09T13:21:49.003938+0100", "flow_id": 1424292678849816, "event_type": "alert", "src_ip": "64.62.156.92", "src_port": 39802, "dest_ip": "134.19.55.199", "dest_port": 2101, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:21:49.003938+0100", "src_ip": "64.62.156.92", "dest_ip": "134.19.55.199", "src_port": 39802, "dest_port": 2101}}'); INSERT INTO alerts VALUES(1990,1773058959.323859931,'{"timestamp": "2026-03-09T13:22:39.323860+0100", "flow_id": 2235394099972690, "event_type": "alert", "src_ip": "65.49.1.240", "src_port": 47388, "dest_ip": "134.19.55.199", "dest_port": 8873, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:22:39.323860+0100", "src_ip": "65.49.1.240", "dest_ip": "134.19.55.199", "src_port": 47388, "dest_port": 8873}}'); INSERT INTO alerts VALUES(1991,1773058979.016925097,'{"timestamp": "2026-03-09T13:22:59.016925+0100", "flow_id": 917120083255449, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 37491, "dest_ip": "134.19.55.199", "dest_port": 2376, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:22:59.016925+0100", "src_ip": "193.142.146.230", "dest_ip": "134.19.55.199", "src_port": 37491, "dest_port": 2376}}'); INSERT INTO alerts VALUES(1992,1773058979.120101928,'{"timestamp": "2026-03-09T13:22:59.120102+0100", "flow_id": 1078788049703367, "event_type": "alert", "src_ip": "193.163.125.200", "src_port": 44843, "dest_ip": "134.19.55.199", "dest_port": 61613, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:22:59.120102+0100", "src_ip": "193.163.125.200", "dest_ip": "134.19.55.199", "src_port": 44843, "dest_port": 61613}}'); INSERT INTO alerts VALUES(1993,1773059068.901511908,'{"timestamp": "2026-03-09T13:24:28.901512+0100", "flow_id": 1338690643164411, "event_type": "alert", "src_ip": "198.98.49.158", "src_port": 55351, "dest_ip": "134.19.55.199", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101616, "rev": 9, "signature": "GPL DNS named version attempt", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_07_26"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-09T13:24:28.901512+0100", "src_ip": "198.98.49.158", "dest_ip": "134.19.55.199", "src_port": 55351, "dest_port": 53}}'); INSERT INTO alerts VALUES(1994,1773059069.431870938,'{"timestamp": "2026-03-09T13:24:29.431871+0100", "flow_id": 1573399570507582, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 45187, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:24:29.431871+0100", "src_ip": "130.12.180.174", "dest_ip": "134.19.55.199", "src_port": 45187, "dest_port": 23}}'); INSERT INTO alerts VALUES(1995,1773059069.431870938,'{"timestamp": "2026-03-09T13:24:29.431871+0100", "flow_id": 1573399570507582, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 45187, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:24:29.431871+0100", "src_ip": "130.12.180.174", "dest_ip": "134.19.55.199", "src_port": 45187, "dest_port": 23}}'); INSERT INTO alerts VALUES(1996,1773059102.821527958,'{"timestamp": "2026-03-09T13:25:02.821528+0100", "flow_id": 1839586575016812, "event_type": "alert", "src_ip": "45.156.87.91", "src_port": 44962, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:25:02.821528+0100", "src_ip": "45.156.87.91", "dest_ip": "134.19.55.199", "src_port": 44962, "dest_port": 5555}}'); INSERT INTO alerts VALUES(1997,1773059124.689374924,'{"timestamp": "2026-03-09T13:25:24.689375+0100", "flow_id": 1271993268936005, "event_type": "alert", "src_ip": "65.49.1.183", "src_port": 58858, "dest_ip": "134.19.55.199", "dest_port": 4001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:25:24.689375+0100", "src_ip": "65.49.1.183", "dest_ip": "134.19.55.199", "src_port": 58858, "dest_port": 4001}}'); INSERT INTO alerts VALUES(1998,1773059128.352108956,'{"timestamp": "2026-03-09T13:25:28.352109+0100", "flow_id": 104924208974824, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50212, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62561, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T13:25:28.352109+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50212, "dest_port": 53}}'); INSERT INTO alerts VALUES(1999,1773059128.352109909,'{"timestamp": "2026-03-09T13:25:28.352110+0100", "flow_id": 104927092621183, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44199, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65220, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T13:25:28.352110+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44199, "dest_port": 53}}'); INSERT INTO alerts VALUES(2000,1773059128.352109909,'{"timestamp": "2026-03-09T13:25:28.352110+0100", "flow_id": 104929674871549, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 35619, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28877, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T13:25:28.352110+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 35619, "dest_port": 53}}'); INSERT INTO alerts VALUES(2001,1773059158.776607036,'{"timestamp": "2026-03-09T13:25:58.776607+0100", "flow_id": 1928127350312436, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46435, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47905, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:25:58.776607+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46435, "dest_port": 53}}'); INSERT INTO alerts VALUES(2002,1773059158.776873112,'{"timestamp": "2026-03-09T13:25:58.776873+0100", "flow_id": 1929271219603491, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43147, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49492, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:25:58.776873+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43147, "dest_port": 53}}'); INSERT INTO alerts VALUES(2003,1773059298.899519921,'{"timestamp": "2026-03-09T13:28:18.899520+0100", "flow_id": 767188015463553, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46027, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52264, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:28:18.899520+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46027, "dest_port": 53}}'); INSERT INTO alerts VALUES(2004,1773059298.899521112,'{"timestamp": "2026-03-09T13:28:18.899521+0100", "flow_id": 767192573921600, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60057, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22845, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:28:18.899521+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60057, "dest_port": 53}}'); INSERT INTO alerts VALUES(2005,1773059346.914823056,'{"timestamp": "2026-03-09T13:29:06.914823+0100", "flow_id": 832913835449731, "event_type": "alert", "src_ip": "203.55.131.3", "src_port": 37752, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T13:29:06.914823+0100", "src_ip": "203.55.131.3", "dest_ip": "134.19.55.199", "src_port": 37752, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2006,1773059347.244959116,'{"timestamp": "2026-03-09T13:29:07.244959+0100", "flow_id": 1052091516512818, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 59134, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:29:07.244959+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 59134, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2007,1773059438.895467042,'{"timestamp": "2026-03-09T13:30:38.895467+0100", "flow_id": 1875676968236453, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40033, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9247, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:30:38.895467+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40033, "dest_port": 53}}'); INSERT INTO alerts VALUES(2008,1773059438.895467042,'{"timestamp": "2026-03-09T13:30:38.895467+0100", "flow_id": 1875680589272709, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34143, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52569, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:30:38.895467+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34143, "dest_port": 53}}'); INSERT INTO alerts VALUES(2009,1773059451.388691903,'{"timestamp": "2026-03-09T13:30:51.388692+0100", "flow_id": 1106471957973180, "event_type": "alert", "src_ip": "65.49.1.61", "src_port": 15724, "dest_ip": "134.19.55.199", "dest_port": 3283, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 33, "bytes_toclient": 0, "start": "2026-03-09T13:30:51.388692+0100", "src_ip": "65.49.1.61", "dest_ip": "134.19.55.199", "src_port": 15724, "dest_port": 3283}}'); INSERT INTO alerts VALUES(2010,1773059578.961509943,'{"timestamp": "2026-03-09T13:32:58.961510+0100", "flow_id": 751956966238048, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43017, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58454, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:32:58.961510+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43017, "dest_port": 53}}'); INSERT INTO alerts VALUES(2011,1773059578.961509943,'{"timestamp": "2026-03-09T13:32:58.961510+0100", "flow_id": 751957904073649, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 47101, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7982, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:32:58.961510+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 47101, "dest_port": 53}}'); INSERT INTO alerts VALUES(2012,1773059719.040781975,'{"timestamp": "2026-03-09T13:35:19.040782+0100", "flow_id": 2145483912413677, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 58430, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22520, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:35:19.040782+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 58430, "dest_port": 53}}'); INSERT INTO alerts VALUES(2013,1773059719.043184995,'{"timestamp": "2026-03-09T13:35:19.043185+0100", "flow_id": 2155805117065838, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41306, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24427, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:35:19.043185+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41306, "dest_port": 53}}'); INSERT INTO alerts VALUES(2014,1773059721.513351918,'{"timestamp": "2026-03-09T13:35:21.513352+0100", "flow_id": 515983157413289, "event_type": "alert", "src_ip": "64.62.156.162", "src_port": 50835, "dest_ip": "134.19.55.199", "dest_port": 22222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:35:21.513352+0100", "src_ip": "64.62.156.162", "dest_ip": "134.19.55.199", "src_port": 50835, "dest_port": 22222}}'); INSERT INTO alerts VALUES(2015,1773059724.184693098,'{"timestamp": "2026-03-09T13:35:24.184693+0100", "flow_id": 1356204431751054, "event_type": "alert", "src_ip": "193.163.125.184", "src_port": 51894, "dest_ip": "134.19.55.199", "dest_port": 21299, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:35:24.184693+0100", "src_ip": "193.163.125.184", "dest_ip": "134.19.55.199", "src_port": 51894, "dest_port": 21299}}'); INSERT INTO alerts VALUES(2016,1773059757.384895086,'{"timestamp": "2026-03-09T13:35:57.384895+0100", "flow_id": 1653112715600651, "event_type": "alert", "src_ip": "79.124.62.178", "src_port": 56324, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:35:57.384895+0100", "src_ip": "79.124.62.178", "dest_ip": "134.19.55.199", "src_port": 56324, "dest_port": 3389}}'); INSERT INTO alerts VALUES(2017,1773059817.569271087,'{"timestamp": "2026-03-09T13:36:57.569271+0100", "flow_id": 474676746113410, "event_type": "alert", "src_ip": "66.132.153.151", "src_port": 30128, "dest_ip": "134.19.55.199", "dest_port": 6006, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:36:57.569271+0100", "src_ip": "66.132.153.151", "dest_ip": "134.19.55.199", "src_port": 30128, "dest_port": 6006}}'); INSERT INTO alerts VALUES(2018,1773059859.100613118,'{"timestamp": "2026-03-09T13:37:39.100613+0100", "flow_id": 995080137390715, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 45004, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19043, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:37:39.100613+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 45004, "dest_port": 53}}'); INSERT INTO alerts VALUES(2019,1773059859.100614071,'{"timestamp": "2026-03-09T13:37:39.100614+0100", "flow_id": 995085388802427, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57662, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1977, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:37:39.100614+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57662, "dest_port": 53}}'); INSERT INTO alerts VALUES(2020,1773059955.834801913,'{"timestamp": "2026-03-09T13:39:15.834802+0100", "flow_id": 1052175859761805, "event_type": "alert", "src_ip": "193.163.125.182", "src_port": 51288, "dest_ip": "134.19.55.199", "dest_port": 23456, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:39:15.834802+0100", "src_ip": "193.163.125.182", "dest_ip": "134.19.55.199", "src_port": 51288, "dest_port": 23456}}'); INSERT INTO alerts VALUES(2021,1773059981.196916104,'{"timestamp": "2026-03-09T13:39:41.196916+0100", "flow_id": 1408699332009212, "event_type": "alert", "src_ip": "64.62.156.101", "src_port": 33494, "dest_ip": "134.19.55.199", "dest_port": 9002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:39:41.196916+0100", "src_ip": "64.62.156.101", "dest_ip": "134.19.55.199", "src_port": 33494, "dest_port": 9002}}'); INSERT INTO alerts VALUES(2022,1773059999.153779983,'{"timestamp": "2026-03-09T13:39:59.153780+0100", "flow_id": 2067857676750387, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57347, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58013, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:39:59.153780+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57347, "dest_port": 53}}'); INSERT INTO alerts VALUES(2023,1773059999.153779983,'{"timestamp": "2026-03-09T13:39:59.153780+0100", "flow_id": 2067855992915155, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50590, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1186, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:39:59.153780+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50590, "dest_port": 53}}'); INSERT INTO alerts VALUES(2024,1773060048.345557929,'{"timestamp": "2026-03-09T13:40:48.345558+0100", "flow_id": 76786230179492, "event_type": "alert", "src_ip": "64.62.197.55", "src_port": 45385, "dest_ip": "134.19.55.199", "dest_port": 7001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:40:48.345558+0100", "src_ip": "64.62.197.55", "dest_ip": "134.19.55.199", "src_port": 45385, "dest_port": 7001}}'); INSERT INTO alerts VALUES(2025,1773060050.971755982,'{"timestamp": "2026-03-09T13:40:50.971756+0100", "flow_id": 795963538118958, "event_type": "alert", "src_ip": "185.242.226.11", "src_port": 42565, "dest_ip": "134.19.55.199", "dest_port": 12275, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:40:50.971756+0100", "src_ip": "185.242.226.11", "dest_ip": "134.19.55.199", "src_port": 42565, "dest_port": 12275}}'); INSERT INTO alerts VALUES(2026,1773060139.213922024,'{"timestamp": "2026-03-09T13:42:19.213922+0100", "flow_id": 918789281002711, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50727, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56850, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:42:19.213922+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50727, "dest_port": 53}}'); INSERT INTO alerts VALUES(2027,1773060139.213922024,'{"timestamp": "2026-03-09T13:42:19.213922+0100", "flow_id": 918788445350949, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59875, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11875, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T13:42:19.213922+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59875, "dest_port": 53}}'); INSERT INTO alerts VALUES(2028,1773060198.510682107,'{"timestamp": "2026-03-09T13:43:18.510682+0100", "flow_id": 1911889358481883, "event_type": "alert", "src_ip": "195.184.76.179", "src_port": 24432, "dest_ip": "134.19.55.199", "dest_port": 5251, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:43:18.510682+0100", "src_ip": "195.184.76.179", "dest_ip": "134.19.55.199", "src_port": 24432, "dest_port": 5251}}'); INSERT INTO alerts VALUES(2029,1773060281.884557009,'{"timestamp": "2026-03-09T13:44:41.884557+0100", "flow_id": 421445034097538, "event_type": "alert", "src_ip": "167.94.138.128", "src_port": 42172, "dest_ip": "134.19.55.199", "dest_port": 554, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:44:41.884557+0100", "src_ip": "167.94.138.128", "dest_ip": "134.19.55.199", "src_port": 42172, "dest_port": 554}}'); INSERT INTO alerts VALUES(2030,1773060309.088182927,'{"timestamp": "2026-03-09T13:45:09.088183+0100", "flow_id": 1504643689248825, "event_type": "alert", "src_ip": "65.49.1.47", "src_port": 10159, "dest_ip": "134.19.55.199", "dest_port": 37810, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-09T13:45:09.088183+0100", "src_ip": "65.49.1.47", "dest_ip": "134.19.55.199", "src_port": 10159, "dest_port": 37810}}'); INSERT INTO alerts VALUES(2031,1773060401.288860083,'{"timestamp": "2026-03-09T13:46:41.288860+0100", "flow_id": 396222186036308, "event_type": "alert", "src_ip": "66.132.153.155", "src_port": 54832, "dest_ip": "134.19.55.199", "dest_port": 6008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:46:41.288860+0100", "src_ip": "66.132.153.155", "dest_ip": "134.19.55.199", "src_port": 54832, "dest_port": 6008}}'); INSERT INTO alerts VALUES(2032,1773060478.682501078,'{"timestamp": "2026-03-09T13:47:58.682501+0100", "flow_id": 1805422697505417, "event_type": "alert", "src_ip": "167.94.146.34", "src_port": 64537, "dest_ip": "134.19.55.199", "dest_port": 57883, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:47:58.682501+0100", "src_ip": "167.94.146.34", "dest_ip": "134.19.55.199", "src_port": 64537, "dest_port": 57883}}'); INSERT INTO alerts VALUES(2033,1773060513.449970006,'{"timestamp": "2026-03-09T13:48:33.449970+0100", "flow_id": 525231946229525, "event_type": "alert", "src_ip": "185.156.73.182", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44337, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:48:33.449970+0100", "src_ip": "185.156.73.182", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44337}}'); INSERT INTO alerts VALUES(2034,1773060557.2486341,'{"timestamp": "2026-03-09T13:49:17.248634+0100", "flow_id": 1630826093750967, "event_type": "alert", "src_ip": "64.62.197.145", "src_port": 56604, "dest_ip": "134.19.55.199", "dest_port": 548, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:49:17.248634+0100", "src_ip": "64.62.197.145", "dest_ip": "134.19.55.199", "src_port": 56604, "dest_port": 548}}'); INSERT INTO alerts VALUES(2035,1773060560.846549034,'{"timestamp": "2026-03-09T13:49:20.846549+0100", "flow_id": 258201339911377, "event_type": "alert", "src_ip": "193.163.125.199", "src_port": 59127, "dest_ip": "134.19.55.199", "dest_port": 6006, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:49:20.846549+0100", "src_ip": "193.163.125.199", "dest_ip": "134.19.55.199", "src_port": 59127, "dest_port": 6006}}'); INSERT INTO alerts VALUES(2036,1773060741.085954904,'{"timestamp": "2026-03-09T13:52:21.085955+0100", "flow_id": 1495077170590641, "event_type": "alert", "src_ip": "87.121.84.93", "src_port": 55081, "dest_ip": "134.19.55.199", "dest_port": 8008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:52:21.085955+0100", "src_ip": "87.121.84.93", "dest_ip": "134.19.55.199", "src_port": 55081, "dest_port": 8008}}'); INSERT INTO alerts VALUES(2037,1773060777.104196072,'{"timestamp": "2026-03-09T13:52:57.104196+0100", "flow_id": 447522054234251, "event_type": "alert", "src_ip": "167.94.146.41", "src_port": 34320, "dest_ip": "134.19.55.199", "dest_port": 18971, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:52:57.104196+0100", "src_ip": "167.94.146.41", "dest_ip": "134.19.55.199", "src_port": 34320, "dest_port": 18971}}'); INSERT INTO alerts VALUES(2038,1773060796.060970067,'{"timestamp": "2026-03-09T13:53:16.060970+0100", "flow_id": 1387766776274435, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 57202, "dest_ip": "134.19.55.199", "dest_port": 3469, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:53:16.060970+0100", "src_ip": "45.142.193.7", "dest_ip": "134.19.55.199", "src_port": 57202, "dest_port": 3469}}'); INSERT INTO alerts VALUES(2039,1773060892.378519058,'{"timestamp": "2026-03-09T13:54:52.378519+0100", "flow_id": 1344255223855239, "event_type": "alert", "src_ip": "64.62.156.94", "src_port": 43872, "dest_ip": "134.19.55.199", "dest_port": 63210, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:54:52.378519+0100", "src_ip": "64.62.156.94", "dest_ip": "134.19.55.199", "src_port": 43872, "dest_port": 63210}}'); INSERT INTO alerts VALUES(2040,1773060934.534092903,'{"timestamp": "2026-03-09T13:55:34.534093+0100", "flow_id": 1730964255552138, "event_type": "alert", "src_ip": "46.151.182.45", "src_port": 45811, "dest_ip": "134.19.55.199", "dest_port": 55555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T13:55:34.534093+0100", "src_ip": "46.151.182.45", "dest_ip": "134.19.55.199", "src_port": 45811, "dest_port": 55555}}'); INSERT INTO alerts VALUES(2041,1773060953.570935011,'{"timestamp": "2026-03-09T13:55:53.570935+0100", "flow_id": 481825059912334, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 49518, "dest_ip": "134.19.55.199", "dest_port": 19311, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T13:55:53.570935+0100", "src_ip": "167.94.146.40", "dest_ip": "134.19.55.199", "src_port": 49518, "dest_port": 19311}}'); INSERT INTO alerts VALUES(2042,1773060987.604599953,'{"timestamp": "2026-03-09T13:56:27.604600+0100", "flow_id": 907890176953961, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 58217, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:56:27.604600+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 58217, "dest_port": 3389}}'); INSERT INTO alerts VALUES(2043,1773060997.802122117,'{"timestamp": "2026-03-09T13:56:37.802122+0100", "flow_id": 1474763336911677, "event_type": "alert", "src_ip": "64.62.197.12", "src_port": 14518, "dest_ip": "134.19.55.199", "dest_port": 32414, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-09T13:56:37.802122+0100", "src_ip": "64.62.197.12", "dest_ip": "134.19.55.199", "src_port": 14518, "dest_port": 32414}}'); INSERT INTO alerts VALUES(2044,1773061020.591090918,'{"timestamp": "2026-03-09T13:57:00.591091+0100", "flow_id": 1131342943428094, "event_type": "alert", "src_ip": "91.224.92.129", "src_port": 54100, "dest_ip": "134.19.55.199", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:57:00.591091+0100", "src_ip": "91.224.92.129", "dest_ip": "134.19.55.199", "src_port": 54100, "dest_port": 8888}}'); INSERT INTO alerts VALUES(2045,1773061053.331803084,'{"timestamp": "2026-03-09T13:57:33.331803+0100", "flow_id": 1425085594317960, "event_type": "alert", "src_ip": "45.142.154.87", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 3118, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T13:57:33.331803+0100", "src_ip": "45.142.154.87", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 3118}}'); INSERT INTO alerts VALUES(2046,1773061114.812349082,'{"timestamp": "2026-03-09T13:58:34.812349+0100", "flow_id": 674266515913201, "event_type": "alert", "src_ip": "65.49.1.155", "src_port": 51522, "dest_ip": "134.19.55.199", "dest_port": 4118, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T13:58:34.812349+0100", "src_ip": "65.49.1.155", "dest_ip": "134.19.55.199", "src_port": 51522, "dest_port": 4118}}'); INSERT INTO alerts VALUES(2047,1773061204.741888046,'{"timestamp": "2026-03-09T14:00:04.741888+0100", "flow_id": 1216060662676750, "event_type": "alert", "src_ip": "167.94.138.96", "src_port": 62553, "dest_ip": "134.19.55.199", "dest_port": 42744, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:00:04.741888+0100", "src_ip": "167.94.138.96", "dest_ip": "134.19.55.199", "src_port": 62553, "dest_port": 42744}}'); INSERT INTO alerts VALUES(2048,1773061227.812843084,'{"timestamp": "2026-03-09T14:00:27.812843+0100", "flow_id": 957862942934319, "event_type": "alert", "src_ip": "87.121.84.88", "src_port": 60000, "dest_ip": "134.19.55.199", "dest_port": 22146, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:00:27.812843+0100", "src_ip": "87.121.84.88", "dest_ip": "134.19.55.199", "src_port": 60000, "dest_port": 22146}}'); INSERT INTO alerts VALUES(2049,1773061355.793853044,'{"timestamp": "2026-03-09T14:02:35.793853+0100", "flow_id": 876302039285075, "event_type": "alert", "src_ip": "66.132.153.158", "src_port": 53988, "dest_ip": "134.19.55.199", "dest_port": 10001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:02:35.793853+0100", "src_ip": "66.132.153.158", "dest_ip": "134.19.55.199", "src_port": 53988, "dest_port": 10001}}'); INSERT INTO alerts VALUES(2050,1773061383.262130022,'{"timestamp": "2026-03-09T14:03:03.262130+0100", "flow_id": 2251742616563213, "event_type": "alert", "src_ip": "176.65.132.141", "src_port": 41252, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:03:03.262130+0100", "src_ip": "176.65.132.141", "dest_ip": "134.19.55.199", "src_port": 41252, "dest_port": 27017}}'); INSERT INTO alerts VALUES(2051,1773061426.815615893,'{"timestamp": "2026-03-09T14:03:46.815616+0100", "flow_id": 688297235149602, "event_type": "alert", "src_ip": "167.94.146.33", "src_port": 18481, "dest_ip": "134.19.55.199", "dest_port": 25587, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:03:46.815616+0100", "src_ip": "167.94.146.33", "dest_ip": "134.19.55.199", "src_port": 18481, "dest_port": 25587}}'); INSERT INTO alerts VALUES(2052,1773061453.439945937,'{"timestamp": "2026-03-09T14:04:13.439946+0100", "flow_id": 1608079775803087, "event_type": "alert", "src_ip": "167.94.146.38", "src_port": 33421, "dest_ip": "134.19.55.199", "dest_port": 21151, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:04:13.439946+0100", "src_ip": "167.94.146.38", "dest_ip": "134.19.55.199", "src_port": 33421, "dest_port": 21151}}'); INSERT INTO alerts VALUES(2053,1773061590.399739028,'{"timestamp": "2026-03-09T14:06:30.399739+0100", "flow_id": 1716866715838704, "event_type": "alert", "src_ip": "167.94.138.100", "src_port": 56361, "dest_ip": "134.19.55.199", "dest_port": 4053, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:06:30.399739+0100", "src_ip": "167.94.138.100", "dest_ip": "134.19.55.199", "src_port": 56361, "dest_port": 4053}}'); INSERT INTO alerts VALUES(2054,1773061614.068953991,'{"timestamp": "2026-03-09T14:06:54.068954+0100", "flow_id": 1703532305733424, "event_type": "alert", "src_ip": "193.163.125.196", "src_port": 34292, "dest_ip": "134.19.55.199", "dest_port": 7170, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:06:54.068954+0100", "src_ip": "193.163.125.196", "dest_ip": "134.19.55.199", "src_port": 34292, "dest_port": 7170}}'); INSERT INTO alerts VALUES(2055,1773061618.172416926,'{"timestamp": "2026-03-09T14:06:58.172417+0100", "flow_id": 740526827035960, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 7080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:06:58.172417+0100", "src_ip": "204.76.203.73", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 7080}}'); INSERT INTO alerts VALUES(2056,1773061618.172416926,'{"timestamp": "2026-03-09T14:06:58.172417+0100", "flow_id": 740526827035960, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 7080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:06:58.172417+0100", "src_ip": "204.76.203.73", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 7080}}'); INSERT INTO alerts VALUES(2057,1773061653.074996949,'{"timestamp": "2026-03-09T14:07:33.074997+0100", "flow_id": 1448011128053115, "event_type": "alert", "src_ip": "176.65.139.38", "src_port": 50000, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:07:33.074997+0100", "src_ip": "176.65.139.38", "dest_ip": "134.19.55.199", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(2058,1773061671.174675942,'{"timestamp": "2026-03-09T14:07:51.174676+0100", "flow_id": 2157603762278525, "event_type": "alert", "src_ip": "64.62.156.126", "src_port": 58910, "dest_ip": "134.19.55.199", "dest_port": 2323, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:07:51.174676+0100", "src_ip": "64.62.156.126", "dest_ip": "134.19.55.199", "src_port": 58910, "dest_port": 2323}}'); INSERT INTO alerts VALUES(2059,1773061689.595084905,'{"timestamp": "2026-03-09T14:08:09.595085+0100", "flow_id": 304073758828655, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 44372, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:08:09.595085+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 44372}}'); INSERT INTO alerts VALUES(2060,1773061689.595084905,'{"timestamp": "2026-03-09T14:08:09.595085+0100", "flow_id": 304073758828655, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 44372, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:08:09.595085+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 44372}}'); INSERT INTO alerts VALUES(2061,1773061733.886392116,'{"timestamp": "2026-03-09T14:08:53.886392+0100", "flow_id": 1555225937898518, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 41287, "dest_ip": "134.19.55.199", "dest_port": 11544, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:08:53.886392+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 41287, "dest_port": 11544}}'); INSERT INTO alerts VALUES(2062,1773061744.796490908,'{"timestamp": "2026-03-09T14:09:04.796491+0100", "flow_id": 43205287074536, "event_type": "alert", "src_ip": "193.163.125.191", "src_port": 45265, "dest_ip": "134.19.55.199", "dest_port": 41977, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:09:04.796491+0100", "src_ip": "193.163.125.191", "dest_ip": "134.19.55.199", "src_port": 45265, "dest_port": 41977}}'); INSERT INTO alerts VALUES(2063,1773061759.839312077,'{"timestamp": "2026-03-09T14:09:19.839312+0100", "flow_id": 2197444357719831, "event_type": "alert", "src_ip": "64.89.163.179", "src_port": 41761, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:09:19.839312+0100", "src_ip": "64.89.163.179", "dest_ip": "134.19.55.199", "src_port": 41761, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2064,1773061759.839312077,'{"timestamp": "2026-03-09T14:09:19.839312+0100", "flow_id": 2197444357719831, "event_type": "alert", "src_ip": "64.89.163.179", "src_port": 41761, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:09:19.839312+0100", "src_ip": "64.89.163.179", "dest_ip": "134.19.55.199", "src_port": 41761, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2065,1773061817.425067901,'{"timestamp": "2026-03-09T14:10:17.425068+0100", "flow_id": 418282161577357, "event_type": "alert", "src_ip": "65.49.1.236", "src_port": 34814, "dest_ip": "134.19.55.199", "dest_port": 5094, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:10:17.425068+0100", "src_ip": "65.49.1.236", "dest_ip": "134.19.55.199", "src_port": 34814, "dest_port": 5094}}'); INSERT INTO alerts VALUES(2066,1773061836.631979943,'{"timestamp": "2026-03-09T14:10:36.631980+0100", "flow_id": 1306959455116778, "event_type": "alert", "src_ip": "193.163.125.208", "src_port": 37515, "dest_ip": "134.19.55.199", "dest_port": 8008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:10:36.631980+0100", "src_ip": "193.163.125.208", "dest_ip": "134.19.55.199", "src_port": 37515, "dest_port": 8008}}'); INSERT INTO alerts VALUES(2067,1773061903.451121092,'{"timestamp": "2026-03-09T14:11:43.451121+0100", "flow_id": 2219025957285945, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 13356, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:11:43.451121+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 13356}}'); INSERT INTO alerts VALUES(2068,1773061975.362654925,'{"timestamp": "2026-03-09T14:12:55.362655+0100", "flow_id": 2120542854848662, "event_type": "alert", "src_ip": "65.49.1.99", "src_port": 34401, "dest_ip": "134.19.55.199", "dest_port": 1337, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:12:55.362655+0100", "src_ip": "65.49.1.99", "dest_ip": "134.19.55.199", "src_port": 34401, "dest_port": 1337}}'); INSERT INTO alerts VALUES(2069,1773062087.556082963,'{"timestamp": "2026-03-09T14:14:47.556083+0100", "flow_id": 2106885943819251, "event_type": "alert", "src_ip": "64.62.156.98", "src_port": 56931, "dest_ip": "134.19.55.199", "dest_port": 17000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:14:47.556083+0100", "src_ip": "64.62.156.98", "dest_ip": "134.19.55.199", "src_port": 56931, "dest_port": 17000}}'); INSERT INTO alerts VALUES(2070,1773062161.89999795,'{"timestamp": "2026-03-09T14:16:01.899998+0100", "flow_id": 487765673269275, "event_type": "alert", "src_ip": "64.62.156.212", "src_port": 54754, "dest_ip": "134.19.55.199", "dest_port": 5904, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:16:01.899998+0100", "src_ip": "64.62.156.212", "dest_ip": "134.19.55.199", "src_port": 54754, "dest_port": 5904}}'); INSERT INTO alerts VALUES(2071,1773062201.587824107,'{"timestamp": "2026-03-09T14:16:41.587824+0100", "flow_id": 554360823494365, "event_type": "alert", "src_ip": "195.184.76.221", "src_port": 14104, "dest_ip": "134.19.55.199", "dest_port": 5254, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:16:41.587824+0100", "src_ip": "195.184.76.221", "dest_ip": "134.19.55.199", "src_port": 14104, "dest_port": 5254}}'); INSERT INTO alerts VALUES(2072,1773062243.485665082,'{"timestamp": "2026-03-09T14:17:23.485665+0100", "flow_id": 960018660314315, "event_type": "alert", "src_ip": "176.65.134.34", "src_port": 38065, "dest_ip": "134.19.55.199", "dest_port": 43000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:17:23.485665+0100", "src_ip": "176.65.134.34", "dest_ip": "134.19.55.199", "src_port": 38065, "dest_port": 43000}}'); INSERT INTO alerts VALUES(2073,1773062286.294363022,'{"timestamp": "2026-03-09T14:18:06.294363+0100", "flow_id": 1827231816105576, "event_type": "alert", "src_ip": "64.62.156.15", "src_port": 13906, "dest_ip": "134.19.55.199", "dest_port": 4500, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 80, "bytes_toclient": 0, "start": "2026-03-09T14:18:06.294363+0100", "src_ip": "64.62.156.15", "dest_ip": "134.19.55.199", "src_port": 13906, "dest_port": 4500}}'); INSERT INTO alerts VALUES(2074,1773062354.473543883,'{"timestamp": "2026-03-09T14:19:14.473544+0100", "flow_id": 626484644772750, "event_type": "alert", "src_ip": "188.113.252.110", "src_port": 12560, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T14:19:14.473544+0100", "src_ip": "188.113.252.110", "dest_ip": "134.19.55.199", "src_port": 12560, "dest_port": 1433}}'); INSERT INTO alerts VALUES(2075,1773062357.483683109,'{"timestamp": "2026-03-09T14:19:17.483683+0100", "flow_id": 626484644772750, "event_type": "alert", "src_ip": "188.113.252.110", "src_port": 12560, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 104, "bytes_toclient": 0, "start": "2026-03-09T14:19:14.473544+0100", "src_ip": "188.113.252.110", "dest_ip": "134.19.55.199", "src_port": 12560, "dest_port": 1433}}'); INSERT INTO alerts VALUES(2076,1773062373.982665061,'{"timestamp": "2026-03-09T14:19:33.982665+0100", "flow_id": 1687239623670201, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 3005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:19:33.982665+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 3005}}'); INSERT INTO alerts VALUES(2077,1773062373.982665061,'{"timestamp": "2026-03-09T14:19:33.982665+0100", "flow_id": 1687239623670201, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 3005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:19:33.982665+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 3005}}'); INSERT INTO alerts VALUES(2078,1773062396.53095007,'{"timestamp": "2026-03-09T14:19:56.530950+0100", "flow_id": 1154513915907481, "event_type": "alert", "src_ip": "64.62.156.175", "src_port": 42395, "dest_ip": "134.19.55.199", "dest_port": 631, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:19:56.530950+0100", "src_ip": "64.62.156.175", "dest_ip": "134.19.55.199", "src_port": 42395, "dest_port": 631}}'); INSERT INTO alerts VALUES(2079,1773062423.818243027,'{"timestamp": "2026-03-09T14:20:23.818243+0100", "flow_id": 2106955351706828, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 57143, "dest_ip": "134.19.55.199", "dest_port": 2022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:20:23.818243+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.55.199", "src_port": 57143, "dest_port": 2022}}'); INSERT INTO alerts VALUES(2080,1773062423.818243027,'{"timestamp": "2026-03-09T14:20:23.818243+0100", "flow_id": 2106955351706828, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 57143, "dest_ip": "134.19.55.199", "dest_port": 2022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:20:23.818243+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.55.199", "src_port": 57143, "dest_port": 2022}}'); INSERT INTO alerts VALUES(2081,1773062435.265659094,'{"timestamp": "2026-03-09T14:20:35.265659+0100", "flow_id": 859524388876255, "event_type": "alert", "src_ip": "167.94.146.42", "src_port": 44186, "dest_ip": "134.19.55.199", "dest_port": 32478, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:20:35.265659+0100", "src_ip": "167.94.146.42", "dest_ip": "134.19.55.199", "src_port": 44186, "dest_port": 32478}}'); INSERT INTO alerts VALUES(2082,1773062522.148956061,'{"timestamp": "2026-03-09T14:22:02.148956+0100", "flow_id": 639761798438212, "event_type": "alert", "src_ip": "64.89.163.85", "src_port": 42339, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:22:02.148956+0100", "src_ip": "64.89.163.85", "dest_ip": "134.19.55.199", "src_port": 42339, "dest_port": 27017}}'); INSERT INTO alerts VALUES(2083,1773062531.828162908,'{"timestamp": "2026-03-09T14:22:11.828163+0100", "flow_id": 1023658704932555, "event_type": "alert", "src_ip": "176.65.148.96", "src_port": 54716, "dest_ip": "134.19.55.199", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T14:22:11.828163+0100", "src_ip": "176.65.148.96", "dest_ip": "134.19.55.199", "src_port": 54716, "dest_port": 8332}}'); INSERT INTO alerts VALUES(2084,1773062531.828162908,'{"timestamp": "2026-03-09T14:22:11.828163+0100", "flow_id": 1023658704932555, "event_type": "alert", "src_ip": "176.65.148.96", "src_port": 54716, "dest_ip": "134.19.55.199", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T14:22:11.828163+0100", "src_ip": "176.65.148.96", "dest_ip": "134.19.55.199", "src_port": 54716, "dest_port": 8332}}'); INSERT INTO alerts VALUES(2085,1773062538.947494983,'{"timestamp": "2026-03-09T14:22:18.947495+0100", "flow_id": 691761405206318, "event_type": "alert", "src_ip": "91.196.152.108", "src_port": 42217, "dest_ip": "134.19.55.199", "dest_port": 2080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:22:18.947495+0100", "src_ip": "91.196.152.108", "dest_ip": "134.19.55.199", "src_port": 42217, "dest_port": 2080}}'); INSERT INTO alerts VALUES(2086,1773062559.0486691,'{"timestamp": "2026-03-09T14:22:39.048669+0100", "flow_id": 2179359799128736, "event_type": "alert", "src_ip": "167.94.138.149", "src_port": 38989, "dest_ip": "134.19.55.199", "dest_port": 5061, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:22:39.048669+0100", "src_ip": "167.94.138.149", "dest_ip": "134.19.55.199", "src_port": 38989, "dest_port": 5061}}'); INSERT INTO alerts VALUES(2087,1773062575.979254962,'{"timestamp": "2026-03-09T14:22:55.979255+0100", "flow_id": 2235543756929187, "event_type": "alert", "src_ip": "101.201.77.231", "src_port": 59762, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T14:22:55.979255+0100", "src_ip": "101.201.77.231", "dest_ip": "134.19.55.199", "src_port": 59762, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2088,1773062672.553313017,'{"timestamp": "2026-03-09T14:24:32.553313+0100", "flow_id": 124662455913894, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 37265, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T14:24:32.553313+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 37265, "dest_port": 8545}}'); INSERT INTO alerts VALUES(2089,1773062672.553313017,'{"timestamp": "2026-03-09T14:24:32.553313+0100", "flow_id": 124662455913894, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 37265, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T14:24:32.553313+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 37265, "dest_port": 8545}}'); INSERT INTO alerts VALUES(2090,1773062679.231952905,'{"timestamp": "2026-03-09T14:24:39.231953+0100", "flow_id": 2122131990223457, "event_type": "alert", "src_ip": "167.94.146.47", "src_port": 46436, "dest_ip": "134.19.55.199", "dest_port": 2850, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:24:39.231953+0100", "src_ip": "167.94.146.47", "dest_ip": "134.19.55.199", "src_port": 46436, "dest_port": 2850}}'); INSERT INTO alerts VALUES(2091,1773062692.145946026,'{"timestamp": "2026-03-09T14:24:52.145946+0100", "flow_id": 1189784551410566, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 40854, "dest_ip": "134.19.55.199", "dest_port": 45478, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:24:52.145946+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 40854, "dest_port": 45478}}'); INSERT INTO alerts VALUES(2092,1773062722.657644033,'{"timestamp": "2026-03-09T14:25:22.657644+0100", "flow_id": 572760666727115, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 45248, "dest_ip": "134.19.55.199", "dest_port": 11935, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:25:22.657644+0100", "src_ip": "167.94.146.45", "dest_ip": "134.19.55.199", "src_port": 45248, "dest_port": 11935}}'); INSERT INTO alerts VALUES(2093,1773062797.88935399,'{"timestamp": "2026-03-09T14:26:37.889354+0100", "flow_id": 1567948916787650, "event_type": "alert", "src_ip": "64.62.197.153", "src_port": 52378, "dest_ip": "134.19.55.199", "dest_port": 33060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:26:37.889354+0100", "src_ip": "64.62.197.153", "dest_ip": "134.19.55.199", "src_port": 52378, "dest_port": 33060}}'); INSERT INTO alerts VALUES(2094,1773062830.352525949,'{"timestamp": "2026-03-09T14:27:10.352526+0100", "flow_id": 1795565014099835, "event_type": "alert", "src_ip": "167.94.138.102", "src_port": 63354, "dest_ip": "134.19.55.199", "dest_port": 60119, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:27:10.352526+0100", "src_ip": "167.94.138.102", "dest_ip": "134.19.55.199", "src_port": 63354, "dest_port": 60119}}'); INSERT INTO alerts VALUES(2095,1773062830.79676199,'{"timestamp": "2026-03-09T14:27:10.796762+0100", "flow_id": 1733219711923637, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 42655, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:27:10.796762+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 42655, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2096,1773062830.79676199,'{"timestamp": "2026-03-09T14:27:10.796762+0100", "flow_id": 1733219711923637, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 42655, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:27:10.796762+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 42655, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2097,1773062854.627547979,'{"timestamp": "2026-03-09T14:27:34.627548+0100", "flow_id": 1850876017173761, "event_type": "alert", "src_ip": "64.62.156.194", "src_port": 43461, "dest_ip": "134.19.55.199", "dest_port": 5802, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:27:34.627548+0100", "src_ip": "64.62.156.194", "dest_ip": "134.19.55.199", "src_port": 43461, "dest_port": 5802}}'); INSERT INTO alerts VALUES(2098,1773062858.011239052,'{"timestamp": "2026-03-09T14:27:38.011239+0100", "flow_id": 611222172545735, "event_type": "alert", "src_ip": "195.184.76.76", "src_port": 359, "dest_ip": "134.19.55.199", "dest_port": 2404, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:27:38.011239+0100", "src_ip": "195.184.76.76", "dest_ip": "134.19.55.199", "src_port": 359, "dest_port": 2404}}'); INSERT INTO alerts VALUES(2099,1773062904.263381004,'{"timestamp": "2026-03-09T14:28:24.263381+0100", "flow_id": 5312918035417, "event_type": "alert", "src_ip": "66.132.153.147", "src_port": 53734, "dest_ip": "134.19.55.199", "dest_port": 993, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:28:24.263381+0100", "src_ip": "66.132.153.147", "dest_ip": "134.19.55.199", "src_port": 53734, "dest_port": 993}}'); INSERT INTO alerts VALUES(2100,1773062968.939615011,'{"timestamp": "2026-03-09T14:29:28.939615+0100", "flow_id": 94970276480927, "event_type": "alert", "src_ip": "176.65.139.41", "src_port": 50000, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:29:28.939615+0100", "src_ip": "176.65.139.41", "dest_ip": "134.19.55.199", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(2101,1773062971.187635899,'{"timestamp": "2026-03-09T14:29:31.187636+0100", "flow_id": 1087367947959912, "event_type": "alert", "src_ip": "167.94.146.44", "src_port": 50796, "dest_ip": "134.19.55.199", "dest_port": 56288, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:29:31.187636+0100", "src_ip": "167.94.146.44", "dest_ip": "134.19.55.199", "src_port": 50796, "dest_port": 56288}}'); INSERT INTO alerts VALUES(2102,1773062998.888623952,'{"timestamp": "2026-03-09T14:29:58.888624+0100", "flow_id": 1846289201939195, "event_type": "alert", "src_ip": "86.54.31.32", "src_port": 29538, "dest_ip": "134.19.55.199", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 79, "bytes_toclient": 0, "start": "2026-03-09T14:29:58.888624+0100", "src_ip": "86.54.31.32", "dest_ip": "134.19.55.199", "src_port": 29538, "dest_port": 161}}'); INSERT INTO alerts VALUES(2103,1773062999.741379977,'{"timestamp": "2026-03-09T14:29:59.741380+0100", "flow_id": 2058307094207868, "event_type": "alert", "src_ip": "64.62.197.34", "src_port": 34392, "dest_ip": "134.19.55.199", "dest_port": 11211, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:29:59.741380+0100", "src_ip": "64.62.197.34", "dest_ip": "134.19.55.199", "src_port": 34392, "dest_port": 11211}}'); INSERT INTO alerts VALUES(2104,1773063014.333736897,'{"timestamp": "2026-03-09T14:30:14.333737+0100", "flow_id": 1714868214141229, "event_type": "alert", "src_ip": "193.163.125.211", "src_port": 39386, "dest_ip": "134.19.55.199", "dest_port": 7110, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:30:14.333737+0100", "src_ip": "193.163.125.211", "dest_ip": "134.19.55.199", "src_port": 39386, "dest_port": 7110}}'); INSERT INTO alerts VALUES(2105,1773063016.146915912,'{"timestamp": "2026-03-09T14:30:16.146916+0100", "flow_id": 68053589342952, "event_type": "alert", "src_ip": "45.135.194.48", "src_port": 57754, "dest_ip": "134.19.55.199", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T14:30:16.146916+0100", "src_ip": "45.135.194.48", "dest_ip": "134.19.55.199", "src_port": 57754, "dest_port": 5900}}'); INSERT INTO alerts VALUES(2106,1773063054.144965888,'{"timestamp": "2026-03-09T14:30:54.144966+0100", "flow_id": 1748528179157152, "event_type": "alert", "src_ip": "167.94.138.129", "src_port": 38383, "dest_ip": "134.19.55.199", "dest_port": 69, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "tftp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 42, "bytes_toclient": 0, "start": "2026-03-09T14:30:54.144966+0100", "src_ip": "167.94.138.129", "dest_ip": "134.19.55.199", "src_port": 38383, "dest_port": 69}}'); INSERT INTO alerts VALUES(2107,1773063072.774543047,'{"timestamp": "2026-03-09T14:31:12.774543+0100", "flow_id": 230414688031035, "event_type": "alert", "src_ip": "64.62.156.226", "src_port": 55167, "dest_ip": "134.19.55.199", "dest_port": 873, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:31:12.774543+0100", "src_ip": "64.62.156.226", "dest_ip": "134.19.55.199", "src_port": 55167, "dest_port": 873}}'); INSERT INTO alerts VALUES(2108,1773063098.245666028,'{"timestamp": "2026-03-09T14:31:38.245666+0100", "flow_id": 773655095949736, "event_type": "alert", "src_ip": "172.94.9.253", "src_port": 46819, "dest_ip": "134.19.55.199", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400031, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 32", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:31:38.245666+0100", "src_ip": "172.94.9.253", "dest_ip": "134.19.55.199", "src_port": 46819, "dest_port": 443}}'); INSERT INTO alerts VALUES(2109,1773063103.272608041,'{"timestamp": "2026-03-09T14:31:43.272608+0100", "flow_id": 2015268251192819, "event_type": "alert", "src_ip": "88.210.63.193", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 45000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:31:43.272608+0100", "src_ip": "88.210.63.193", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 45000}}'); INSERT INTO alerts VALUES(2110,1773063159.540427924,'{"timestamp": "2026-03-09T14:32:39.540428+0100", "flow_id": 2039647225995000, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 31443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:32:39.540428+0100", "src_ip": "185.156.73.181", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 31443}}'); INSERT INTO alerts VALUES(2111,1773063180.889132023,'{"timestamp": "2026-03-09T14:33:00.889132+0100", "flow_id": 1285519432107821, "event_type": "alert", "src_ip": "195.184.76.84", "src_port": 19777, "dest_ip": "134.19.55.199", "dest_port": 1883, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:33:00.889132+0100", "src_ip": "195.184.76.84", "dest_ip": "134.19.55.199", "src_port": 19777, "dest_port": 1883}}'); INSERT INTO alerts VALUES(2112,1773063195.773695946,'{"timestamp": "2026-03-09T14:33:15.773696+0100", "flow_id": 1071199910435977, "event_type": "alert", "src_ip": "64.62.156.14", "src_port": 38176, "dest_ip": "134.19.55.199", "dest_port": 2455, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:33:15.773696+0100", "src_ip": "64.62.156.14", "dest_ip": "134.19.55.199", "src_port": 38176, "dest_port": 2455}}'); INSERT INTO alerts VALUES(2113,1773063337.22753191,'{"timestamp": "2026-03-09T14:35:37.227532+0100", "flow_id": 414293530707097, "event_type": "alert", "src_ip": "185.242.226.18", "src_port": 41003, "dest_ip": "134.19.55.199", "dest_port": 2087, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:35:37.227532+0100", "src_ip": "185.242.226.18", "dest_ip": "134.19.55.199", "src_port": 41003, "dest_port": 2087}}'); INSERT INTO alerts VALUES(2114,1773063506.947072029,'{"timestamp": "2026-03-09T14:38:26.947072+0100", "flow_id": 689944951367478, "event_type": "alert", "src_ip": "45.156.87.91", "src_port": 49604, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:38:26.947072+0100", "src_ip": "45.156.87.91", "dest_ip": "134.19.55.199", "src_port": 49604, "dest_port": 5555}}'); INSERT INTO alerts VALUES(2115,1773063587.415849925,'{"timestamp": "2026-03-09T14:39:47.415850+0100", "flow_id": 941640145734200, "event_type": "alert", "src_ip": "91.224.92.177", "src_port": 55369, "dest_ip": "134.19.55.199", "dest_port": 3001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:39:47.415850+0100", "src_ip": "91.224.92.177", "dest_ip": "134.19.55.199", "src_port": 55369, "dest_port": 3001}}'); INSERT INTO alerts VALUES(2116,1773063805.852308034,'{"timestamp": "2026-03-09T14:43:25.852308+0100", "flow_id": 1408838181173859, "event_type": "alert", "src_ip": "80.94.92.168", "src_port": 48608, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:43:25.852308+0100", "src_ip": "80.94.92.168", "dest_ip": "134.19.55.199", "src_port": 48608, "dest_port": 22}}'); INSERT INTO alerts VALUES(2117,1773063807.924830914,'{"timestamp": "2026-03-09T14:43:27.924831+0100", "flow_id": 2001795378562185, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:43:27.924831+0100", "src_ip": "185.156.73.86", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44389}}'); INSERT INTO alerts VALUES(2118,1773063813.181785106,'{"timestamp": "2026-03-09T14:43:33.181785+0100", "flow_id": 1625188180186771, "event_type": "alert", "src_ip": "45.142.154.10", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 8983, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:43:33.181785+0100", "src_ip": "45.142.154.10", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 8983}}'); INSERT INTO alerts VALUES(2119,1773063814.485668897,'{"timestamp": "2026-03-09T14:43:34.485669+0100", "flow_id": 1804460389314430, "event_type": "alert", "src_ip": "159.89.95.31", "src_port": 53736, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:43:34.485669+0100", "src_ip": "159.89.95.31", "dest_ip": "134.19.55.199", "src_port": 53736, "dest_port": 5432}}'); INSERT INTO alerts VALUES(2120,1773063821.816755056,'{"timestamp": "2026-03-09T14:43:41.816755+0100", "flow_id": 1537614520613481, "event_type": "alert", "src_ip": "193.163.125.205", "src_port": 42081, "dest_ip": "134.19.55.199", "dest_port": 50501, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:43:41.816755+0100", "src_ip": "193.163.125.205", "dest_ip": "134.19.55.199", "src_port": 42081, "dest_port": 50501}}'); INSERT INTO alerts VALUES(2121,1773063870.125132083,'{"timestamp": "2026-03-09T14:44:30.125132+0100", "flow_id": 1944816386453908, "event_type": "alert", "src_ip": "65.49.1.111", "src_port": 41470, "dest_ip": "134.19.55.199", "dest_port": 4002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:44:30.125132+0100", "src_ip": "65.49.1.111", "dest_ip": "134.19.55.199", "src_port": 41470, "dest_port": 4002}}'); INSERT INTO alerts VALUES(2122,1773063875.235711097,'{"timestamp": "2026-03-09T14:44:35.235711+0100", "flow_id": 1012371714909228, "event_type": "alert", "src_ip": "176.65.139.12", "src_port": 53951, "dest_ip": "134.19.55.199", "dest_port": 17000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:44:35.235711+0100", "src_ip": "176.65.139.12", "dest_ip": "134.19.55.199", "src_port": 53951, "dest_port": 17000}}'); INSERT INTO alerts VALUES(2123,1773063889.753232003,'{"timestamp": "2026-03-09T14:44:49.753232+0100", "flow_id": 420360059329019, "event_type": "alert", "src_ip": "64.62.156.63", "src_port": 17381, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:44:49.753232+0100", "src_ip": "64.62.156.63", "dest_ip": "134.19.55.199", "src_port": 17381, "dest_port": 3389}}'); INSERT INTO alerts VALUES(2124,1773063896.648020029,'{"timestamp": "2026-03-09T14:44:56.648020+0100", "flow_id": 249952105463389, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 46162, "dest_ip": "134.19.55.199", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:44:56.648020+0100", "src_ip": "193.142.146.230", "dest_ip": "134.19.55.199", "src_port": 46162, "dest_port": 8888}}'); INSERT INTO alerts VALUES(2125,1773063941.006138087,'{"timestamp": "2026-03-09T14:45:41.006138+0100", "flow_id": 1433737790711203, "event_type": "alert", "src_ip": "193.163.125.197", "src_port": 56965, "dest_ip": "134.19.55.199", "dest_port": 60002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T14:45:41.006138+0100", "src_ip": "193.163.125.197", "dest_ip": "134.19.55.199", "src_port": 56965, "dest_port": 60002}}'); INSERT INTO alerts VALUES(2126,1773063989.584237098,'{"timestamp": "2026-03-09T14:46:29.584237+0100", "flow_id": 1664857436018325, "event_type": "alert", "src_ip": "185.242.226.65", "src_port": 51923, "dest_ip": "134.19.55.199", "dest_port": 2054, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 57, "bytes_toclient": 0, "start": "2026-03-09T14:46:29.584237+0100", "src_ip": "185.242.226.65", "dest_ip": "134.19.55.199", "src_port": 51923, "dest_port": 2054}}'); INSERT INTO alerts VALUES(2127,1773064048.131127119,'{"timestamp": "2026-03-09T14:47:28.131127+0100", "flow_id": 237564954360, "event_type": "alert", "src_ip": "195.184.76.183", "src_port": 60291, "dest_ip": "134.19.55.199", "dest_port": 5265, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:47:28.131127+0100", "src_ip": "195.184.76.183", "dest_ip": "134.19.55.199", "src_port": 60291, "dest_port": 5265}}'); INSERT INTO alerts VALUES(2128,1773064114.01600194,'{"timestamp": "2026-03-09T14:48:34.016002+0100", "flow_id": 631680144046010, "event_type": "alert", "src_ip": "176.65.149.234", "src_port": 50556, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:48:34.016002+0100", "src_ip": "176.65.149.234", "dest_ip": "134.19.55.199", "src_port": 50556, "dest_port": 80}}'); INSERT INTO alerts VALUES(2129,1773064172.851739884,'{"timestamp": "2026-03-09T14:49:32.851740+0100", "flow_id": 1406398588518938, "event_type": "alert", "src_ip": "64.62.156.198", "src_port": 36501, "dest_ip": "134.19.55.199", "dest_port": 2001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:49:32.851740+0100", "src_ip": "64.62.156.198", "dest_ip": "134.19.55.199", "src_port": 36501, "dest_port": 2001}}'); INSERT INTO alerts VALUES(2130,1773064179.496238946,'{"timestamp": "2026-03-09T14:49:39.496239+0100", "flow_id": 1005433915057428, "event_type": "alert", "src_ip": "36.111.81.124", "src_port": 42540, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:49:39.496239+0100", "src_ip": "36.111.81.124", "dest_ip": "134.19.55.199", "src_port": 42540, "dest_port": 5432}}'); INSERT INTO alerts VALUES(2131,1773064180.500292063,'{"timestamp": "2026-03-09T14:49:40.500292+0100", "flow_id": 1005433915057428, "event_type": "alert", "src_ip": "36.111.81.124", "src_port": 42540, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 120, "bytes_toclient": 0, "start": "2026-03-09T14:49:39.496239+0100", "src_ip": "36.111.81.124", "dest_ip": "134.19.55.199", "src_port": 42540, "dest_port": 5432}}'); INSERT INTO alerts VALUES(2132,1773064202.1356349,'{"timestamp": "2026-03-09T14:50:02.135635+0100", "flow_id": 582551369852078, "event_type": "alert", "src_ip": "64.62.156.123", "src_port": 35334, "dest_ip": "134.19.55.199", "dest_port": 3001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:50:02.135635+0100", "src_ip": "64.62.156.123", "dest_ip": "134.19.55.199", "src_port": 35334, "dest_port": 3001}}'); INSERT INTO alerts VALUES(2133,1773064288.986684084,'{"timestamp": "2026-03-09T14:51:28.986684+0100", "flow_id": 15653396250900, "event_type": "alert", "src_ip": "96.127.153.174", "src_port": 6430, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 438, "bytes_toclient": 0, "start": "2026-03-09T14:51:28.986684+0100", "src_ip": "96.127.153.174", "dest_ip": "134.19.55.199", "src_port": 6430, "dest_port": 5060}}'); INSERT INTO alerts VALUES(2134,1773064288.986684084,'{"timestamp": "2026-03-09T14:51:28.986684+0100", "flow_id": 15653396250900, "event_type": "alert", "src_ip": "96.127.153.174", "src_port": 6430, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 438, "bytes_toclient": 0, "start": "2026-03-09T14:51:28.986684+0100", "src_ip": "96.127.153.174", "dest_ip": "134.19.55.199", "src_port": 6430, "dest_port": 5060}}'); INSERT INTO alerts VALUES(2135,1773064310.534759998,'{"timestamp": "2026-03-09T14:51:50.534760+0100", "flow_id": 1733829315709351, "event_type": "alert", "src_ip": "64.62.197.86", "src_port": 42743, "dest_ip": "134.19.55.199", "dest_port": 5001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:51:50.534760+0100", "src_ip": "64.62.197.86", "dest_ip": "134.19.55.199", "src_port": 42743, "dest_port": 5001}}'); INSERT INTO alerts VALUES(2136,1773064578.363396883,'{"timestamp": "2026-03-09T14:56:18.363397+0100", "flow_id": 716355156966469, "event_type": "alert", "src_ip": "167.94.138.128", "src_port": 44685, "dest_ip": "134.19.55.199", "dest_port": 7170, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T14:56:18.363397+0100", "src_ip": "167.94.138.128", "dest_ip": "134.19.55.199", "src_port": 44685, "dest_port": 7170}}'); INSERT INTO alerts VALUES(2137,1773064623.866481066,'{"timestamp": "2026-03-09T14:57:03.866481+0100", "flow_id": 2032658630913815, "event_type": "alert", "src_ip": "64.62.197.108", "src_port": 47340, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:57:03.866481+0100", "src_ip": "64.62.197.108", "dest_ip": "134.19.55.199", "src_port": 47340, "dest_port": 27017}}'); INSERT INTO alerts VALUES(2138,1773064641.213131905,'{"timestamp": "2026-03-09T14:57:21.213132+0100", "flow_id": 352447698672241, "event_type": "alert", "src_ip": "65.49.1.76", "src_port": 41391, "dest_ip": "134.19.55.199", "dest_port": 5803, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:57:21.213132+0100", "src_ip": "65.49.1.76", "dest_ip": "134.19.55.199", "src_port": 41391, "dest_port": 5803}}'); INSERT INTO alerts VALUES(2139,1773064657.310889005,'{"timestamp": "2026-03-09T14:57:37.310889+0100", "flow_id": 490835985751420, "event_type": "alert", "src_ip": "162.217.98.180", "src_port": 39212, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 411, "bytes_toclient": 0, "start": "2026-03-09T14:57:37.310889+0100", "src_ip": "162.217.98.180", "dest_ip": "134.19.55.199", "src_port": 39212, "dest_port": 5060}}'); INSERT INTO alerts VALUES(2140,1773064687.093149901,'{"timestamp": "2026-03-09T14:58:07.093150+0100", "flow_id": 2088929877059368, "event_type": "alert", "src_ip": "64.62.156.230", "src_port": 57429, "dest_ip": "134.19.55.199", "dest_port": 8883, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:58:07.093150+0100", "src_ip": "64.62.156.230", "dest_ip": "134.19.55.199", "src_port": 57429, "dest_port": 8883}}'); INSERT INTO alerts VALUES(2141,1773064793.330890894,'{"timestamp": "2026-03-09T14:59:53.330891+0100", "flow_id": 295267805278822, "event_type": "alert", "src_ip": "64.62.156.205", "src_port": 50519, "dest_ip": "134.19.55.199", "dest_port": 102, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T14:59:53.330891+0100", "src_ip": "64.62.156.205", "dest_ip": "134.19.55.199", "src_port": 50519, "dest_port": 102}}'); INSERT INTO alerts VALUES(2142,1773064824.839629888,'{"timestamp": "2026-03-09T15:00:24.839630+0100", "flow_id": 228485095762843, "event_type": "alert", "src_ip": "45.142.154.86", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 6688, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:00:24.839630+0100", "src_ip": "45.142.154.86", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 6688}}'); INSERT INTO alerts VALUES(2143,1773064873.867058038,'{"timestamp": "2026-03-09T15:01:13.867058+0100", "flow_id": 346286693250759, "event_type": "alert", "src_ip": "185.242.226.103", "src_port": 35395, "dest_ip": "134.19.55.199", "dest_port": 5952, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:01:13.867058+0100", "src_ip": "185.242.226.103", "dest_ip": "134.19.55.199", "src_port": 35395, "dest_port": 5952}}'); INSERT INTO alerts VALUES(2144,1773064893.395236968,'{"timestamp": "2026-03-09T15:01:33.395237+0100", "flow_id": 1416057003066666, "event_type": "alert", "src_ip": "64.62.156.55", "src_port": 56987, "dest_ip": "134.19.55.199", "dest_port": 20256, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:01:33.395237+0100", "src_ip": "64.62.156.55", "dest_ip": "134.19.55.199", "src_port": 56987, "dest_port": 20256}}'); INSERT INTO alerts VALUES(2145,1773064918.797432899,'{"timestamp": "2026-03-09T15:01:58.797433+0100", "flow_id": 1736100188322313, "event_type": "alert", "src_ip": "65.49.1.232", "src_port": 54587, "dest_ip": "134.19.55.199", "dest_port": 143, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:01:58.797433+0100", "src_ip": "65.49.1.232", "dest_ip": "134.19.55.199", "src_port": 54587, "dest_port": 143}}'); INSERT INTO alerts VALUES(2146,1773064939.809062004,'{"timestamp": "2026-03-09T15:02:19.809062+0100", "flow_id": 941623600151486, "event_type": "alert", "src_ip": "130.12.180.52", "src_port": 59044, "dest_ip": "134.19.55.199", "dest_port": 9090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:02:19.809062+0100", "src_ip": "130.12.180.52", "dest_ip": "134.19.55.199", "src_port": 59044, "dest_port": 9090}}'); INSERT INTO alerts VALUES(2147,1773064939.809062004,'{"timestamp": "2026-03-09T15:02:19.809062+0100", "flow_id": 941623600151486, "event_type": "alert", "src_ip": "130.12.180.52", "src_port": 59044, "dest_ip": "134.19.55.199", "dest_port": 9090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:02:19.809062+0100", "src_ip": "130.12.180.52", "dest_ip": "134.19.55.199", "src_port": 59044, "dest_port": 9090}}'); INSERT INTO alerts VALUES(2148,1773065049.570013999,'{"timestamp": "2026-03-09T15:04:09.570014+0100", "flow_id": 477870677590650, "event_type": "alert", "src_ip": "34.118.59.79", "src_port": 45432, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:04:09.570014+0100", "src_ip": "34.118.59.79", "dest_ip": "134.19.55.199", "src_port": 45432, "dest_port": 5432}}'); INSERT INTO alerts VALUES(2149,1773065109.507356883,'{"timestamp": "2026-03-09T15:05:09.507357+0100", "flow_id": 1616131947174698, "event_type": "alert", "src_ip": "185.242.3.212", "src_port": 48703, "dest_ip": "134.19.55.199", "dest_port": 65432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:05:09.507357+0100", "src_ip": "185.242.3.212", "dest_ip": "134.19.55.199", "src_port": 48703, "dest_port": 65432}}'); INSERT INTO alerts VALUES(2150,1773065128.142519951,'{"timestamp": "2026-03-09T15:05:28.142520+0100", "flow_id": 49172824543955, "event_type": "alert", "src_ip": "64.62.156.27", "src_port": 56900, "dest_ip": "134.19.55.199", "dest_port": 2375, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:05:28.142520+0100", "src_ip": "64.62.156.27", "dest_ip": "134.19.55.199", "src_port": 56900, "dest_port": 2375}}'); INSERT INTO alerts VALUES(2151,1773065135.454318047,'{"timestamp": "2026-03-09T15:05:35.454318+0100", "flow_id": 2232758394356716, "event_type": "alert", "src_ip": "65.49.1.185", "src_port": 52015, "dest_ip": "134.19.55.199", "dest_port": 4369, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:05:35.454318+0100", "src_ip": "65.49.1.185", "dest_ip": "134.19.55.199", "src_port": 52015, "dest_port": 4369}}'); INSERT INTO alerts VALUES(2152,1773065144.904782057,'{"timestamp": "2026-03-09T15:05:44.904782+0100", "flow_id": 226837953764153, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 65091, "dest_ip": "134.19.55.199", "dest_port": 31136, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:05:44.904782+0100", "src_ip": "167.94.146.32", "dest_ip": "134.19.55.199", "src_port": 65091, "dest_port": 31136}}'); INSERT INTO alerts VALUES(2153,1773065163.37078309,'{"timestamp": "2026-03-09T15:06:03.370783+0100", "flow_id": 1029552694220628, "event_type": "alert", "src_ip": "64.62.197.91", "src_port": 49323, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:06:03.370783+0100", "src_ip": "64.62.197.91", "dest_ip": "134.19.55.199", "src_port": 49323, "dest_port": 22}}'); INSERT INTO alerts VALUES(2154,1773065420.830764055,'{"timestamp": "2026-03-09T15:10:20.830764+0100", "flow_id": 1316304474757923, "event_type": "alert", "src_ip": "64.62.156.140", "src_port": 53276, "dest_ip": "134.19.55.199", "dest_port": 995, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:10:20.830764+0100", "src_ip": "64.62.156.140", "dest_ip": "134.19.55.199", "src_port": 53276, "dest_port": 995}}'); INSERT INTO alerts VALUES(2155,1773065480.561678886,'{"timestamp": "2026-03-09T15:11:20.561679+0100", "flow_id": 160596953857419, "event_type": "alert", "src_ip": "64.62.197.209", "src_port": 48288, "dest_ip": "134.19.55.199", "dest_port": 49667, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:11:20.561679+0100", "src_ip": "64.62.197.209", "dest_ip": "134.19.55.199", "src_port": 48288, "dest_port": 49667}}'); INSERT INTO alerts VALUES(2156,1773065505.515326976,'{"timestamp": "2026-03-09T15:11:45.515327+0100", "flow_id": 524465596127941, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 41287, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:11:45.515327+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 41287, "dest_port": 3389}}'); INSERT INTO alerts VALUES(2157,1773065571.586620093,'{"timestamp": "2026-03-09T15:12:51.586620+0100", "flow_id": 1112141172918403, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 10960, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:12:51.586620+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 10960}}'); INSERT INTO alerts VALUES(2158,1773065635.554182053,'{"timestamp": "2026-03-09T15:13:55.554182+0100", "flow_id": 972819198383682, "event_type": "alert", "src_ip": "193.163.125.183", "src_port": 50474, "dest_ip": "134.19.55.199", "dest_port": 4262, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:13:55.554182+0100", "src_ip": "193.163.125.183", "dest_ip": "134.19.55.199", "src_port": 50474, "dest_port": 4262}}'); INSERT INTO alerts VALUES(2159,1773065648.732316017,'{"timestamp": "2026-03-09T15:14:08.732316+0100", "flow_id": 49052178490232, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 43369, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:14:08.732316+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 43369, "dest_port": 3389}}'); INSERT INTO alerts VALUES(2160,1773065680.35401392,'{"timestamp": "2026-03-09T15:14:40.354014+0100", "flow_id": 113106997326758, "event_type": "alert", "src_ip": "176.65.134.22", "src_port": 33715, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:14:40.354014+0100", "src_ip": "176.65.134.22", "dest_ip": "134.19.55.199", "src_port": 33715, "dest_port": 22}}'); INSERT INTO alerts VALUES(2161,1773065757.021567107,'{"timestamp": "2026-03-09T15:15:57.021567+0100", "flow_id": 1500006339071678, "event_type": "alert", "src_ip": "64.62.156.144", "src_port": 57330, "dest_ip": "134.19.55.199", "dest_port": 25, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:15:57.021567+0100", "src_ip": "64.62.156.144", "dest_ip": "134.19.55.199", "src_port": 57330, "dest_port": 25}}'); INSERT INTO alerts VALUES(2162,1773065800.10508895,'{"timestamp": "2026-03-09T15:16:40.105089+0100", "flow_id": 169879629058786, "event_type": "alert", "src_ip": "64.62.197.117", "src_port": 50266, "dest_ip": "134.19.55.199", "dest_port": 18245, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:16:40.105089+0100", "src_ip": "64.62.197.117", "dest_ip": "134.19.55.199", "src_port": 50266, "dest_port": 18245}}'); INSERT INTO alerts VALUES(2163,1773065853.764383077,'{"timestamp": "2026-03-09T15:17:33.764383+0100", "flow_id": 1594153903542032, "event_type": "alert", "src_ip": "64.62.156.220", "src_port": 33963, "dest_ip": "134.19.55.199", "dest_port": 1723, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:17:33.764383+0100", "src_ip": "64.62.156.220", "dest_ip": "134.19.55.199", "src_port": 33963, "dest_port": 1723}}'); INSERT INTO alerts VALUES(2164,1773065873.311342954,'{"timestamp": "2026-03-09T15:17:53.311343+0100", "flow_id": 492785921993806, "event_type": "alert", "src_ip": "147.203.255.20", "src_port": 51114, "dest_ip": "134.19.55.199", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T15:17:53.311343+0100", "src_ip": "147.203.255.20", "dest_ip": "134.19.55.199", "src_port": 51114, "dest_port": 161}}'); INSERT INTO alerts VALUES(2165,1773065908.273494006,'{"timestamp": "2026-03-09T15:18:28.273494+0100", "flow_id": 1174649874126637, "event_type": "alert", "src_ip": "176.65.148.204", "src_port": 42706, "dest_ip": "134.19.55.199", "dest_port": 25585, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:18:28.273494+0100", "src_ip": "176.65.148.204", "dest_ip": "134.19.55.199", "src_port": 42706, "dest_port": 25585}}'); INSERT INTO alerts VALUES(2166,1773065908.273494006,'{"timestamp": "2026-03-09T15:18:28.273494+0100", "flow_id": 1174649874126637, "event_type": "alert", "src_ip": "176.65.148.204", "src_port": 42706, "dest_ip": "134.19.55.199", "dest_port": 25585, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:18:28.273494+0100", "src_ip": "176.65.148.204", "dest_ip": "134.19.55.199", "src_port": 42706, "dest_port": 25585}}'); INSERT INTO alerts VALUES(2167,1773065974.036427975,'{"timestamp": "2026-03-09T15:19:34.036428+0100", "flow_id": 1845309447539460, "event_type": "alert", "src_ip": "65.49.1.190", "src_port": 54478, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:19:34.036428+0100", "src_ip": "65.49.1.190", "dest_ip": "134.19.55.199", "src_port": 54478, "dest_port": 3389}}'); INSERT INTO alerts VALUES(2168,1773065979.123836994,'{"timestamp": "2026-03-09T15:19:39.123837+0100", "flow_id": 1094829786801653, "event_type": "alert", "src_ip": "193.163.125.208", "src_port": 34506, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:19:39.123837+0100", "src_ip": "193.163.125.208", "dest_ip": "134.19.55.199", "src_port": 34506, "dest_port": 8080}}'); INSERT INTO alerts VALUES(2169,1773066021.613192082,'{"timestamp": "2026-03-09T15:20:21.613192+0100", "flow_id": 1507742167600377, "event_type": "alert", "src_ip": "91.196.152.228", "src_port": 46806, "dest_ip": "134.19.55.199", "dest_port": 2404, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:20:21.613192+0100", "src_ip": "91.196.152.228", "dest_ip": "134.19.55.199", "src_port": 46806, "dest_port": 2404}}'); INSERT INTO alerts VALUES(2170,1773066079.267589093,'{"timestamp": "2026-03-09T15:21:19.267589+0100", "flow_id": 1993714036972836, "event_type": "alert", "src_ip": "195.184.76.177", "src_port": 1601, "dest_ip": "134.19.55.199", "dest_port": 5270, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:21:19.267589+0100", "src_ip": "195.184.76.177", "dest_ip": "134.19.55.199", "src_port": 1601, "dest_port": 5270}}'); INSERT INTO alerts VALUES(2171,1773066142.348815917,'{"timestamp": "2026-03-09T15:22:22.348816+0100", "flow_id": 1779628815696405, "event_type": "alert", "src_ip": "193.163.125.185", "src_port": 34395, "dest_ip": "134.19.55.199", "dest_port": 7547, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:22:22.348816+0100", "src_ip": "193.163.125.185", "dest_ip": "134.19.55.199", "src_port": 34395, "dest_port": 7547}}'); INSERT INTO alerts VALUES(2172,1773066179.763227939,'{"timestamp": "2026-03-09T15:22:59.763228+0100", "flow_id": 1026243281426627, "event_type": "alert", "src_ip": "167.94.138.155", "src_port": 47563, "dest_ip": "134.19.55.199", "dest_port": 503, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:22:59.763228+0100", "src_ip": "167.94.138.155", "dest_ip": "134.19.55.199", "src_port": 47563, "dest_port": 503}}'); INSERT INTO alerts VALUES(2173,1773066200.410139084,'{"timestamp": "2026-03-09T15:23:20.410139+0100", "flow_id": 72685753093759, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 46202, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:23:20.410139+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 46202, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2174,1773066217.743957997,'{"timestamp": "2026-03-09T15:23:37.743958+0100", "flow_id": 380529554195087, "event_type": "alert", "src_ip": "65.49.1.104", "src_port": 45161, "dest_ip": "134.19.55.199", "dest_port": 5556, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:23:37.743958+0100", "src_ip": "65.49.1.104", "dest_ip": "134.19.55.199", "src_port": 45161, "dest_port": 5556}}'); INSERT INTO alerts VALUES(2175,1773066304.109466076,'{"timestamp": "2026-03-09T15:25:04.109466+0100", "flow_id": 188679224396068, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 40854, "dest_ip": "134.19.55.199", "dest_port": 21, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:25:04.109466+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 40854, "dest_port": 21}}'); INSERT INTO alerts VALUES(2176,1773066311.660806895,'{"timestamp": "2026-03-09T15:25:11.660807+0100", "flow_id": 1993723763245650, "event_type": "alert", "src_ip": "40.124.172.38", "src_port": 37753, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T15:25:11.660807+0100", "src_ip": "40.124.172.38", "dest_ip": "134.19.55.199", "src_port": 37753, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2177,1773066349.941337108,'{"timestamp": "2026-03-09T15:25:49.941337+0100", "flow_id": 1509738492137298, "event_type": "alert", "src_ip": "66.132.153.157", "src_port": 5190, "dest_ip": "134.19.55.199", "dest_port": 2052, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:25:49.941337+0100", "src_ip": "66.132.153.157", "dest_ip": "134.19.55.199", "src_port": 5190, "dest_port": 2052}}'); INSERT INTO alerts VALUES(2178,1773066384.620065928,'{"timestamp": "2026-03-09T15:26:24.620066+0100", "flow_id": 129888509061057, "event_type": "alert", "src_ip": "193.163.125.201", "src_port": 39888, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:26:24.620066+0100", "src_ip": "193.163.125.201", "dest_ip": "134.19.55.199", "src_port": 39888, "dest_port": 5060}}'); INSERT INTO alerts VALUES(2179,1773066455.8166461,'{"timestamp": "2026-03-09T15:27:35.816646+0100", "flow_id": 2100096674803277, "event_type": "alert", "src_ip": "87.121.84.76", "src_port": 50167, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:27:35.816646+0100", "src_ip": "87.121.84.76", "dest_ip": "134.19.55.199", "src_port": 50167, "dest_port": 80}}'); INSERT INTO alerts VALUES(2180,1773066457.082921028,'{"timestamp": "2026-03-09T15:27:37.082921+0100", "flow_id": 356144334547518, "event_type": "alert", "src_ip": "45.142.154.99", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 30005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:27:37.082921+0100", "src_ip": "45.142.154.99", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 30005}}'); INSERT INTO alerts VALUES(2181,1773066484.586755991,'{"timestamp": "2026-03-09T15:28:04.586756+0100", "flow_id": 1394201668464084, "event_type": "alert", "src_ip": "65.49.1.78", "src_port": 33097, "dest_ip": "134.19.55.199", "dest_port": 212, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:28:04.586756+0100", "src_ip": "65.49.1.78", "dest_ip": "134.19.55.199", "src_port": 33097, "dest_port": 212}}'); INSERT INTO alerts VALUES(2182,1773066531.534163952,'{"timestamp": "2026-03-09T15:28:51.534164+0100", "flow_id": 886845038286743, "event_type": "alert", "src_ip": "176.65.149.215", "src_port": 34875, "dest_ip": "134.19.55.199", "dest_port": 8443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:28:51.534164+0100", "src_ip": "176.65.149.215", "dest_ip": "134.19.55.199", "src_port": 34875, "dest_port": 8443}}'); INSERT INTO alerts VALUES(2183,1773066602.358814001,'{"timestamp": "2026-03-09T15:30:02.358814+0100", "flow_id": 696673037060485, "event_type": "alert", "src_ip": "45.156.87.50", "src_port": 48997, "dest_ip": "134.19.55.199", "dest_port": 17000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:30:02.358814+0100", "src_ip": "45.156.87.50", "dest_ip": "134.19.55.199", "src_port": 48997, "dest_port": 17000}}'); INSERT INTO alerts VALUES(2184,1773066616.227097035,'{"timestamp": "2026-03-09T15:30:16.227097+0100", "flow_id": 130949380728098, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 46435, "dest_ip": "134.19.55.199", "dest_port": 3307, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:30:16.227097+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 46435, "dest_port": 3307}}'); INSERT INTO alerts VALUES(2185,1773066646.697594881,'{"timestamp": "2026-03-09T15:30:46.697595+0100", "flow_id": 1870250490681719, "event_type": "alert", "src_ip": "64.62.197.138", "src_port": 56445, "dest_ip": "134.19.55.199", "dest_port": 49664, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:30:46.697595+0100", "src_ip": "64.62.197.138", "dest_ip": "134.19.55.199", "src_port": 56445, "dest_port": 49664}}'); INSERT INTO alerts VALUES(2186,1773066647.649941922,'{"timestamp": "2026-03-09T15:30:47.649942+0100", "flow_id": 2228531031973571, "event_type": "alert", "src_ip": "167.94.146.34", "src_port": 59669, "dest_ip": "134.19.55.199", "dest_port": 28890, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:30:47.649942+0100", "src_ip": "167.94.146.34", "dest_ip": "134.19.55.199", "src_port": 59669, "dest_port": 28890}}'); INSERT INTO alerts VALUES(2187,1773066667.310560942,'{"timestamp": "2026-03-09T15:31:07.310561+0100", "flow_id": 1052374386013310, "event_type": "alert", "src_ip": "64.62.197.185", "src_port": 56391, "dest_ip": "134.19.55.199", "dest_port": 5801, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:31:07.310561+0100", "src_ip": "64.62.197.185", "dest_ip": "134.19.55.199", "src_port": 56391, "dest_port": 5801}}'); INSERT INTO alerts VALUES(2188,1773066700.864877939,'{"timestamp": "2026-03-09T15:31:40.864878+0100", "flow_id": 1181348261250366, "event_type": "alert", "src_ip": "64.62.156.185", "src_port": 36055, "dest_ip": "134.19.55.199", "dest_port": 57722, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:31:40.864878+0100", "src_ip": "64.62.156.185", "dest_ip": "134.19.55.199", "src_port": 36055, "dest_port": 57722}}'); INSERT INTO alerts VALUES(2189,1773066806.795126915,'{"timestamp": "2026-03-09T15:33:26.795127+0100", "flow_id": 1726195947270442, "event_type": "alert", "src_ip": "91.196.152.221", "src_port": 49148, "dest_ip": "134.19.55.199", "dest_port": 20090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:33:26.795127+0100", "src_ip": "91.196.152.221", "dest_ip": "134.19.55.199", "src_port": 49148, "dest_port": 20090}}'); INSERT INTO alerts VALUES(2190,1773066818.668965102,'{"timestamp": "2026-03-09T15:33:38.668965+0100", "flow_id": 621386267290058, "event_type": "alert", "src_ip": "176.65.148.92", "src_port": 46720, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:33:38.668965+0100", "src_ip": "176.65.148.92", "dest_ip": "134.19.55.199", "src_port": 46720, "dest_port": 3389}}'); INSERT INTO alerts VALUES(2191,1773066818.668965102,'{"timestamp": "2026-03-09T15:33:38.668965+0100", "flow_id": 621386267290058, "event_type": "alert", "src_ip": "176.65.148.92", "src_port": 46720, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:33:38.668965+0100", "src_ip": "176.65.148.92", "dest_ip": "134.19.55.199", "src_port": 46720, "dest_port": 3389}}'); INSERT INTO alerts VALUES(2192,1773066833.916259051,'{"timestamp": "2026-03-09T15:33:53.916259+0100", "flow_id": 557604255220787, "event_type": "alert", "src_ip": "91.196.152.125", "src_port": 18935, "dest_ip": "134.19.55.199", "dest_port": 20069, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:33:53.916259+0100", "src_ip": "91.196.152.125", "dest_ip": "134.19.55.199", "src_port": 18935, "dest_port": 20069}}'); INSERT INTO alerts VALUES(2193,1773066906.06782198,'{"timestamp": "2026-03-09T15:35:06.067822+0100", "flow_id": 572771546699056, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52216, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2049132, "rev": 1, "signature": "ET INFO Supabase Development Platform Related Domain in DNS Lookup", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2023_11_09"], "deployment": ["Perimeter"], "performance_impact": ["Low"], "reviewed_at": ["2024_04_09"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2023_11_09"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3400, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "uagvwyhbnlutltxparir.supabase.co", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-09T15:35:06.067822+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52216, "dest_port": 53}}'); INSERT INTO alerts VALUES(2194,1773066906.069649934,'{"timestamp": "2026-03-09T15:35:06.069650+0100", "flow_id": 580622809525087, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64311, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2049132, "rev": 1, "signature": "ET INFO Supabase Development Platform Related Domain in DNS Lookup", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2023_11_09"], "deployment": ["Perimeter"], "performance_impact": ["Low"], "reviewed_at": ["2024_04_09"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2023_11_09"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55305, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "uagvwyhbnlutltxparir.supabase.co", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-09T15:35:06.069650+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64311, "dest_port": 53}}'); INSERT INTO alerts VALUES(2195,1773066925.057791949,'{"timestamp": "2026-03-09T15:35:25.057792+0100", "flow_id": 1655591390304423, "event_type": "alert", "src_ip": "195.184.76.213", "src_port": 15461, "dest_ip": "134.19.55.199", "dest_port": 6106, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:35:25.057792+0100", "src_ip": "195.184.76.213", "dest_ip": "134.19.55.199", "src_port": 15461, "dest_port": 6106}}'); INSERT INTO alerts VALUES(2196,1773066925.443777084,'{"timestamp": "2026-03-09T15:35:25.443777+0100", "flow_id": 1624533066425260, "event_type": "alert", "src_ip": "91.196.152.213", "src_port": 10083, "dest_ip": "134.19.55.199", "dest_port": 2111, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:35:25.443777+0100", "src_ip": "91.196.152.213", "dest_ip": "134.19.55.199", "src_port": 10083, "dest_port": 2111}}'); INSERT INTO alerts VALUES(2197,1773066937.46409893,'{"timestamp": "2026-03-09T15:35:37.464099+0100", "flow_id": 304443357031727, "event_type": "alert", "src_ip": "195.184.76.205", "src_port": 9491, "dest_ip": "134.19.55.199", "dest_port": 5906, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:35:37.464099+0100", "src_ip": "195.184.76.205", "dest_ip": "134.19.55.199", "src_port": 9491, "dest_port": 5906}}'); INSERT INTO alerts VALUES(2198,1773066939.617372036,'{"timestamp": "2026-03-09T15:35:39.617372+0100", "flow_id": 962745424818235, "event_type": "alert", "src_ip": "195.184.76.69", "src_port": 16913, "dest_ip": "134.19.55.199", "dest_port": 6122, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:35:39.617372+0100", "src_ip": "195.184.76.69", "dest_ip": "134.19.55.199", "src_port": 16913, "dest_port": 6122}}'); INSERT INTO alerts VALUES(2199,1773066941.42583704,'{"timestamp": "2026-03-09T15:35:41.425837+0100", "flow_id": 1547483837352576, "event_type": "alert", "src_ip": "195.184.76.21", "src_port": 55640, "dest_ip": "134.19.55.199", "dest_port": 5701, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:35:41.425837+0100", "src_ip": "195.184.76.21", "dest_ip": "134.19.55.199", "src_port": 55640, "dest_port": 5701}}'); INSERT INTO alerts VALUES(2200,1773066953.162565946,'{"timestamp": "2026-03-09T15:35:53.162566+0100", "flow_id": 416744630733682, "event_type": "alert", "src_ip": "195.184.76.245", "src_port": 41222, "dest_ip": "134.19.55.199", "dest_port": 65533, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:35:53.162566+0100", "src_ip": "195.184.76.245", "dest_ip": "134.19.55.199", "src_port": 41222, "dest_port": 65533}}'); INSERT INTO alerts VALUES(2201,1773066961.582087993,'{"timestamp": "2026-03-09T15:36:01.582088+0100", "flow_id": 529727034071013, "event_type": "alert", "src_ip": "64.62.156.133", "src_port": 60359, "dest_ip": "134.19.55.199", "dest_port": 20000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:36:01.582088+0100", "src_ip": "64.62.156.133", "dest_ip": "134.19.55.199", "src_port": 60359, "dest_port": 20000}}'); INSERT INTO alerts VALUES(2202,1773066963.394800901,'{"timestamp": "2026-03-09T15:36:03.394801+0100", "flow_id": 851233586263551, "event_type": "alert", "src_ip": "167.94.138.149", "src_port": 49959, "dest_ip": "134.19.55.199", "dest_port": 2222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:36:03.394801+0100", "src_ip": "167.94.138.149", "dest_ip": "134.19.55.199", "src_port": 49959, "dest_port": 2222}}'); INSERT INTO alerts VALUES(2203,1773066965.497725009,'{"timestamp": "2026-03-09T15:36:05.497725+0100", "flow_id": 1574763377473311, "event_type": "alert", "src_ip": "193.163.125.182", "src_port": 48969, "dest_ip": "134.19.55.199", "dest_port": 10099, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:36:05.497725+0100", "src_ip": "193.163.125.182", "dest_ip": "134.19.55.199", "src_port": 48969, "dest_port": 10099}}'); INSERT INTO alerts VALUES(2204,1773066970.384423017,'{"timestamp": "2026-03-09T15:36:10.384423+0100", "flow_id": 806663519479054, "event_type": "alert", "src_ip": "195.184.76.93", "src_port": 48046, "dest_ip": "134.19.55.199", "dest_port": 7081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:36:10.384423+0100", "src_ip": "195.184.76.93", "dest_ip": "134.19.55.199", "src_port": 48046, "dest_port": 7081}}'); INSERT INTO alerts VALUES(2205,1773067034.520795107,'{"timestamp": "2026-03-09T15:37:14.520795+0100", "flow_id": 829424640510470, "event_type": "alert", "src_ip": "167.94.146.43", "src_port": 52847, "dest_ip": "134.19.55.199", "dest_port": 40269, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:37:14.520795+0100", "src_ip": "167.94.146.43", "dest_ip": "134.19.55.199", "src_port": 52847, "dest_port": 40269}}'); INSERT INTO alerts VALUES(2206,1773067048.54186201,'{"timestamp": "2026-03-09T15:37:28.541862+0100", "flow_id": 75482216123003, "event_type": "alert", "src_ip": "64.89.163.85", "src_port": 46851, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:37:28.541862+0100", "src_ip": "64.89.163.85", "dest_ip": "134.19.55.199", "src_port": 46851, "dest_port": 27017}}'); INSERT INTO alerts VALUES(2207,1773067055.475110055,'{"timestamp": "2026-03-09T15:37:35.475110+0100", "flow_id": 2040585313367915, "event_type": "alert", "src_ip": "65.49.1.135", "src_port": 49657, "dest_ip": "134.19.55.199", "dest_port": 61617, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:37:35.475110+0100", "src_ip": "65.49.1.135", "dest_ip": "134.19.55.199", "src_port": 49657, "dest_port": 61617}}'); INSERT INTO alerts VALUES(2208,1773067135.797512054,'{"timestamp": "2026-03-09T15:38:55.797512+0100", "flow_id": 2017914290814342, "event_type": "alert", "src_ip": "167.94.146.46", "src_port": 64345, "dest_ip": "134.19.55.199", "dest_port": 22657, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:38:55.797512+0100", "src_ip": "167.94.146.46", "dest_ip": "134.19.55.199", "src_port": 64345, "dest_port": 22657}}'); INSERT INTO alerts VALUES(2209,1773067136.93076396,'{"timestamp": "2026-03-09T15:38:56.930764+0100", "flow_id": 56951996713592, "event_type": "alert", "src_ip": "64.62.156.197", "src_port": 45744, "dest_ip": "134.19.55.199", "dest_port": 5800, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:38:56.930764+0100", "src_ip": "64.62.156.197", "dest_ip": "134.19.55.199", "src_port": 45744, "dest_port": 5800}}'); INSERT INTO alerts VALUES(2210,1773067151.456516981,'{"timestamp": "2026-03-09T15:39:11.456517+0100", "flow_id": 2242203170806702, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 8000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:39:11.456517+0100", "src_ip": "204.76.203.73", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 8000}}'); INSERT INTO alerts VALUES(2211,1773067151.456516981,'{"timestamp": "2026-03-09T15:39:11.456517+0100", "flow_id": 2242203170806702, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 8000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:39:11.456517+0100", "src_ip": "204.76.203.73", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 8000}}'); INSERT INTO alerts VALUES(2212,1773067218.329178095,'{"timestamp": "2026-03-09T15:40:18.329178+0100", "flow_id": 569385930776399, "event_type": "alert", "src_ip": "64.62.156.131", "src_port": 34900, "dest_ip": "134.19.55.199", "dest_port": 5804, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:40:18.329178+0100", "src_ip": "64.62.156.131", "dest_ip": "134.19.55.199", "src_port": 34900, "dest_port": 5804}}'); INSERT INTO alerts VALUES(2213,1773067269.614572048,'{"timestamp": "2026-03-09T15:41:09.614572+0100", "flow_id": 1513667758244844, "event_type": "alert", "src_ip": "64.62.197.136", "src_port": 41516, "dest_ip": "134.19.55.199", "dest_port": 4786, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:41:09.614572+0100", "src_ip": "64.62.197.136", "dest_ip": "134.19.55.199", "src_port": 41516, "dest_port": 4786}}'); INSERT INTO alerts VALUES(2214,1773067282.371876002,'{"timestamp": "2026-03-09T15:41:22.371876+0100", "flow_id": 752773820759064, "event_type": "alert", "src_ip": "80.47.12.159", "src_port": 46225, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:41:22.371876+0100", "src_ip": "80.47.12.159", "dest_ip": "134.19.55.199", "src_port": 46225, "dest_port": 1433}}'); INSERT INTO alerts VALUES(2215,1773067300.768135071,'{"timestamp": "2026-03-09T15:41:40.768135+0100", "flow_id": 1328793138895053, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:41:40.768135+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(2216,1773067300.768135071,'{"timestamp": "2026-03-09T15:41:40.768135+0100", "flow_id": 1328793138895053, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:41:40.768135+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(2217,1773067366.967549086,'{"timestamp": "2026-03-09T15:42:46.967549+0100", "flow_id": 1903795025993662, "event_type": "alert", "src_ip": "193.163.125.199", "src_port": 45941, "dest_ip": "134.19.55.199", "dest_port": 7005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:42:46.967549+0100", "src_ip": "193.163.125.199", "dest_ip": "134.19.55.199", "src_port": 45941, "dest_port": 7005}}'); INSERT INTO alerts VALUES(2218,1773067390.28512907,'{"timestamp": "2026-03-09T15:43:10.285129+0100", "flow_id": 1787570027119001, "event_type": "alert", "src_ip": "185.242.226.113", "src_port": 41730, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T15:43:10.285129+0100", "src_ip": "185.242.226.113", "dest_ip": "134.19.55.199", "src_port": 41730, "dest_port": 80}}'); INSERT INTO alerts VALUES(2219,1773067408.707587004,'{"timestamp": "2026-03-09T15:43:28.707587+0100", "flow_id": 224315959636958, "event_type": "alert", "src_ip": "64.62.156.201", "src_port": 51131, "dest_ip": "134.19.55.199", "dest_port": 50075, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:43:28.707587+0100", "src_ip": "64.62.156.201", "dest_ip": "134.19.55.199", "src_port": 51131, "dest_port": 50075}}'); INSERT INTO alerts VALUES(2220,1773067423.580400943,'{"timestamp": "2026-03-09T15:43:43.580401+0100", "flow_id": 2211331344930231, "event_type": "alert", "src_ip": "167.94.146.38", "src_port": 63280, "dest_ip": "134.19.55.199", "dest_port": 61007, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:43:43.580401+0100", "src_ip": "167.94.146.38", "dest_ip": "134.19.55.199", "src_port": 63280, "dest_port": 61007}}'); INSERT INTO alerts VALUES(2221,1773067430.658391953,'{"timestamp": "2026-03-09T15:43:50.658392+0100", "flow_id": 1701876211687864, "event_type": "alert", "src_ip": "64.62.197.175", "src_port": 36678, "dest_ip": "134.19.55.199", "dest_port": 2000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:43:50.658392+0100", "src_ip": "64.62.197.175", "dest_ip": "134.19.55.199", "src_port": 36678, "dest_port": 2000}}'); INSERT INTO alerts VALUES(2222,1773067457.022157907,'{"timestamp": "2026-03-09T15:44:17.022158+0100", "flow_id": 376643905596276, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 56878, "dest_ip": "134.19.55.199", "dest_port": 7069, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:44:17.022158+0100", "src_ip": "79.124.40.82", "dest_ip": "134.19.55.199", "src_port": 56878, "dest_port": 7069}}'); INSERT INTO alerts VALUES(2223,1773067474.793673038,'{"timestamp": "2026-03-09T15:44:34.793673+0100", "flow_id": 594053485610368, "event_type": "alert", "src_ip": "167.94.138.124", "src_port": 21714, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:44:34.793673+0100", "src_ip": "167.94.138.124", "dest_ip": "134.19.55.199", "src_port": 21714, "dest_port": 5060}}'); INSERT INTO alerts VALUES(2224,1773067477.203636885,'{"timestamp": "2026-03-09T15:44:37.203637+0100", "flow_id": 1437564977118413, "event_type": "alert", "src_ip": "193.163.125.211", "src_port": 48159, "dest_ip": "134.19.55.199", "dest_port": 4082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:44:37.203637+0100", "src_ip": "193.163.125.211", "dest_ip": "134.19.55.199", "src_port": 48159, "dest_port": 4082}}'); INSERT INTO alerts VALUES(2225,1773067497.150701046,'{"timestamp": "2026-03-09T15:44:57.150701+0100", "flow_id": 365782198350565, "event_type": "alert", "src_ip": "167.94.146.39", "src_port": 49264, "dest_ip": "134.19.55.199", "dest_port": 53269, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:44:57.150701+0100", "src_ip": "167.94.146.39", "dest_ip": "134.19.55.199", "src_port": 49264, "dest_port": 53269}}'); INSERT INTO alerts VALUES(2226,1773067498.604958057,'{"timestamp": "2026-03-09T15:44:58.604958+0100", "flow_id": 627952356161535, "event_type": "alert", "src_ip": "66.132.153.121", "src_port": 54036, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:44:58.604958+0100", "src_ip": "66.132.153.121", "dest_ip": "134.19.55.199", "src_port": 54036, "dest_port": 5060}}'); INSERT INTO alerts VALUES(2227,1773067628.464863061,'{"timestamp": "2026-03-09T15:47:08.464863+0100", "flow_id": 1152148948229057, "event_type": "alert", "src_ip": "64.62.197.28", "src_port": 52437, "dest_ip": "134.19.55.199", "dest_port": 49665, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:47:08.464863+0100", "src_ip": "64.62.197.28", "dest_ip": "134.19.55.199", "src_port": 52437, "dest_port": 49665}}'); INSERT INTO alerts VALUES(2228,1773067643.686737061,'{"timestamp": "2026-03-09T15:47:23.686737+0100", "flow_id": 979189922863178, "event_type": "alert", "src_ip": "172.94.9.253", "src_port": 44820, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400031, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 32", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:47:23.686737+0100", "src_ip": "172.94.9.253", "dest_ip": "134.19.55.199", "src_port": 44820, "dest_port": 80}}'); INSERT INTO alerts VALUES(2229,1773067726.96774292,'{"timestamp": "2026-03-09T15:48:46.967743+0100", "flow_id": 1904625027049302, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 29443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:48:46.967743+0100", "src_ip": "185.156.73.181", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 29443}}'); INSERT INTO alerts VALUES(2230,1773067738.542519092,'{"timestamp": "2026-03-09T15:48:58.542519+0100", "flow_id": 641253686415246, "event_type": "alert", "src_ip": "185.242.226.95", "src_port": 50880, "dest_ip": "134.19.55.199", "dest_port": 8488, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:48:58.542519+0100", "src_ip": "185.242.226.95", "dest_ip": "134.19.55.199", "src_port": 50880, "dest_port": 8488}}'); INSERT INTO alerts VALUES(2231,1773067775.313903094,'{"timestamp": "2026-03-09T15:49:35.313903+0100", "flow_id": 2192628220736390, "event_type": "alert", "src_ip": "167.94.146.42", "src_port": 10914, "dest_ip": "134.19.55.199", "dest_port": 39648, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:49:35.313903+0100", "src_ip": "167.94.146.42", "dest_ip": "134.19.55.199", "src_port": 10914, "dest_port": 39648}}'); INSERT INTO alerts VALUES(2232,1773067824.042761087,'{"timestamp": "2026-03-09T15:50:24.042761+0100", "flow_id": 183657498209509, "event_type": "alert", "src_ip": "64.62.156.154", "src_port": 45000, "dest_ip": "134.19.55.199", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:50:24.042761+0100", "src_ip": "64.62.156.154", "dest_ip": "134.19.55.199", "src_port": 45000, "dest_port": 5900}}'); INSERT INTO alerts VALUES(2233,1773067926.284049035,'{"timestamp": "2026-03-09T15:52:06.284049+0100", "flow_id": 1782935310115864, "event_type": "alert", "src_ip": "64.89.163.244", "src_port": 47839, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:52:06.284049+0100", "src_ip": "64.89.163.244", "dest_ip": "134.19.55.199", "src_port": 47839, "dest_port": 27017}}'); INSERT INTO alerts VALUES(2234,1773067943.761646033,'{"timestamp": "2026-03-09T15:52:23.761646+0100", "flow_id": 2145347423633792, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 45146, "dest_ip": "134.19.55.199", "dest_port": 3022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:52:23.761646+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.55.199", "src_port": 45146, "dest_port": 3022}}'); INSERT INTO alerts VALUES(2235,1773067943.761646033,'{"timestamp": "2026-03-09T15:52:23.761646+0100", "flow_id": 2145347423633792, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 45146, "dest_ip": "134.19.55.199", "dest_port": 3022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:52:23.761646+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.55.199", "src_port": 45146, "dest_port": 3022}}'); INSERT INTO alerts VALUES(2236,1773067954.047626018,'{"timestamp": "2026-03-09T15:52:34.047626+0100", "flow_id": 767503172337010, "event_type": "alert", "src_ip": "64.62.197.43", "src_port": 56167, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 131, "bytes_toclient": 0, "start": "2026-03-09T15:52:34.047626+0100", "src_ip": "64.62.197.43", "dest_ip": "134.19.55.199", "src_port": 56167, "dest_port": 80}}'); INSERT INTO alerts VALUES(2237,1773067959.988358021,'{"timestamp": "2026-03-09T15:52:39.988358+0100", "flow_id": 1993168870116854, "event_type": "alert", "src_ip": "88.210.63.190", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 24435, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:52:39.988358+0100", "src_ip": "88.210.63.190", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 24435}}'); INSERT INTO alerts VALUES(2238,1773067989.007936955,'{"timestamp": "2026-03-09T15:53:09.007937+0100", "flow_id": 1441466011493151, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 60381, "dest_ip": "134.19.55.199", "dest_port": 18080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:53:09.007937+0100", "src_ip": "193.142.146.230", "dest_ip": "134.19.55.199", "src_port": 60381, "dest_port": 18080}}'); INSERT INTO alerts VALUES(2239,1773068003.768723965,'{"timestamp": "2026-03-09T15:53:23.768724+0100", "flow_id": 1049848704425585, "event_type": "alert", "src_ip": "87.121.84.88", "src_port": 60000, "dest_ip": "134.19.55.199", "dest_port": 22153, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:53:23.768724+0100", "src_ip": "87.121.84.88", "dest_ip": "134.19.55.199", "src_port": 60000, "dest_port": 22153}}'); INSERT INTO alerts VALUES(2240,1773068028.833424092,'{"timestamp": "2026-03-09T15:53:48.833424+0100", "flow_id": 1327732695126606, "event_type": "alert", "src_ip": "79.124.62.53", "src_port": 44331, "dest_ip": "134.19.55.199", "dest_port": 3391, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:53:48.833424+0100", "src_ip": "79.124.62.53", "dest_ip": "134.19.55.199", "src_port": 44331, "dest_port": 3391}}'); INSERT INTO alerts VALUES(2241,1773068099.103529931,'{"timestamp": "2026-03-09T15:54:59.103530+0100", "flow_id": 1007609637015807, "event_type": "alert", "src_ip": "195.184.76.219", "src_port": 14353, "dest_ip": "134.19.55.199", "dest_port": 5302, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T15:54:59.103530+0100", "src_ip": "195.184.76.219", "dest_ip": "134.19.55.199", "src_port": 14353, "dest_port": 5302}}'); INSERT INTO alerts VALUES(2242,1773068108.048947096,'{"timestamp": "2026-03-09T15:55:08.048947+0100", "flow_id": 1336129143656953, "event_type": "alert", "src_ip": "64.62.197.180", "src_port": 49535, "dest_ip": "134.19.55.199", "dest_port": 6000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:55:08.048947+0100", "src_ip": "64.62.197.180", "dest_ip": "134.19.55.199", "src_port": 49535, "dest_port": 6000}}'); INSERT INTO alerts VALUES(2243,1773068166.526796102,'{"timestamp": "2026-03-09T15:56:06.526796+0100", "flow_id": 1699623271446158, "event_type": "alert", "src_ip": "193.163.125.196", "src_port": 36027, "dest_ip": "134.19.55.199", "dest_port": 995, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:56:06.526796+0100", "src_ip": "193.163.125.196", "dest_ip": "134.19.55.199", "src_port": 36027, "dest_port": 995}}'); INSERT INTO alerts VALUES(2244,1773068182.15949893,'{"timestamp": "2026-03-09T15:56:22.159499+0100", "flow_id": 1810944172384322, "event_type": "alert", "src_ip": "193.163.125.213", "src_port": 50650, "dest_ip": "134.19.55.199", "dest_port": 3010, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:56:22.159499+0100", "src_ip": "193.163.125.213", "dest_ip": "134.19.55.199", "src_port": 50650, "dest_port": 3010}}'); INSERT INTO alerts VALUES(2245,1773068219.650933981,'{"timestamp": "2026-03-09T15:56:59.650934+0100", "flow_id": 1106891797147401, "event_type": "alert", "src_ip": "95.215.0.144", "src_port": 60021, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:56:59.650934+0100", "src_ip": "95.215.0.144", "dest_ip": "134.19.55.199", "src_port": 60021, "dest_port": 1433}}'); INSERT INTO alerts VALUES(2246,1773068227.184986114,'{"timestamp": "2026-03-09T15:57:07.184986+0100", "flow_id": 1075986538832580, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 48015, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T15:57:07.184986+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 48015, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2247,1773068341.430881978,'{"timestamp": "2026-03-09T15:59:01.430882+0100", "flow_id": 1569151415015927, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44397, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:59:01.430882+0100", "src_ip": "185.156.73.86", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44397}}'); INSERT INTO alerts VALUES(2248,1773068375.307063102,'{"timestamp": "2026-03-09T15:59:35.307063+0100", "flow_id": 2163251937757536, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 54225, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:59:35.307063+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 54225}}'); INSERT INTO alerts VALUES(2249,1773068375.307063102,'{"timestamp": "2026-03-09T15:59:35.307063+0100", "flow_id": 2163251937757536, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 54225, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:59:35.307063+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 54225}}'); INSERT INTO alerts VALUES(2250,1773068376.843116044,'{"timestamp": "2026-03-09T15:59:36.843116+0100", "flow_id": 243459462353235, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 47855, "dest_ip": "134.19.55.199", "dest_port": 3485, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T15:59:36.843116+0100", "src_ip": "45.142.193.7", "dest_ip": "134.19.55.199", "src_port": 47855, "dest_port": 3485}}'); INSERT INTO alerts VALUES(2251,1773068415.105457068,'{"timestamp": "2026-03-09T16:00:15.105457+0100", "flow_id": 2141787494159888, "event_type": "alert", "src_ip": "193.163.125.186", "src_port": 37218, "dest_ip": "134.19.55.199", "dest_port": 7, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:00:15.105457+0100", "src_ip": "193.163.125.186", "dest_ip": "134.19.55.199", "src_port": 37218, "dest_port": 7}}'); INSERT INTO alerts VALUES(2252,1773068446.730432033,'{"timestamp": "2026-03-09T16:00:46.730432+0100", "flow_id": 1729810423763750, "event_type": "alert", "src_ip": "167.94.138.134", "src_port": 20182, "dest_ip": "134.19.55.199", "dest_port": 18246, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:00:46.730432+0100", "src_ip": "167.94.138.134", "dest_ip": "134.19.55.199", "src_port": 20182, "dest_port": 18246}}'); INSERT INTO alerts VALUES(2253,1773068455.531917095,'{"timestamp": "2026-03-09T16:00:55.531917+0100", "flow_id": 2003094694414405, "event_type": "alert", "src_ip": "193.163.125.210", "src_port": 39609, "dest_ip": "134.19.55.199", "dest_port": 130, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:00:55.531917+0100", "src_ip": "193.163.125.210", "dest_ip": "134.19.55.199", "src_port": 39609, "dest_port": 130}}'); INSERT INTO alerts VALUES(2254,1773068468.144649983,'{"timestamp": "2026-03-09T16:01:08.144650+0100", "flow_id": 1184217942023477, "event_type": "alert", "src_ip": "64.62.197.49", "src_port": 8131, "dest_ip": "134.19.55.199", "dest_port": 10161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 113, "bytes_toclient": 0, "start": "2026-03-09T16:01:08.144650+0100", "src_ip": "64.62.197.49", "dest_ip": "134.19.55.199", "src_port": 8131, "dest_port": 10161}}'); INSERT INTO alerts VALUES(2255,1773068471.899940967,'{"timestamp": "2026-03-09T16:01:11.899941+0100", "flow_id": 2176370771494442, "event_type": "alert", "src_ip": "167.94.138.141", "src_port": 53224, "dest_ip": "134.19.55.199", "dest_port": 6008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:01:11.899941+0100", "src_ip": "167.94.138.141", "dest_ip": "134.19.55.199", "src_port": 53224, "dest_port": 6008}}'); INSERT INTO alerts VALUES(2256,1773068509.962920905,'{"timestamp": "2026-03-09T16:01:49.962921+0100", "flow_id": 1602440339634954, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60888, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57727, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T16:01:49.962921+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60888, "dest_port": 53}}'); INSERT INTO alerts VALUES(2257,1773068509.963548899,'{"timestamp": "2026-03-09T16:01:49.963549+0100", "flow_id": 1605140389949616, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51287, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4416, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T16:01:49.963549+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51287, "dest_port": 53}}'); INSERT INTO alerts VALUES(2258,1773068509.982440949,'{"timestamp": "2026-03-09T16:01:49.982441+0100", "flow_id": 1686279489224981, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40786, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35433, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T16:01:49.982441+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40786, "dest_port": 53}}'); INSERT INTO alerts VALUES(2259,1773068514.202222108,'{"timestamp": "2026-03-09T16:01:54.202222+0100", "flow_id": 587063382932467, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 53446, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15805, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:01:54.202222+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 53446, "dest_port": 53}}'); INSERT INTO alerts VALUES(2260,1773068514.202222108,'{"timestamp": "2026-03-09T16:01:54.202222+0100", "flow_id": 587063379055376, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 35764, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62169, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:01:54.202222+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 35764, "dest_port": 53}}'); INSERT INTO alerts VALUES(2261,1773068536.264847993,'{"timestamp": "2026-03-09T16:02:16.264848+0100", "flow_id": 11613834203790, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 45146, "dest_ip": "134.19.55.199", "dest_port": 1398, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:02:16.264848+0100", "src_ip": "167.94.146.40", "dest_ip": "134.19.55.199", "src_port": 45146, "dest_port": 1398}}'); INSERT INTO alerts VALUES(2262,1773068622.662086009,'{"timestamp": "2026-03-09T16:03:42.662086+0100", "flow_id": 1717738480016318, "event_type": "alert", "src_ip": "167.94.146.36", "src_port": 51136, "dest_ip": "134.19.55.199", "dest_port": 3965, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:03:42.662086+0100", "src_ip": "167.94.146.36", "dest_ip": "134.19.55.199", "src_port": 51136, "dest_port": 3965}}'); INSERT INTO alerts VALUES(2263,1773068632.59622097,'{"timestamp": "2026-03-09T16:03:52.596221+0100", "flow_id": 27477116807403, "event_type": "alert", "src_ip": "185.242.226.97", "src_port": 42109, "dest_ip": "134.19.55.199", "dest_port": 40991, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-09T16:03:52.596221+0100", "src_ip": "185.242.226.97", "dest_ip": "134.19.55.199", "src_port": 42109, "dest_port": 40991}}'); INSERT INTO alerts VALUES(2264,1773068654.188883066,'{"timestamp": "2026-03-09T16:04:14.188883+0100", "flow_id": 1937149444974968, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 37586, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 870, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:04:14.188883+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 37586, "dest_port": 53}}'); INSERT INTO alerts VALUES(2265,1773068654.188883066,'{"timestamp": "2026-03-09T16:04:14.188883+0100", "flow_id": 1937149414286050, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 48313, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25166, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:04:14.188883+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 48313, "dest_port": 53}}'); INSERT INTO alerts VALUES(2266,1773068668.540803909,'{"timestamp": "2026-03-09T16:04:28.540804+0100", "flow_id": 1196838982858104, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 43744, "dest_ip": "134.19.55.199", "dest_port": 8443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:04:28.540804+0100", "src_ip": "87.121.84.57", "dest_ip": "134.19.55.199", "src_port": 43744, "dest_port": 8443}}'); INSERT INTO alerts VALUES(2267,1773068699.212410926,'{"timestamp": "2026-03-09T16:04:59.212411+0100", "flow_id": 912299857223035, "event_type": "alert", "src_ip": "176.65.139.38", "src_port": 50000, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:04:59.212411+0100", "src_ip": "176.65.139.38", "dest_ip": "134.19.55.199", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(2268,1773068727.486778974,'{"timestamp": "2026-03-09T16:05:27.486779+0100", "flow_id": 2090702793378696, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 44908, "dest_ip": "134.19.55.199", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T16:05:27.486779+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 44908, "dest_port": 8332}}'); INSERT INTO alerts VALUES(2269,1773068727.486778974,'{"timestamp": "2026-03-09T16:05:27.486779+0100", "flow_id": 2090702793378696, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 44908, "dest_ip": "134.19.55.199", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T16:05:27.486779+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 44908, "dest_port": 8332}}'); INSERT INTO alerts VALUES(2270,1773068753.631628036,'{"timestamp": "2026-03-09T16:05:53.631628+0100", "flow_id": 461025366316295, "event_type": "alert", "src_ip": "167.94.146.41", "src_port": 29587, "dest_ip": "134.19.55.199", "dest_port": 12147, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:05:53.631628+0100", "src_ip": "167.94.146.41", "dest_ip": "134.19.55.199", "src_port": 29587, "dest_port": 12147}}'); INSERT INTO alerts VALUES(2271,1773068831.184268952,'{"timestamp": "2026-03-09T16:07:11.184269+0100", "flow_id": 2198806230976172, "event_type": "alert", "src_ip": "87.121.84.67", "src_port": 49474, "dest_ip": "134.19.55.199", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:07:11.184269+0100", "src_ip": "87.121.84.67", "dest_ip": "134.19.55.199", "src_port": 49474, "dest_port": 5900}}'); INSERT INTO alerts VALUES(2272,1773068859.216310978,'{"timestamp": "2026-03-09T16:07:39.216311+0100", "flow_id": 929052064471103, "event_type": "alert", "src_ip": "193.163.125.205", "src_port": 35398, "dest_ip": "134.19.55.199", "dest_port": 8971, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:07:39.216311+0100", "src_ip": "193.163.125.205", "dest_ip": "134.19.55.199", "src_port": 35398, "dest_port": 8971}}'); INSERT INTO alerts VALUES(2273,1773068887.772310973,'{"timestamp": "2026-03-09T16:08:07.772311+0100", "flow_id": 2191153913049845, "event_type": "alert", "src_ip": "176.65.134.20", "src_port": 34926, "dest_ip": "134.19.55.199", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:08:07.772311+0100", "src_ip": "176.65.134.20", "dest_ip": "134.19.55.199", "src_port": 34926, "dest_port": 443}}'); INSERT INTO alerts VALUES(2274,1773068923.980791091,'{"timestamp": "2026-03-09T16:08:43.980791+0100", "flow_id": 1116241903029885, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 47355, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:08:43.980791+0100", "src_ip": "130.12.180.174", "dest_ip": "134.19.55.199", "src_port": 47355, "dest_port": 23}}'); INSERT INTO alerts VALUES(2275,1773068923.980791091,'{"timestamp": "2026-03-09T16:08:43.980791+0100", "flow_id": 1116241903029885, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 47355, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:08:43.980791+0100", "src_ip": "130.12.180.174", "dest_ip": "134.19.55.199", "src_port": 47355, "dest_port": 23}}'); INSERT INTO alerts VALUES(2276,1773068930.111675977,'{"timestamp": "2026-03-09T16:08:50.111676+0100", "flow_id": 761123281649733, "event_type": "alert", "src_ip": "185.156.73.182", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 8009, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:08:50.111676+0100", "src_ip": "185.156.73.182", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 8009}}'); INSERT INTO alerts VALUES(2277,1773068937.155590058,'{"timestamp": "2026-03-09T16:08:57.155590+0100", "flow_id": 386780967779407, "event_type": "alert", "src_ip": "178.20.210.152", "src_port": 42657, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:08:57.155590+0100", "src_ip": "178.20.210.152", "dest_ip": "134.19.55.199", "src_port": 42657, "dest_port": 22}}'); INSERT INTO alerts VALUES(2278,1773068957.292299032,'{"timestamp": "2026-03-09T16:09:17.292299+0100", "flow_id": 1536893829335069, "event_type": "alert", "src_ip": "45.156.87.7", "src_port": 48884, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:09:17.292299+0100", "src_ip": "45.156.87.7", "dest_ip": "134.19.55.199", "src_port": 48884, "dest_port": 27017}}'); INSERT INTO alerts VALUES(2279,1773069138.276812076,'{"timestamp": "2026-03-09T16:12:18.276812+0100", "flow_id": 625950901876287, "event_type": "alert", "src_ip": "178.20.210.151", "src_port": 46829, "dest_ip": "134.19.55.199", "dest_port": 50022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:12:18.276812+0100", "src_ip": "178.20.210.151", "dest_ip": "134.19.55.199", "src_port": 46829, "dest_port": 50022}}'); INSERT INTO alerts VALUES(2280,1773069228.931740046,'{"timestamp": "2026-03-09T16:13:48.931740+0100", "flow_id": 1187045230281414, "event_type": "alert", "src_ip": "43.228.157.16", "src_port": 58468, "dest_ip": "134.19.55.199", "dest_port": 50004, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:13:48.931740+0100", "src_ip": "43.228.157.16", "dest_ip": "134.19.55.199", "src_port": 58468, "dest_port": 50004}}'); INSERT INTO alerts VALUES(2281,1773069289.836244107,'{"timestamp": "2026-03-09T16:14:49.836244+0100", "flow_id": 495420142258079, "event_type": "alert", "src_ip": "176.65.139.41", "src_port": 50000, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:14:49.836244+0100", "src_ip": "176.65.139.41", "dest_ip": "134.19.55.199", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(2282,1773069297.106231927,'{"timestamp": "2026-03-09T16:14:57.106232+0100", "flow_id": 456263667701018, "event_type": "alert", "src_ip": "64.89.163.153", "src_port": 49192, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:14:57.106232+0100", "src_ip": "64.89.163.153", "dest_ip": "134.19.55.199", "src_port": 49192, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2283,1773069297.106231927,'{"timestamp": "2026-03-09T16:14:57.106232+0100", "flow_id": 456263667701018, "event_type": "alert", "src_ip": "64.89.163.153", "src_port": 49192, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:14:57.106232+0100", "src_ip": "64.89.163.153", "dest_ip": "134.19.55.199", "src_port": 49192, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2284,1773069482.847763061,'{"timestamp": "2026-03-09T16:18:02.847763+0100", "flow_id": 826368149977817, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 12721, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:18:02.847763+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 12721}}'); INSERT INTO alerts VALUES(2285,1773069485.907505989,'{"timestamp": "2026-03-09T16:18:05.907506+0100", "flow_id": 1645910056742822, "event_type": "alert", "src_ip": "176.65.148.29", "src_port": 34851, "dest_ip": "134.19.55.199", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T16:18:05.907506+0100", "src_ip": "176.65.148.29", "dest_ip": "134.19.55.199", "src_port": 34851, "dest_port": 8332}}'); INSERT INTO alerts VALUES(2286,1773069485.907505989,'{"timestamp": "2026-03-09T16:18:05.907506+0100", "flow_id": 1645910056742822, "event_type": "alert", "src_ip": "176.65.148.29", "src_port": 34851, "dest_ip": "134.19.55.199", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T16:18:05.907506+0100", "src_ip": "176.65.148.29", "dest_ip": "134.19.55.199", "src_port": 34851, "dest_port": 8332}}'); INSERT INTO alerts VALUES(2287,1773069508.719682931,'{"timestamp": "2026-03-09T16:18:28.719683+0100", "flow_id": 1402168134861041, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 46606, "dest_ip": "134.19.55.199", "dest_port": 16193, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:18:28.719683+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 46606, "dest_port": 16193}}'); INSERT INTO alerts VALUES(2288,1773069544.507579089,'{"timestamp": "2026-03-09T16:19:04.507579+0100", "flow_id": 209713804283915, "event_type": "alert", "src_ip": "193.163.125.198", "src_port": 59015, "dest_ip": "134.19.55.199", "dest_port": 30013, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:19:04.507579+0100", "src_ip": "193.163.125.198", "dest_ip": "134.19.55.199", "src_port": 59015, "dest_port": 30013}}'); INSERT INTO alerts VALUES(2289,1773069546.852577925,'{"timestamp": "2026-03-09T16:19:06.852578+0100", "flow_id": 565573483063869, "event_type": "alert", "src_ip": "167.94.138.144", "src_port": 32265, "dest_ip": "134.19.55.199", "dest_port": 4369, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:19:06.852578+0100", "src_ip": "167.94.138.144", "dest_ip": "134.19.55.199", "src_port": 32265, "dest_port": 4369}}'); INSERT INTO alerts VALUES(2290,1773069674.339498043,'{"timestamp": "2026-03-09T16:21:14.339498+0100", "flow_id": 613711441009129, "event_type": "alert", "src_ip": "193.163.125.204", "src_port": 39857, "dest_ip": "134.19.55.199", "dest_port": 8570, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:21:14.339498+0100", "src_ip": "193.163.125.204", "dest_ip": "134.19.55.199", "src_port": 39857, "dest_port": 8570}}'); INSERT INTO alerts VALUES(2291,1773069796.516948939,'{"timestamp": "2026-03-09T16:23:16.516949+0100", "flow_id": 1375856345637348, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 47484, "dest_ip": "134.19.55.199", "dest_port": 11499, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:23:16.516949+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 47484, "dest_port": 11499}}'); INSERT INTO alerts VALUES(2292,1773069852.652240991,'{"timestamp": "2026-03-09T16:24:12.652241+0100", "flow_id": 1393981858952738, "event_type": "alert", "src_ip": "79.124.62.178", "src_port": 56324, "dest_ip": "134.19.55.199", "dest_port": 13389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:24:12.652241+0100", "src_ip": "79.124.62.178", "dest_ip": "134.19.55.199", "src_port": 56324, "dest_port": 13389}}'); INSERT INTO alerts VALUES(2293,1773070124.878493071,'{"timestamp": "2026-03-09T16:28:44.878493+0100", "flow_id": 1239825591184388, "event_type": "alert", "src_ip": "193.163.125.59", "src_port": 24501, "dest_ip": "134.19.55.199", "dest_port": 5978, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 48, "bytes_toclient": 0, "start": "2026-03-09T16:28:44.878493+0100", "src_ip": "193.163.125.59", "dest_ip": "134.19.55.199", "src_port": 24501, "dest_port": 5978}}'); INSERT INTO alerts VALUES(2294,1773070133.109637975,'{"timestamp": "2026-03-09T16:28:53.109638+0100", "flow_id": 1596794648396659, "event_type": "alert", "src_ip": "195.184.76.181", "src_port": 61495, "dest_ip": "134.19.55.199", "dest_port": 5310, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:28:53.109638+0100", "src_ip": "195.184.76.181", "dest_ip": "134.19.55.199", "src_port": 61495, "dest_port": 5310}}'); INSERT INTO alerts VALUES(2295,1773070156.481667042,'{"timestamp": "2026-03-09T16:29:16.481667+0100", "flow_id": 1224320826672346, "event_type": "alert", "src_ip": "45.142.154.98", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 5985, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:29:16.481667+0100", "src_ip": "45.142.154.98", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 5985}}'); INSERT INTO alerts VALUES(2296,1773070180.108139038,'{"timestamp": "2026-03-09T16:29:40.108139+0100", "flow_id": 1308880997266901, "event_type": "alert", "src_ip": "167.94.146.72", "src_port": 30890, "dest_ip": "134.19.55.199", "dest_port": 4291, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:29:40.108139+0100", "src_ip": "167.94.146.72", "dest_ip": "134.19.55.199", "src_port": 30890, "dest_port": 4291}}'); INSERT INTO alerts VALUES(2297,1773070252.204365969,'{"timestamp": "2026-03-09T16:30:52.204366+0100", "flow_id": 1159221488384279, "event_type": "alert", "src_ip": "66.132.153.153", "src_port": 23582, "dest_ip": "134.19.55.199", "dest_port": 4840, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:30:52.204366+0100", "src_ip": "66.132.153.153", "dest_ip": "134.19.55.199", "src_port": 23582, "dest_port": 4840}}'); INSERT INTO alerts VALUES(2298,1773070339.737617969,'{"timestamp": "2026-03-09T16:32:19.737618+0100", "flow_id": 916247688418973, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 21000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:32:19.737618+0100", "src_ip": "88.210.63.69", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 21000}}'); INSERT INTO alerts VALUES(2299,1773070663.3975451,'{"timestamp": "2026-03-09T16:37:43.397545+0100", "flow_id": 1988919709891059, "event_type": "alert", "src_ip": "176.65.134.22", "src_port": 41688, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:37:43.397545+0100", "src_ip": "176.65.134.22", "dest_ip": "134.19.55.199", "src_port": 41688, "dest_port": 22}}'); INSERT INTO alerts VALUES(2300,1773070736.692825079,'{"timestamp": "2026-03-09T16:38:56.692825+0100", "flow_id": 160913197582129, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 44662, "dest_ip": "134.19.55.199", "dest_port": 9001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:38:56.692825+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 44662, "dest_port": 9001}}'); INSERT INTO alerts VALUES(2301,1773070736.692825079,'{"timestamp": "2026-03-09T16:38:56.692825+0100", "flow_id": 160913197582129, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 44662, "dest_ip": "134.19.55.199", "dest_port": 9001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:38:56.692825+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 44662, "dest_port": 9001}}'); INSERT INTO alerts VALUES(2302,1773070795.196727038,'{"timestamp": "2026-03-09T16:39:55.196727+0100", "flow_id": 844937056471728, "event_type": "alert", "src_ip": "46.151.182.162", "src_port": 50464, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:39:55.196727+0100", "src_ip": "46.151.182.162", "dest_ip": "134.19.55.199", "src_port": 50464, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2303,1773070795.196727038,'{"timestamp": "2026-03-09T16:39:55.196727+0100", "flow_id": 844937056471728, "event_type": "alert", "src_ip": "46.151.182.162", "src_port": 50464, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:39:55.196727+0100", "src_ip": "46.151.182.162", "dest_ip": "134.19.55.199", "src_port": 50464, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2304,1773070806.467643976,'{"timestamp": "2026-03-09T16:40:06.467644+0100", "flow_id": 1727043547603886, "event_type": "alert", "src_ip": "88.210.63.193", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 3333, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:40:06.467644+0100", "src_ip": "88.210.63.193", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 3333}}'); INSERT INTO alerts VALUES(2305,1773070841.617136002,'{"timestamp": "2026-03-09T16:40:41.617136+0100", "flow_id": 398780132436164, "event_type": "alert", "src_ip": "91.196.152.191", "src_port": 1621, "dest_ip": "134.19.55.199", "dest_port": 20123, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:40:41.617136+0100", "src_ip": "91.196.152.191", "dest_ip": "134.19.55.199", "src_port": 1621, "dest_port": 20123}}'); INSERT INTO alerts VALUES(2306,1773070876.136420012,'{"timestamp": "2026-03-09T16:41:16.136420+0100", "flow_id": 1148872605399088, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 44203, "dest_ip": "134.19.55.199", "dest_port": 50000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:41:16.136420+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.55.199", "src_port": 44203, "dest_port": 50000}}'); INSERT INTO alerts VALUES(2307,1773070876.136420012,'{"timestamp": "2026-03-09T16:41:16.136420+0100", "flow_id": 1148872605399088, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 44203, "dest_ip": "134.19.55.199", "dest_port": 50000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:41:16.136420+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.55.199", "src_port": 44203, "dest_port": 50000}}'); INSERT INTO alerts VALUES(2308,1773070904.878273011,'{"timestamp": "2026-03-09T16:41:44.878273+0100", "flow_id": 112982865132841, "event_type": "alert", "src_ip": "91.196.152.39", "src_port": 959, "dest_ip": "134.19.55.199", "dest_port": 20075, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:41:44.878273+0100", "src_ip": "91.196.152.39", "dest_ip": "134.19.55.199", "src_port": 959, "dest_port": 20075}}'); INSERT INTO alerts VALUES(2309,1773070921.220479011,'{"timestamp": "2026-03-09T16:42:01.220479+0100", "flow_id": 384002623744054, "event_type": "alert", "src_ip": "165.154.252.214", "src_port": 44028, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400029, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 30", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:42:01.220479+0100", "src_ip": "165.154.252.214", "dest_ip": "134.19.55.199", "src_port": 44028, "dest_port": 80}}'); INSERT INTO alerts VALUES(2310,1773070935.136481046,'{"timestamp": "2026-03-09T16:42:15.136481+0100", "flow_id": 1993560310846987, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36705, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57422, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:42:15.136481+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36705, "dest_port": 53}}'); INSERT INTO alerts VALUES(2311,1773070935.136482001,'{"timestamp": "2026-03-09T16:42:15.136482+0100", "flow_id": 1993560912918362, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42790, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3389, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:42:15.136482+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42790, "dest_port": 53}}'); INSERT INTO alerts VALUES(2312,1773070937.06886506,'{"timestamp": "2026-03-09T16:42:17.068865+0100", "flow_id": 295775141208707, "event_type": "alert", "src_ip": "193.163.125.201", "src_port": 38235, "dest_ip": "134.19.55.199", "dest_port": 7801, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:42:17.068865+0100", "src_ip": "193.163.125.201", "dest_ip": "134.19.55.199", "src_port": 38235, "dest_port": 7801}}'); INSERT INTO alerts VALUES(2313,1773070965.96927905,'{"timestamp": "2026-03-09T16:42:45.969279+0100", "flow_id": 1629748298039951, "event_type": "alert", "src_ip": "195.184.76.143", "src_port": 54741, "dest_ip": "134.19.55.199", "dest_port": 6509, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:42:45.969279+0100", "src_ip": "195.184.76.143", "dest_ip": "134.19.55.199", "src_port": 54741, "dest_port": 6509}}'); INSERT INTO alerts VALUES(2314,1773070971.228353978,'{"timestamp": "2026-03-09T16:42:51.228354+0100", "flow_id": 980773175050800, "event_type": "alert", "src_ip": "195.184.76.175", "src_port": 37192, "dest_ip": "134.19.55.199", "dest_port": 6123, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:42:51.228354+0100", "src_ip": "195.184.76.175", "dest_ip": "134.19.55.199", "src_port": 37192, "dest_port": 6123}}'); INSERT INTO alerts VALUES(2315,1773070974.937252045,'{"timestamp": "2026-03-09T16:42:54.937252+0100", "flow_id": 1773668031585842, "event_type": "alert", "src_ip": "195.184.76.167", "src_port": 12501, "dest_ip": "134.19.55.199", "dest_port": 5907, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:42:54.937252+0100", "src_ip": "195.184.76.167", "dest_ip": "134.19.55.199", "src_port": 12501, "dest_port": 5907}}'); INSERT INTO alerts VALUES(2316,1773070975.353730916,'{"timestamp": "2026-03-09T16:42:55.353731+0100", "flow_id": 2082213698160533, "event_type": "alert", "src_ip": "91.196.152.183", "src_port": 12501, "dest_ip": "134.19.55.199", "dest_port": 2119, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:42:55.353731+0100", "src_ip": "91.196.152.183", "dest_ip": "134.19.55.199", "src_port": 12501, "dest_port": 2119}}'); INSERT INTO alerts VALUES(2317,1773070996.93057704,'{"timestamp": "2026-03-09T16:43:16.930577+0100", "flow_id": 1182050929613293, "event_type": "alert", "src_ip": "195.184.76.119", "src_port": 23889, "dest_ip": "134.19.55.199", "dest_port": 5705, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:43:16.930577+0100", "src_ip": "195.184.76.119", "dest_ip": "134.19.55.199", "src_port": 23889, "dest_port": 5705}}'); INSERT INTO alerts VALUES(2318,1773071023.140642881,'{"timestamp": "2026-03-09T16:43:43.140643+0100", "flow_id": 2011432794097709, "event_type": "alert", "src_ip": "185.156.73.180", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44309, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:43:43.140643+0100", "src_ip": "185.156.73.180", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44309}}'); INSERT INTO alerts VALUES(2319,1773071026.60475111,'{"timestamp": "2026-03-09T16:43:46.604751+0100", "flow_id": 627061887314379, "event_type": "alert", "src_ip": "195.184.76.39", "src_port": 62474, "dest_ip": "134.19.55.199", "dest_port": 6969, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:43:46.604751+0100", "src_ip": "195.184.76.39", "dest_ip": "134.19.55.199", "src_port": 62474, "dest_port": 6969}}'); INSERT INTO alerts VALUES(2320,1773071040.0429039,'{"timestamp": "2026-03-09T16:44:00.042904+0100", "flow_id": 184272709993871, "event_type": "alert", "src_ip": "195.184.76.135", "src_port": 39622, "dest_ip": "134.19.55.199", "dest_port": 7221, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:44:00.042904+0100", "src_ip": "195.184.76.135", "dest_ip": "134.19.55.199", "src_port": 39622, "dest_port": 7221}}'); INSERT INTO alerts VALUES(2321,1773071055.69593811,'{"timestamp": "2026-03-09T16:44:15.695938+0100", "flow_id": 2144609966324665, "event_type": "alert", "src_ip": "167.94.146.46", "src_port": 39989, "dest_ip": "134.19.55.199", "dest_port": 45287, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:44:15.695938+0100", "src_ip": "167.94.146.46", "dest_ip": "134.19.55.199", "src_port": 39989, "dest_port": 45287}}'); INSERT INTO alerts VALUES(2322,1773071075.204797029,'{"timestamp": "2026-03-09T16:44:35.204797+0100", "flow_id": 879596908443708, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 52705, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37813, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:44:35.204797+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 52705, "dest_port": 53}}'); INSERT INTO alerts VALUES(2323,1773071075.204797029,'{"timestamp": "2026-03-09T16:44:35.204797+0100", "flow_id": 879597540725983, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 49365, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:44:35.204797+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 49365, "dest_port": 53}}'); INSERT INTO alerts VALUES(2324,1773071164.261027097,'{"timestamp": "2026-03-09T16:46:04.261027+0100", "flow_id": 1402581604968022, "event_type": "alert", "src_ip": "176.65.139.12", "src_port": 47152, "dest_ip": "134.19.55.199", "dest_port": 17000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:46:04.261027+0100", "src_ip": "176.65.139.12", "dest_ip": "134.19.55.199", "src_port": 47152, "dest_port": 17000}}'); INSERT INTO alerts VALUES(2325,1773071169.443016052,'{"timestamp": "2026-03-09T16:46:09.443016+0100", "flow_id": 495368169702573, "event_type": "alert", "src_ip": "167.94.138.150", "src_port": 29143, "dest_ip": "134.19.55.199", "dest_port": 2181, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:46:09.443016+0100", "src_ip": "167.94.138.150", "dest_ip": "134.19.55.199", "src_port": 29143, "dest_port": 2181}}'); INSERT INTO alerts VALUES(2326,1773071179.890328884,'{"timestamp": "2026-03-09T16:46:19.890329+0100", "flow_id": 1009185606753465, "event_type": "alert", "src_ip": "185.242.226.104", "src_port": 52810, "dest_ip": "134.19.55.199", "dest_port": 42235, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:46:19.890329+0100", "src_ip": "185.242.226.104", "dest_ip": "134.19.55.199", "src_port": 52810, "dest_port": 42235}}'); INSERT INTO alerts VALUES(2327,1773071215.328479051,'{"timestamp": "2026-03-09T16:46:55.328479+0100", "flow_id": 1973756559261805, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 37048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16694, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:46:55.328479+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 37048, "dest_port": 53}}'); INSERT INTO alerts VALUES(2328,1773071215.328479051,'{"timestamp": "2026-03-09T16:46:55.328479+0100", "flow_id": 1973760612944289, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44688, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1142, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:46:55.328479+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44688, "dest_port": 53}}'); INSERT INTO alerts VALUES(2329,1773071247.682804108,'{"timestamp": "2026-03-09T16:47:27.682804+0100", "flow_id": 1996943202184894, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39252, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:47:27.661557+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 39252, "dest_port": 853}}'); INSERT INTO alerts VALUES(2330,1773071247.683538914,'{"timestamp": "2026-03-09T16:47:27.683539+0100", "flow_id": 1994732982408339, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39240, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:47:27.661042+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 39240, "dest_port": 853}}'); INSERT INTO alerts VALUES(2331,1773071247.688436031,'{"timestamp": "2026-03-09T16:47:27.688436+0100", "flow_id": 1999051435531723, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 41594, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:47:27.662048+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 41594, "dest_port": 853}}'); INSERT INTO alerts VALUES(2332,1773071247.740761996,'{"timestamp": "2026-03-09T16:47:27.740762+0100", "flow_id": 2240753038640315, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 41596, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:47:27.718323+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 41596, "dest_port": 853}}'); INSERT INTO alerts VALUES(2333,1773071247.831137895,'{"timestamp": "2026-03-09T16:47:27.831138+0100", "flow_id": 2071265394410932, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 41604, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:47:27.809934+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 41604, "dest_port": 853}}'); INSERT INTO alerts VALUES(2334,1773071247.840092898,'{"timestamp": "2026-03-09T16:47:27.840093+0100", "flow_id": 2107297010454977, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39262, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:47:27.818323+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 39262, "dest_port": 853}}'); INSERT INTO alerts VALUES(2335,1773071248.133716107,'{"timestamp": "2026-03-09T16:47:28.133716+0100", "flow_id": 199181566048186, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 41618, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:47:28.111911+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 41618, "dest_port": 853}}'); INSERT INTO alerts VALUES(2336,1773071248.338638068,'{"timestamp": "2026-03-09T16:47:28.338638+0100", "flow_id": 233549030085554, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 41622, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:47:28.316521+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 41622, "dest_port": 853}}'); INSERT INTO alerts VALUES(2337,1773071254.428220034,'{"timestamp": "2026-03-09T16:47:34.428220+0100", "flow_id": 1747893659688067, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 40264, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:47:34.406963+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 40264, "dest_port": 853}}'); INSERT INTO alerts VALUES(2338,1773071316.013400077,'{"timestamp": "2026-03-09T16:48:36.013400+0100", "flow_id": 878026258997213, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 46126, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:48:35.990863+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 46126, "dest_port": 853}}'); INSERT INTO alerts VALUES(2339,1773071316.723262071,'{"timestamp": "2026-03-09T16:48:36.723262+0100", "flow_id": 1136065705335912, "event_type": "alert", "src_ip": "167.94.146.39", "src_port": 62792, "dest_ip": "134.19.55.199", "dest_port": 48529, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:48:36.723262+0100", "src_ip": "167.94.146.39", "dest_ip": "134.19.55.199", "src_port": 62792, "dest_port": 48529}}'); INSERT INTO alerts VALUES(2340,1773071319.015753984,'{"timestamp": "2026-03-09T16:48:39.015754+0100", "flow_id": 1739595323185441, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39610, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:48:38.994855+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 39610, "dest_port": 853}}'); INSERT INTO alerts VALUES(2341,1773071322.018131971,'{"timestamp": "2026-03-09T16:48:42.018132+0100", "flow_id": 337658070906297, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39618, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:48:41.996121+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 39618, "dest_port": 853}}'); INSERT INTO alerts VALUES(2342,1773071324.353527069,'{"timestamp": "2026-03-09T16:48:44.353527+0100", "flow_id": 1236914032571138, "event_type": "alert", "src_ip": "185.242.226.73", "src_port": 49423, "dest_ip": "134.19.55.199", "dest_port": 8420, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:48:44.353527+0100", "src_ip": "185.242.226.73", "dest_ip": "134.19.55.199", "src_port": 49423, "dest_port": 8420}}'); INSERT INTO alerts VALUES(2343,1773071325.019967079,'{"timestamp": "2026-03-09T16:48:45.019967+0100", "flow_id": 1193870705386880, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39844, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:48:44.998865+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 39844, "dest_port": 853}}'); INSERT INTO alerts VALUES(2344,1773071328.024239064,'{"timestamp": "2026-03-09T16:48:48.024239+0100", "flow_id": 7447960468424, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39628, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:48:48.001734+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 39628, "dest_port": 853}}'); INSERT INTO alerts VALUES(2345,1773071331.232819081,'{"timestamp": "2026-03-09T16:48:51.232819+0100", "flow_id": 902459768778563, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 51272, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:48:51.210120+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 51272, "dest_port": 853}}'); INSERT INTO alerts VALUES(2346,1773071332.182269097,'{"timestamp": "2026-03-09T16:48:52.182269+0100", "flow_id": 1249167063274886, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 51274, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:48:52.159772+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 51274, "dest_port": 853}}'); INSERT INTO alerts VALUES(2347,1773071335.845233918,'{"timestamp": "2026-03-09T16:48:55.845234+0100", "flow_id": 2126748226498297, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 34610, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:48:55.822852+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 34610, "dest_port": 853}}'); INSERT INTO alerts VALUES(2348,1773071336.792243003,'{"timestamp": "2026-03-09T16:48:56.792243+0100", "flow_id": 210722523850434, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 34624, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:48:56.769958+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 34624, "dest_port": 853}}'); INSERT INTO alerts VALUES(2349,1773071342.246038914,'{"timestamp": "2026-03-09T16:49:02.246039+0100", "flow_id": 1810316770129046, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53366, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:49:02.224889+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 53366, "dest_port": 853}}'); INSERT INTO alerts VALUES(2350,1773071343.190926075,'{"timestamp": "2026-03-09T16:49:03.190926+0100", "flow_id": 2143058571549798, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53368, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:49:03.171289+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 53368, "dest_port": 853}}'); INSERT INTO alerts VALUES(2351,1773071349.983788014,'{"timestamp": "2026-03-09T16:49:09.983788+0100", "flow_id": 1410588371342327, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 56318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60649, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T16:49:09.983788+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 56318, "dest_port": 53}}'); INSERT INTO alerts VALUES(2352,1773071349.983788968,'{"timestamp": "2026-03-09T16:49:09.983789+0100", "flow_id": 1410595507782530, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41157, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28850, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T16:49:09.983789+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41157, "dest_port": 53}}'); INSERT INTO alerts VALUES(2353,1773071350.07249403,'{"timestamp": "2026-03-09T16:49:10.072494+0100", "flow_id": 1718737990777708, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59808, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6800, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T16:49:10.072494+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59808, "dest_port": 53}}'); INSERT INTO alerts VALUES(2354,1773071350.514976979,'{"timestamp": "2026-03-09T16:49:10.514977+0100", "flow_id": 1930335967983277, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 52121, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56578, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cloudflare-dns.com", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-09T16:49:10.514977+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 52121, "dest_port": 53}}'); INSERT INTO alerts VALUES(2355,1773071351.463859082,'{"timestamp": "2026-03-09T16:49:11.463859+0100", "flow_id": 2182831443703088, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 44214, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:49:11.442694+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 44214, "dest_port": 853}}'); INSERT INTO alerts VALUES(2356,1773071352.408823014,'{"timestamp": "2026-03-09T16:49:12.408823+0100", "flow_id": 258921825376312, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 38798, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:49:12.387964+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 38798, "dest_port": 853}}'); INSERT INTO alerts VALUES(2357,1773071355.382256032,'{"timestamp": "2026-03-09T16:49:15.382256+0100", "flow_id": 1078829968416806, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42019, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65300, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:49:15.382256+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42019, "dest_port": 53}}'); INSERT INTO alerts VALUES(2358,1773071355.385626078,'{"timestamp": "2026-03-09T16:49:15.385626+0100", "flow_id": 1093304032040628, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 56903, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13959, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:49:15.385626+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 56903, "dest_port": 53}}'); INSERT INTO alerts VALUES(2359,1773071370.841283082,'{"timestamp": "2026-03-09T16:49:30.841283+0100", "flow_id": 712127343998571, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 38744, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:49:30.821165+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 38744, "dest_port": 853}}'); INSERT INTO alerts VALUES(2360,1773071396.445636035,'{"timestamp": "2026-03-09T16:49:56.445636+0100", "flow_id": 1264770159639503, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 50088, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:49:56.425549+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 50088, "dest_port": 853}}'); INSERT INTO alerts VALUES(2361,1773071433.315963983,'{"timestamp": "2026-03-09T16:50:33.315964+0100", "flow_id": 418935710402645, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 35248, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:50:33.294149+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 35248, "dest_port": 853}}'); INSERT INTO alerts VALUES(2362,1773071433.947561025,'{"timestamp": "2026-03-09T16:50:33.947561+0100", "flow_id": 410572191735390, "event_type": "alert", "src_ip": "147.185.132.225", "src_port": 51083, "dest_ip": "134.19.55.199", "dest_port": 21, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:50:33.947561+0100", "src_ip": "147.185.132.225", "dest_ip": "134.19.55.199", "src_port": 51083, "dest_port": 21}}'); INSERT INTO alerts VALUES(2363,1773071484.516269922,'{"timestamp": "2026-03-09T16:51:24.516270+0100", "flow_id": 1282721496837473, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39952, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:51:24.495264+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 39952, "dest_port": 853}}'); INSERT INTO alerts VALUES(2364,1773071495.451762915,'{"timestamp": "2026-03-09T16:51:35.451763+0100", "flow_id": 2221782369325401, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 53983, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16013, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:51:35.451763+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 53983, "dest_port": 53}}'); INSERT INTO alerts VALUES(2365,1773071495.451762915,'{"timestamp": "2026-03-09T16:51:35.451763+0100", "flow_id": 2221785933259985, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 45649, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59748, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T16:51:35.451763+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 45649, "dest_port": 53}}'); INSERT INTO alerts VALUES(2366,1773071542.671447039,'{"timestamp": "2026-03-09T16:52:22.671447+0100", "flow_id": 1757944612317672, "event_type": "alert", "src_ip": "88.247.20.79", "src_port": 50345, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:52:22.671447+0100", "src_ip": "88.247.20.79", "dest_ip": "134.19.55.199", "src_port": 50345, "dest_port": 1433}}'); INSERT INTO alerts VALUES(2367,1773071545.621232033,'{"timestamp": "2026-03-09T16:52:25.621232+0100", "flow_id": 416371785098746, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 51743, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:52:25.621232+0100", "src_ip": "45.153.34.32", "dest_ip": "134.19.55.199", "src_port": 51743, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2368,1773071545.621232033,'{"timestamp": "2026-03-09T16:52:25.621232+0100", "flow_id": 416371785098746, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 51743, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:52:25.621232+0100", "src_ip": "45.153.34.32", "dest_ip": "134.19.55.199", "src_port": 51743, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2369,1773071558.248665094,'{"timestamp": "2026-03-09T16:52:38.248665+0100", "flow_id": 1823390034949809, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 50020, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T16:52:38.227933+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 50020, "dest_port": 853}}'); INSERT INTO alerts VALUES(2370,1773071563.49191308,'{"timestamp": "2026-03-09T16:52:43.491913+0100", "flow_id": 986853760969605, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 54115, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7042, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T16:52:43.491913+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 54115, "dest_port": 53}}'); INSERT INTO alerts VALUES(2371,1773071563.49191308,'{"timestamp": "2026-03-09T16:52:43.491913+0100", "flow_id": 986851206449097, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40544, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48985, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T16:52:43.491913+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40544, "dest_port": 53}}'); INSERT INTO alerts VALUES(2372,1773071563.49191308,'{"timestamp": "2026-03-09T16:52:43.491913+0100", "flow_id": 986850950056646, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 48965, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58921, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T16:52:43.491913+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 48965, "dest_port": 53}}'); INSERT INTO alerts VALUES(2373,1773071564.034888029,'{"timestamp": "2026-03-09T16:52:44.034888+0100", "flow_id": 1275744157110117, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 53680, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39609, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cloudflare-dns.com", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-09T16:52:44.034888+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 53680, "dest_port": 53}}'); INSERT INTO alerts VALUES(2374,1773071570.348170042,'{"timestamp": "2026-03-09T16:52:50.348170+0100", "flow_id": 650955100398476, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63992, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 654, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:52:50.348170+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63992, "dest_port": 53}}'); INSERT INTO alerts VALUES(2375,1773071570.348170042,'{"timestamp": "2026-03-09T16:52:50.348170+0100", "flow_id": 650955757636050, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59954, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20098, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:52:50.348170+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59954, "dest_port": 53}}'); INSERT INTO alerts VALUES(2376,1773071578.625819921,'{"timestamp": "2026-03-09T16:52:58.625820+0100", "flow_id": 717553955342718, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61822, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50463, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:52:58.625820+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61822, "dest_port": 53}}'); INSERT INTO alerts VALUES(2377,1773071578.625821114,'{"timestamp": "2026-03-09T16:52:58.625821+0100", "flow_id": 717558023805279, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65039, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28029, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:52:58.625821+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65039, "dest_port": 53}}'); INSERT INTO alerts VALUES(2378,1773071588.970791102,'{"timestamp": "2026-03-09T16:53:08.970791+0100", "flow_id": 1354768290596456, "event_type": "alert", "src_ip": "193.163.125.182", "src_port": 36135, "dest_ip": "134.19.55.199", "dest_port": 3342, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:53:08.970791+0100", "src_ip": "193.163.125.182", "dest_ip": "134.19.55.199", "src_port": 36135, "dest_port": 3342}}'); INSERT INTO alerts VALUES(2379,1773071589.279230118,'{"timestamp": "2026-03-09T16:53:09.279230+0100", "flow_id": 1480761456950886, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61416, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63256, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:53:09.279230+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61416, "dest_port": 53}}'); INSERT INTO alerts VALUES(2380,1773071589.279230118,'{"timestamp": "2026-03-09T16:53:09.279230+0100", "flow_id": 1480762072793238, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60521, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56253, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:53:09.279230+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60521, "dest_port": 53}}'); INSERT INTO alerts VALUES(2381,1773071595.492429019,'{"timestamp": "2026-03-09T16:53:15.492429+0100", "flow_id": 989066629515108, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59986, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T16:53:15.492429+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59986, "dest_port": 53}}'); INSERT INTO alerts VALUES(2382,1773071595.966068984,'{"timestamp": "2026-03-09T16:53:15.966069+0100", "flow_id": 1053013684440848, "event_type": "alert", "src_ip": "193.163.125.184", "src_port": 32938, "dest_ip": "134.19.55.199", "dest_port": 49171, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:53:15.966069+0100", "src_ip": "193.163.125.184", "dest_ip": "134.19.55.199", "src_port": 32938, "dest_port": 49171}}'); INSERT INTO alerts VALUES(2383,1773071599.30222702,'{"timestamp": "2026-03-09T16:53:19.302227+0100", "flow_id": 2142481424675381, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53851, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10251, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:53:19.302227+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53851, "dest_port": 53}}'); INSERT INTO alerts VALUES(2384,1773071599.30222702,'{"timestamp": "2026-03-09T16:53:19.302227+0100", "flow_id": 2142484232925556, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59198, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43149, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:53:19.302227+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59198, "dest_port": 53}}'); INSERT INTO alerts VALUES(2385,1773071600.407402038,'{"timestamp": "2026-03-09T16:53:20.407402+0100", "flow_id": 60929141287274, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T16:53:20.407402+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2386,1773071610.15707302,'{"timestamp": "2026-03-09T16:53:30.157073+0100", "flow_id": 674626957302060, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58293, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52521, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:53:30.157073+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58293, "dest_port": 53}}'); INSERT INTO alerts VALUES(2387,1773071610.157073974,'{"timestamp": "2026-03-09T16:53:30.157074+0100", "flow_id": 674629498301711, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65388, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59385, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:53:30.157074+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65388, "dest_port": 53}}'); INSERT INTO alerts VALUES(2388,1773071610.587649106,'{"timestamp": "2026-03-09T16:53:30.587649+0100", "flow_id": 835083763298575, "event_type": "alert", "src_ip": "88.210.63.192", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 62443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T16:53:30.587649+0100", "src_ip": "88.210.63.192", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 62443}}'); INSERT INTO alerts VALUES(2389,1773071621.023307085,'{"timestamp": "2026-03-09T16:53:41.023307+0100", "flow_id": 1507481077338174, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58752, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36090, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:53:41.023307+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58752, "dest_port": 53}}'); INSERT INTO alerts VALUES(2390,1773071621.023778915,'{"timestamp": "2026-03-09T16:53:41.023779+0100", "flow_id": 1509506386455702, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64044, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58642, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:53:41.023779+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64044, "dest_port": 53}}'); INSERT INTO alerts VALUES(2391,1773071631.879249096,'{"timestamp": "2026-03-09T16:53:51.879249+0100", "flow_id": 2087497848037992, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49669, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8157, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:53:51.879249+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49669, "dest_port": 53}}'); INSERT INTO alerts VALUES(2392,1773071631.879249096,'{"timestamp": "2026-03-09T16:53:51.879249+0100", "flow_id": 2087497724403116, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54273, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54769, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:53:51.879249+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54273, "dest_port": 53}}'); INSERT INTO alerts VALUES(2393,1773071642.73990798,'{"timestamp": "2026-03-09T16:54:02.739908+0100", "flow_id": 644608371075768, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63914, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20110, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:54:02.739908+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63914, "dest_port": 53}}'); INSERT INTO alerts VALUES(2394,1773071642.739908933,'{"timestamp": "2026-03-09T16:54:02.739909+0100", "flow_id": 644612135983126, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53186, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7323, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:54:02.739909+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53186, "dest_port": 53}}'); INSERT INTO alerts VALUES(2395,1773071653.585527896,'{"timestamp": "2026-03-09T16:54:13.585528+0100", "flow_id": 1670401715875030, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59817, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43863, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:54:13.585528+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59817, "dest_port": 53}}'); INSERT INTO alerts VALUES(2396,1773071653.585529088,'{"timestamp": "2026-03-09T16:54:13.585529+0100", "flow_id": 1670406424209914, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50577, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52841, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:54:13.585529+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50577, "dest_port": 53}}'); INSERT INTO alerts VALUES(2397,1773071665.059922934,'{"timestamp": "2026-03-09T16:54:25.059923+0100", "flow_id": 538842655300367, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54190, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23615, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:54:25.059923+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54190, "dest_port": 53}}'); INSERT INTO alerts VALUES(2398,1773071665.059923888,'{"timestamp": "2026-03-09T16:54:25.059924+0100", "flow_id": 538848273540901, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57307, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36327, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:54:25.059924+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57307, "dest_port": 53}}'); INSERT INTO alerts VALUES(2399,1773071671.391952991,'{"timestamp": "2026-03-09T16:54:31.391953+0100", "flow_id": 2246378404137071, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 15316, "dest_ip": "134.19.55.199", "dest_port": 16654, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:54:31.391953+0100", "src_ip": "167.94.146.37", "dest_ip": "134.19.55.199", "src_port": 15316, "dest_port": 16654}}'); INSERT INTO alerts VALUES(2400,1773071675.915326119,'{"timestamp": "2026-03-09T16:54:35.915326+0100", "flow_id": 1116547645434197, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53617, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24783, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:54:35.915326+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53617, "dest_port": 53}}'); INSERT INTO alerts VALUES(2401,1773071675.915326119,'{"timestamp": "2026-03-09T16:54:35.915326+0100", "flow_id": 1116546318792151, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54545, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64668, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:54:35.915326+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54545, "dest_port": 53}}'); INSERT INTO alerts VALUES(2402,1773071683.042186021,'{"timestamp": "2026-03-09T16:54:43.042186+0100", "flow_id": 1025612838039739, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62462, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33454, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "contacts.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T16:54:43.042186+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62462, "dest_port": 53}}'); INSERT INTO alerts VALUES(2403,1773071690.45324707,'{"timestamp": "2026-03-09T16:54:50.453247+0100", "flow_id": 820781732461210, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55239, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55755, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:54:50.453247+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55239, "dest_port": 53}}'); INSERT INTO alerts VALUES(2404,1773071690.45324707,'{"timestamp": "2026-03-09T16:54:50.453247+0100", "flow_id": 820783512143042, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63071, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14439, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:54:50.453247+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63071, "dest_port": 53}}'); INSERT INTO alerts VALUES(2405,1773071698.131601096,'{"timestamp": "2026-03-09T16:54:58.131601+0100", "flow_id": 565226063578416, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65067, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26773, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "caldav.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T16:54:58.131601+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65067, "dest_port": 53}}'); INSERT INTO alerts VALUES(2406,1773071701.303550004,'{"timestamp": "2026-03-09T16:55:01.303550+0100", "flow_id": 1585214209200115, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62163, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26806, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:55:01.303550+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62163, "dest_port": 53}}'); INSERT INTO alerts VALUES(2407,1773071701.303550004,'{"timestamp": "2026-03-09T16:55:01.303550+0100", "flow_id": 1585215632431811, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64183, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64861, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:55:01.303550+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64183, "dest_port": 53}}'); INSERT INTO alerts VALUES(2408,1773071712.177015066,'{"timestamp": "2026-03-09T16:55:12.177015+0100", "flow_id": 197327528594891, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53983, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26561, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:55:12.177015+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53983, "dest_port": 53}}'); INSERT INTO alerts VALUES(2409,1773071712.177015066,'{"timestamp": "2026-03-09T16:55:12.177015+0100", "flow_id": 197325963368299, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62667, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6420, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:55:12.177015+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62667, "dest_port": 53}}'); INSERT INTO alerts VALUES(2410,1773071723.020361901,'{"timestamp": "2026-03-09T16:55:23.020362+0100", "flow_id": 931882350286449, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58665, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59708, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:55:23.020362+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58665, "dest_port": 53}}'); INSERT INTO alerts VALUES(2411,1773071723.020361901,'{"timestamp": "2026-03-09T16:55:23.020362+0100", "flow_id": 931880643843870, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55346, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5528, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:55:23.020362+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55346, "dest_port": 53}}'); INSERT INTO alerts VALUES(2412,1773071733.874703884,'{"timestamp": "2026-03-09T16:55:33.874704+0100", "flow_id": 1505026038663834, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60444, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11251, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:55:33.874704+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60444, "dest_port": 53}}'); INSERT INTO alerts VALUES(2413,1773071733.874703884,'{"timestamp": "2026-03-09T16:55:33.874704+0100", "flow_id": 1505025944548376, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63455, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38085, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:55:33.874704+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63455, "dest_port": 53}}'); INSERT INTO alerts VALUES(2414,1773071744.729681968,'{"timestamp": "2026-03-09T16:55:44.729682+0100", "flow_id": 37738256700947, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61757, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53546, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:55:44.729682+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61757, "dest_port": 53}}'); INSERT INTO alerts VALUES(2415,1773071744.729681968,'{"timestamp": "2026-03-09T16:55:44.729682+0100", "flow_id": 37737429665286, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51088, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17530, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:55:44.729682+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51088, "dest_port": 53}}'); INSERT INTO alerts VALUES(2416,1773071755.577857018,'{"timestamp": "2026-03-09T16:55:55.577857+0100", "flow_id": 1074505118397608, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55869, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64324, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:55:55.577857+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55869, "dest_port": 53}}'); INSERT INTO alerts VALUES(2417,1773071755.577857018,'{"timestamp": "2026-03-09T16:55:55.577857+0100", "flow_id": 1074503000174974, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55110, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34849, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T16:55:55.577857+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55110, "dest_port": 53}}'); INSERT INTO alerts VALUES(2418,1773071774.512130976,'{"timestamp": "2026-03-09T16:56:14.512131+0100", "flow_id": 1918114298596579, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57931, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21745, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T16:56:14.512131+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57931, "dest_port": 53}}'); INSERT INTO alerts VALUES(2419,1773071774.512131929,'{"timestamp": "2026-03-09T16:56:14.512132+0100", "flow_id": 1918118111910358, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56649, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65210, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T16:56:14.512132+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56649, "dest_port": 53}}'); INSERT INTO alerts VALUES(2420,1773071803.906358958,'{"timestamp": "2026-03-09T16:56:43.906359+0100", "flow_id": 1078032701191272, "event_type": "alert", "src_ip": "167.94.146.33", "src_port": 44281, "dest_ip": "134.19.55.199", "dest_port": 57782, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:56:43.906359+0100", "src_ip": "167.94.146.33", "dest_ip": "134.19.55.199", "src_port": 44281, "dest_port": 57782}}'); INSERT INTO alerts VALUES(2421,1773071838.899693013,'{"timestamp": "2026-03-09T16:57:18.899693+0100", "flow_id": 1893827909691754, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T16:57:18.899693+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2422,1773071842.369980097,'{"timestamp": "2026-03-09T16:57:22.369980+0100", "flow_id": 744630085081881, "event_type": "alert", "src_ip": "91.196.152.68", "src_port": 42806, "dest_ip": "134.19.55.199", "dest_port": 2323, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T16:57:22.369980+0100", "src_ip": "91.196.152.68", "dest_ip": "134.19.55.199", "src_port": 42806, "dest_port": 2323}}'); INSERT INTO alerts VALUES(2423,1773071844.858386993,'{"timestamp": "2026-03-09T16:57:24.858387+0100", "flow_id": 1153471902039652, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58884, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18545, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T16:57:24.858387+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58884, "dest_port": 53}}'); INSERT INTO alerts VALUES(2424,1773071844.859968901,'{"timestamp": "2026-03-09T16:57:24.859969+0100", "flow_id": 1160268011272026, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64234, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22779, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T16:57:24.859969+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64234, "dest_port": 53}}'); INSERT INTO alerts VALUES(2425,1773071870.277314901,'{"timestamp": "2026-03-09T16:57:50.277315+0100", "flow_id": 1754009544337770, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T16:57:50.277315+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2426,1773071901.539411067,'{"timestamp": "2026-03-09T16:58:21.539411+0100", "flow_id": 1472328409196906, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T16:58:21.539411+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2427,1773071906.453490972,'{"timestamp": "2026-03-09T16:58:26.453491+0100", "flow_id": 821832662378820, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 51887, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:58:26.453491+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 51887, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2428,1773071906.453490972,'{"timestamp": "2026-03-09T16:58:26.453491+0100", "flow_id": 821832662378820, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 51887, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T16:58:26.453491+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 51887, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2429,1773072019.85144496,'{"timestamp": "2026-03-09T17:00:19.851445+0100", "flow_id": 1123654374173034, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:00:19.851445+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2430,1773072040.468724012,'{"timestamp": "2026-03-09T17:00:40.468724+0100", "flow_id": 42831115374449, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59547, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36219, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:00:40.468724+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59547, "dest_port": 53}}'); INSERT INTO alerts VALUES(2431,1773072040.468724012,'{"timestamp": "2026-03-09T17:00:40.468724+0100", "flow_id": 42829674477567, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58885, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5094, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:00:40.468724+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58885, "dest_port": 53}}'); INSERT INTO alerts VALUES(2432,1773072098.879144907,'{"timestamp": "2026-03-09T17:01:38.879145+0100", "flow_id": 679674991170287, "event_type": "alert", "src_ip": "43.228.157.22", "src_port": 51411, "dest_ip": "134.19.55.199", "dest_port": 62622, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:01:38.879145+0100", "src_ip": "43.228.157.22", "dest_ip": "134.19.55.199", "src_port": 51411, "dest_port": 62622}}'); INSERT INTO alerts VALUES(2433,1773072104.826613904,'{"timestamp": "2026-03-09T17:01:44.826614+0100", "flow_id": 172581111114090, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:01:44.826614+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2434,1773072135.030193091,'{"timestamp": "2026-03-09T17:02:15.030193+0100", "flow_id": 2100006699057429, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63537, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46459, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:02:15.030193+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63537, "dest_port": 53}}'); INSERT INTO alerts VALUES(2435,1773072135.586045026,'{"timestamp": "2026-03-09T17:02:15.586045+0100", "flow_id": 2235569867499882, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:02:15.586045+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2436,1773072141.068583965,'{"timestamp": "2026-03-09T17:02:21.068584+0100", "flow_id": 1420469767401590, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60508, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T17:02:21.068584+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2437,1773072141.248274088,'{"timestamp": "2026-03-09T17:02:21.248274+0100", "flow_id": 1545384664914425, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 37668, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:02:21.228740+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 37668, "dest_port": 853}}'); INSERT INTO alerts VALUES(2438,1773072144.291568994,'{"timestamp": "2026-03-09T17:02:24.291569+0100", "flow_id": 126382026239847, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60422, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2075, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:02:24.291569+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60422, "dest_port": 53}}'); INSERT INTO alerts VALUES(2439,1773072144.291568994,'{"timestamp": "2026-03-09T17:02:24.291569+0100", "flow_id": 126381663504328, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57465, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24252, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:02:24.291569+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57465, "dest_port": 53}}'); INSERT INTO alerts VALUES(2440,1773072145.632359981,'{"timestamp": "2026-03-09T17:02:25.632360+0100", "flow_id": 464169756026212, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61207, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22402, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:02:25.632360+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61207, "dest_port": 53}}'); INSERT INTO alerts VALUES(2441,1773072145.633400917,'{"timestamp": "2026-03-09T17:02:25.633401+0100", "flow_id": 468637178538421, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64859, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12951, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:02:25.633401+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64859, "dest_port": 53}}'); INSERT INTO alerts VALUES(2442,1773072148.681438923,'{"timestamp": "2026-03-09T17:02:28.681439+0100", "flow_id": 1237909166074359, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55448, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48901, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T17:02:28.681439+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55448, "dest_port": 53}}'); INSERT INTO alerts VALUES(2443,1773072149.830882072,'{"timestamp": "2026-03-09T17:02:29.830882+0100", "flow_id": 1598286420791162, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63346, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46102, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:02:29.830882+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63346, "dest_port": 53}}'); INSERT INTO alerts VALUES(2444,1773072149.831579923,'{"timestamp": "2026-03-09T17:02:29.831580+0100", "flow_id": 1601285576695794, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50096, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61264, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:02:29.831580+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50096, "dest_port": 53}}'); INSERT INTO alerts VALUES(2445,1773072155.746470928,'{"timestamp": "2026-03-09T17:02:35.746471+0100", "flow_id": 954269388510524, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63091, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15638, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:02:35.746471+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63091, "dest_port": 53}}'); INSERT INTO alerts VALUES(2446,1773072161.825088024,'{"timestamp": "2026-03-09T17:02:41.825088+0100", "flow_id": 447503239907451, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62836, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43287, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "unlinkability.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T17:02:41.825088+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62836, "dest_port": 53}}'); INSERT INTO alerts VALUES(2447,1773072163.408706903,'{"timestamp": "2026-03-09T17:02:43.408707+0100", "flow_id": 910959866656816, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61688, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48964, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "attester.gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 80, "bytes_toclient": 0, "start": "2026-03-09T17:02:43.408707+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61688, "dest_port": 53}}'); INSERT INTO alerts VALUES(2448,1773072166.007685899,'{"timestamp": "2026-03-09T17:02:46.007686+0100", "flow_id": 1721861714127210, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:02:46.007686+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2449,1773072166.064022064,'{"timestamp": "2026-03-09T17:02:46.064022+0100", "flow_id": 1963823216497634, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21946, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "config.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:02:46.064022+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2450,1773072166.288564921,'{"timestamp": "2026-03-09T17:02:46.288565+0100", "flow_id": 1802329798179098, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51568, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20471, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T17:02:46.288565+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51568, "dest_port": 53}}'); INSERT INTO alerts VALUES(2451,1773072166.990773917,'{"timestamp": "2026-03-09T17:02:46.990774+0100", "flow_id": 1722070759123303, "event_type": "alert", "src_ip": "205.210.31.73", "src_port": 50456, "dest_ip": "134.19.55.199", "dest_port": 9999, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:02:46.990774+0100", "src_ip": "205.210.31.73", "dest_ip": "134.19.55.199", "src_port": 50456, "dest_port": 9999}}'); INSERT INTO alerts VALUES(2452,1773072168.779556036,'{"timestamp": "2026-03-09T17:02:48.779556+0100", "flow_id": 251944600216254, "event_type": "alert", "src_ip": "185.242.226.71", "src_port": 56858, "dest_ip": "134.19.55.199", "dest_port": 51417, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:02:48.779556+0100", "src_ip": "185.242.226.71", "dest_ip": "134.19.55.199", "src_port": 56858, "dest_port": 51417}}'); INSERT INTO alerts VALUES(2453,1773072175.133232117,'{"timestamp": "2026-03-09T17:02:55.133232+0100", "flow_id": 1979604194887252, "event_type": "alert", "src_ip": "195.184.76.223", "src_port": 56031, "dest_ip": "134.19.55.199", "dest_port": 5313, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:02:55.133232+0100", "src_ip": "195.184.76.223", "dest_ip": "134.19.55.199", "src_port": 56031, "dest_port": 5313}}'); INSERT INTO alerts VALUES(2454,1773072179.037601948,'{"timestamp": "2026-03-09T17:02:59.037602+0100", "flow_id": 1005926804906823, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53542, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "escrowproxy.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-09T17:02:59.037602+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53542, "dest_port": 53}}'); INSERT INTO alerts VALUES(2455,1773072195.984255075,'{"timestamp": "2026-03-09T17:03:15.984255+0100", "flow_id": 849643751791751, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60347, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49131, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:03:15.984255+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60347, "dest_port": 53}}'); INSERT INTO alerts VALUES(2456,1773072195.984572888,'{"timestamp": "2026-03-09T17:03:15.984573+0100", "flow_id": 851012286598622, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60020, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35731, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:03:15.984573+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60020, "dest_port": 53}}'); INSERT INTO alerts VALUES(2457,1773072196.43204093,'{"timestamp": "2026-03-09T17:03:16.432041+0100", "flow_id": 1292652747336042, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:03:16.432041+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2458,1773072212.483289957,'{"timestamp": "2026-03-09T17:03:32.483290+0100", "flow_id": 1231293744322713, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51334, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27684, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:03:32.483290+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51334, "dest_port": 53}}'); INSERT INTO alerts VALUES(2459,1773072212.485548974,'{"timestamp": "2026-03-09T17:03:32.485549+0100", "flow_id": 1240993092773349, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53956, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60411, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:03:32.485549+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53956, "dest_port": 53}}'); INSERT INTO alerts VALUES(2460,1773072212.540128947,'{"timestamp": "2026-03-09T17:03:32.540129+0100", "flow_id": 1193936630077203, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65482, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6800, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:03:32.540129+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65482, "dest_port": 53}}'); INSERT INTO alerts VALUES(2461,1773072212.540128947,'{"timestamp": "2026-03-09T17:03:32.540129+0100", "flow_id": 1193939103583419, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63029, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28641, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:03:32.540129+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63029, "dest_port": 53}}'); INSERT INTO alerts VALUES(2462,1773072212.821314096,'{"timestamp": "2026-03-09T17:03:32.821314+0100", "flow_id": 1275718842023206, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50089, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63975, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T17:03:32.821314+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50089, "dest_port": 53}}'); INSERT INTO alerts VALUES(2463,1773072212.821314096,'{"timestamp": "2026-03-09T17:03:32.821314+0100", "flow_id": 1275718028892271, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55036, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59049, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T17:03:32.821314+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55036, "dest_port": 53}}'); INSERT INTO alerts VALUES(2464,1773072213.69738412,'{"timestamp": "2026-03-09T17:03:33.697384+0100", "flow_id": 1587868600937101, "event_type": "alert", "src_ip": "167.94.146.47", "src_port": 24370, "dest_ip": "134.19.55.199", "dest_port": 45675, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:03:33.697384+0100", "src_ip": "167.94.146.47", "dest_ip": "134.19.55.199", "src_port": 24370, "dest_port": 45675}}'); INSERT INTO alerts VALUES(2465,1773072221.751935959,'{"timestamp": "2026-03-09T17:03:41.751936+0100", "flow_id": 1540693785747568, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57452, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59657, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:03:41.751936+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57452, "dest_port": 53}}'); INSERT INTO alerts VALUES(2466,1773072221.751936913,'{"timestamp": "2026-03-09T17:03:41.751937+0100", "flow_id": 1540697437262135, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51995, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50126, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:03:41.751937+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51995, "dest_port": 53}}'); INSERT INTO alerts VALUES(2467,1773072226.590044021,'{"timestamp": "2026-03-09T17:03:46.590044+0100", "flow_id": 563895581452650, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:03:46.590044+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2468,1773072230.84067607,'{"timestamp": "2026-03-09T17:03:50.840676+0100", "flow_id": 1921827896048301, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51520, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2769, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T17:03:50.840676+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51520, "dest_port": 53}}'); INSERT INTO alerts VALUES(2469,1773072241.030350923,'{"timestamp": "2026-03-09T17:04:01.030351+0100", "flow_id": 411835206300148, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51982, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26572, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:04:01.030351+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51982, "dest_port": 53}}'); INSERT INTO alerts VALUES(2470,1773072249.494427919,'{"timestamp": "2026-03-09T17:04:09.494428+0100", "flow_id": 434702292718409, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 52357, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:04:09.494428+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 52357}}'); INSERT INTO alerts VALUES(2471,1773072249.494427919,'{"timestamp": "2026-03-09T17:04:09.494428+0100", "flow_id": 434702292718409, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 52357, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:04:09.494428+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 52357}}'); INSERT INTO alerts VALUES(2472,1773072250.397372961,'{"timestamp": "2026-03-09T17:04:10.397373+0100", "flow_id": 580804892263995, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 34624, "dest_ip": "134.19.55.199", "dest_port": 8081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:04:10.397373+0100", "src_ip": "193.142.146.230", "dest_ip": "134.19.55.199", "src_port": 34624, "dest_port": 8081}}'); INSERT INTO alerts VALUES(2473,1773072257.878974915,'{"timestamp": "2026-03-09T17:04:17.878975+0100", "flow_id": 397469893699946, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:04:17.878975+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2474,1773072261.252497912,'{"timestamp": "2026-03-09T17:04:21.252498+0100", "flow_id": 1554072710446116, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53414, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:04:21.230763+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 53414, "dest_port": 853}}'); INSERT INTO alerts VALUES(2475,1773072278.637691974,'{"timestamp": "2026-03-09T17:04:38.637692+0100", "flow_id": 1894445213050829, "event_type": "alert", "src_ip": "45.142.154.86", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 29090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:04:38.637692+0100", "src_ip": "45.142.154.86", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 29090}}'); INSERT INTO alerts VALUES(2476,1773072288.327191114,'{"timestamp": "2026-03-09T17:04:48.327191+0100", "flow_id": 279375472929130, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:04:48.327191+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2477,1773072307.447856903,'{"timestamp": "2026-03-09T17:05:07.447857+0100", "flow_id": 1079107718101670, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52382, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39394, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T17:05:07.447857+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52382, "dest_port": 53}}'); INSERT INTO alerts VALUES(2478,1773072319.694506884,'{"timestamp": "2026-03-09T17:05:19.694507+0100", "flow_id": 2138460656937322, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:05:19.694507+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2479,1773072350.77242589,'{"timestamp": "2026-03-09T17:05:50.772426+0100", "flow_id": 1910170260253034, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:05:50.772426+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2480,1773072379.316313982,'{"timestamp": "2026-03-09T17:06:19.316314+0100", "flow_id": 1077086402759703, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63180, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41761, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:06:19.316314+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63180, "dest_port": 53}}'); INSERT INTO alerts VALUES(2481,1773072381.254612923,'{"timestamp": "2026-03-09T17:06:21.254613+0100", "flow_id": 1563092045604684, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 35368, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:06:21.232863+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 35368, "dest_port": 853}}'); INSERT INTO alerts VALUES(2482,1773072382.125813962,'{"timestamp": "2026-03-09T17:06:22.125814+0100", "flow_id": 1947742634158442, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:06:22.125814+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2483,1773072413.101875066,'{"timestamp": "2026-03-09T17:06:53.101875+0100", "flow_id": 1563450435348842, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:06:53.101875+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2484,1773072442.118818999,'{"timestamp": "2026-03-09T17:07:22.118819+0100", "flow_id": 791801790057495, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63180, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41761, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:07:22.118819+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63180, "dest_port": 53}}'); INSERT INTO alerts VALUES(2485,1773072443.96549797,'{"timestamp": "2026-03-09T17:07:23.965498+0100", "flow_id": 1050558325762410, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:07:23.965498+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2486,1773072473.248127938,'{"timestamp": "2026-03-09T17:07:53.248128+0100", "flow_id": 502754786003991, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63180, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41761, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:07:53.248128+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63180, "dest_port": 53}}'); INSERT INTO alerts VALUES(2487,1773072475.395772933,'{"timestamp": "2026-03-09T17:07:55.395773+0100", "flow_id": 855407896734058, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:07:55.395773+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2488,1773072501.258482934,'{"timestamp": "2026-03-09T17:08:21.258483+0100", "flow_id": 1586109801355365, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 33598, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:08:21.238222+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 33598, "dest_port": 853}}'); INSERT INTO alerts VALUES(2489,1773072504.36482811,'{"timestamp": "2026-03-09T17:08:24.364828+0100", "flow_id": 159552539315223, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63180, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41761, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:08:24.364828+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63180, "dest_port": 53}}'); INSERT INTO alerts VALUES(2490,1773072505.572160005,'{"timestamp": "2026-03-09T17:08:25.572160+0100", "flow_id": 487084386330986, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:08:25.572160+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2491,1773072514.745738029,'{"timestamp": "2026-03-09T17:08:34.745738+0100", "flow_id": 669647227104617, "event_type": "alert", "src_ip": "167.94.138.200", "src_port": 53852, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 290, "bytes_toclient": 0, "start": "2026-03-09T17:08:34.745738+0100", "src_ip": "167.94.138.200", "dest_ip": "134.19.55.199", "src_port": 53852, "dest_port": 5060}}'); INSERT INTO alerts VALUES(2492,1773072536.624036074,'{"timestamp": "2026-03-09T17:08:56.624036+0100", "flow_id": 146940156356970, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:08:56.624036+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2493,1773072542.438237906,'{"timestamp": "2026-03-09T17:09:02.438238+0100", "flow_id": 1882218487002487, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 56878, "dest_ip": "134.19.55.199", "dest_port": 30003, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:09:02.438238+0100", "src_ip": "79.124.40.82", "dest_ip": "134.19.55.199", "src_port": 56878, "dest_port": 30003}}'); INSERT INTO alerts VALUES(2494,1773072589.787240982,'{"timestamp": "2026-03-09T17:09:49.787241+0100", "flow_id": 1410852146905241, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56387, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39120, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:09:49.787241+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56387, "dest_port": 53}}'); INSERT INTO alerts VALUES(2495,1773072589.787240982,'{"timestamp": "2026-03-09T17:09:49.787241+0100", "flow_id": 1410850343127615, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64337, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45509, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:09:49.787241+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64337, "dest_port": 53}}'); INSERT INTO alerts VALUES(2496,1773072621.262676955,'{"timestamp": "2026-03-09T17:10:21.262677+0100", "flow_id": 1603926883589236, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53774, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:10:21.242371+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 53774, "dest_port": 853}}'); INSERT INTO alerts VALUES(2497,1773072636.388005019,'{"timestamp": "2026-03-09T17:10:36.388005+0100", "flow_id": 1384997880308401, "event_type": "alert", "src_ip": "20.163.15.207", "src_port": 56376, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T17:10:36.388005+0100", "src_ip": "20.163.15.207", "dest_ip": "134.19.55.199", "src_port": 56376, "dest_port": 5432}}'); INSERT INTO alerts VALUES(2498,1773072653.673290014,'{"timestamp": "2026-03-09T17:10:53.673290+0100", "flow_id": 1484384382396778, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:10:53.673290+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2499,1773072684.709278107,'{"timestamp": "2026-03-09T17:11:24.709278+0100", "flow_id": 1357476688734570, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:11:24.709278+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2500,1773072698.441905021,'{"timestamp": "2026-03-09T17:11:38.441905+0100", "flow_id": 772071192999593, "event_type": "alert", "src_ip": "167.94.138.156", "src_port": 31025, "dest_ip": "134.19.55.199", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:11:38.441905+0100", "src_ip": "167.94.138.156", "dest_ip": "134.19.55.199", "src_port": 31025, "dest_port": 5900}}'); INSERT INTO alerts VALUES(2501,1773072715.623228074,'{"timestamp": "2026-03-09T17:11:55.623228+0100", "flow_id": 987894752913770, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56781, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:11:55.623228+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56781, "dest_port": 53}}'); INSERT INTO alerts VALUES(2502,1773072715.623228074,'{"timestamp": "2026-03-09T17:11:55.623228+0100", "flow_id": 987895391258768, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56184, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33659, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:11:55.623228+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56184, "dest_port": 53}}'); INSERT INTO alerts VALUES(2503,1773072735.420674085,'{"timestamp": "2026-03-09T17:12:15.420674+0100", "flow_id": 2088257323557268, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:12:15.420674+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2504,1773072735.421055078,'{"timestamp": "2026-03-09T17:12:15.421055+0100", "flow_id": 2089895290214250, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:12:15.421055+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2505,1773072737.79185009,'{"timestamp": "2026-03-09T17:12:17.791850+0100", "flow_id": 304745875273957, "event_type": "alert", "src_ip": "45.156.87.91", "src_port": 39568, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:12:17.791850+0100", "src_ip": "45.156.87.91", "dest_ip": "134.19.55.199", "src_port": 39568, "dest_port": 5555}}'); INSERT INTO alerts VALUES(2506,1773072741.264874936,'{"timestamp": "2026-03-09T17:12:21.264875+0100", "flow_id": 1610135047305795, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 60434, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:12:21.243816+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 60434, "dest_port": 853}}'); INSERT INTO alerts VALUES(2507,1773072745.750782012,'{"timestamp": "2026-03-09T17:12:25.750782+0100", "flow_id": 409835151053561, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52452, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63642, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:12:25.750782+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52452, "dest_port": 53}}'); INSERT INTO alerts VALUES(2508,1773072745.750782012,'{"timestamp": "2026-03-09T17:12:25.750782+0100", "flow_id": 409834622302380, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60218, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49604, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:12:25.750782+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60218, "dest_port": 53}}'); INSERT INTO alerts VALUES(2509,1773072749.192374945,'{"timestamp": "2026-03-09T17:12:29.192375+0100", "flow_id": 1670669514299627, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50391, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5948, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:12:29.192375+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50391, "dest_port": 53}}'); INSERT INTO alerts VALUES(2510,1773072757.771405935,'{"timestamp": "2026-03-09T17:12:37.771406+0100", "flow_id": 1624316424029105, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58796, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29629, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:12:37.771406+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58796, "dest_port": 53}}'); INSERT INTO alerts VALUES(2511,1773072765.031374931,'{"timestamp": "2026-03-09T17:12:45.031375+0100", "flow_id": 1542129536872858, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63288, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:12:45.031375+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60064, "dest_port": 53}}'); INSERT INTO alerts VALUES(2512,1773072769.480701924,'{"timestamp": "2026-03-09T17:12:49.480702+0100", "flow_id": 375750129894565, "event_type": "alert", "src_ip": "185.242.226.95", "src_port": 51519, "dest_ip": "134.19.55.199", "dest_port": 8494, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:12:49.480702+0100", "src_ip": "185.242.226.95", "dest_ip": "134.19.55.199", "src_port": 51519, "dest_port": 8494}}'); INSERT INTO alerts VALUES(2513,1773072775.727972984,'{"timestamp": "2026-03-09T17:12:55.727973+0100", "flow_id": 2000721071647924, "event_type": "alert", "src_ip": "61.155.56.138", "src_port": 56179, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T17:12:55.727973+0100", "src_ip": "61.155.56.138", "dest_ip": "134.19.55.199", "src_port": 56179, "dest_port": 1433}}'); INSERT INTO alerts VALUES(2514,1773072780.797633886,'{"timestamp": "2026-03-09T17:13:00.797634+0100", "flow_id": 1174015845579812, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58736, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37927, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:13:00.797634+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58736, "dest_port": 53}}'); INSERT INTO alerts VALUES(2515,1773072792.455115079,'{"timestamp": "2026-03-09T17:13:12.455115+0100", "flow_id": 265855120832528, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55829, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12064, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:13:12.455115+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55829, "dest_port": 53}}'); INSERT INTO alerts VALUES(2516,1773072797.355070115,'{"timestamp": "2026-03-09T17:13:17.355070+0100", "flow_id": 1525015312359828, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:13:17.355070+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2517,1773072797.355071067,'{"timestamp": "2026-03-09T17:13:17.355071+0100", "flow_id": 1525021191444330, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:13:17.355071+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2518,1773072801.634390115,'{"timestamp": "2026-03-09T17:13:21.634390+0100", "flow_id": 472884605144068, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50187, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48359, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:13:21.634390+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50187, "dest_port": 53}}'); INSERT INTO alerts VALUES(2519,1773072803.867068053,'{"timestamp": "2026-03-09T17:13:23.867068+0100", "flow_id": 909281171916950, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55863, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43917, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:13:23.867068+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55863, "dest_port": 53}}'); INSERT INTO alerts VALUES(2520,1773072804.788352012,'{"timestamp": "2026-03-09T17:13:24.788352+0100", "flow_id": 1134147505583244, "event_type": "alert", "src_ip": "198.235.24.150", "src_port": 55076, "dest_ip": "134.19.55.199", "dest_port": 264, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:13:24.788352+0100", "src_ip": "198.235.24.150", "dest_ip": "134.19.55.199", "src_port": 55076, "dest_port": 264}}'); INSERT INTO alerts VALUES(2521,1773072816.153610945,'{"timestamp": "2026-03-09T17:13:36.153611+0100", "flow_id": 96805931570472, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56589, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12743, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:13:36.153611+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56589, "dest_port": 53}}'); INSERT INTO alerts VALUES(2522,1773072827.711855888,'{"timestamp": "2026-03-09T17:13:47.711856+0100", "flow_id": 1087074677055892, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:13:47.711856+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2523,1773072827.711857081,'{"timestamp": "2026-03-09T17:13:47.711857+0100", "flow_id": 1087080556140394, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:13:47.711857+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2524,1773072832.335988998,'{"timestamp": "2026-03-09T17:13:52.335989+0100", "flow_id": 35686890753918, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52228, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40470, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:13:52.335989+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52228, "dest_port": 53}}'); INSERT INTO alerts VALUES(2525,1773072837.258276939,'{"timestamp": "2026-03-09T17:13:57.258277+0100", "flow_id": 1672244629450557, "event_type": "alert", "src_ip": "205.210.31.155", "src_port": 51048, "dest_ip": "134.19.55.199", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:13:57.258277+0100", "src_ip": "205.210.31.155", "dest_ip": "134.19.55.199", "src_port": 51048, "dest_port": 5900}}'); INSERT INTO alerts VALUES(2526,1773072851.050076007,'{"timestamp": "2026-03-09T17:14:11.050076+0100", "flow_id": 1059499791421595, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51290, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46299, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:14:11.050076+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51290, "dest_port": 53}}'); INSERT INTO alerts VALUES(2527,1773072851.930079937,'{"timestamp": "2026-03-09T17:14:11.930080+0100", "flow_id": 898439392372752, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54539, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8031, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:14:11.930080+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54539, "dest_port": 53}}'); INSERT INTO alerts VALUES(2528,1773072851.93008089,'{"timestamp": "2026-03-09T17:14:11.930081+0100", "flow_id": 898443647961075, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51563, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40690, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:14:11.930081+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51563, "dest_port": 53}}'); INSERT INTO alerts VALUES(2529,1773072858.968966007,'{"timestamp": "2026-03-09T17:14:18.968966+0100", "flow_id": 783978834977172, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:14:18.968966+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2530,1773072858.968966007,'{"timestamp": "2026-03-09T17:14:18.968966+0100", "flow_id": 783980419094378, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:14:18.968966+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2531,1773072861.266887904,'{"timestamp": "2026-03-09T17:14:21.266888+0100", "flow_id": 1621373730435668, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 54454, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:14:21.246433+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 54454, "dest_port": 853}}'); INSERT INTO alerts VALUES(2532,1773072862.645023108,'{"timestamp": "2026-03-09T17:14:22.645023+0100", "flow_id": 1925928685194775, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50655, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55541, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:14:22.645023+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50655, "dest_port": 53}}'); INSERT INTO alerts VALUES(2533,1773072874.809041023,'{"timestamp": "2026-03-09T17:14:34.809041+0100", "flow_id": 660058744805784, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58153, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10334, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:14:34.809041+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58153, "dest_port": 53}}'); INSERT INTO alerts VALUES(2534,1773072909.822324992,'{"timestamp": "2026-03-09T17:15:09.822325+0100", "flow_id": 1561534902726302, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64607, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10293, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:15:09.822325+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64607, "dest_port": 53}}'); INSERT INTO alerts VALUES(2535,1773072925.173275947,'{"timestamp": "2026-03-09T17:15:25.173276+0100", "flow_id": 1588641056884880, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56184, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33659, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:15:25.173276+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56184, "dest_port": 53}}'); INSERT INTO alerts VALUES(2536,1773072944.80222392,'{"timestamp": "2026-03-09T17:15:44.802224+0100", "flow_id": 67827398107540, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:15:44.802224+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2537,1773072944.80222392,'{"timestamp": "2026-03-09T17:15:44.802224+0100", "flow_id": 67828982224746, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:15:44.802224+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2538,1773072948.194466114,'{"timestamp": "2026-03-09T17:15:48.194466+0100", "flow_id": 1398177459589904, "event_type": "alert", "src_ip": "167.94.138.154", "src_port": 39392, "dest_ip": "134.19.55.199", "dest_port": 1961, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:15:48.194466+0100", "src_ip": "167.94.138.154", "dest_ip": "134.19.55.199", "src_port": 39392, "dest_port": 1961}}'); INSERT INTO alerts VALUES(2539,1773072955.757237912,'{"timestamp": "2026-03-09T17:15:55.757238+0100", "flow_id": 1000513344532513, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55507, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40259, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:15:55.757238+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55507, "dest_port": 53}}'); INSERT INTO alerts VALUES(2540,1773072955.757237912,'{"timestamp": "2026-03-09T17:15:55.757238+0100", "flow_id": 1000514560996126, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57828, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43475, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:15:55.757238+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57828, "dest_port": 53}}'); INSERT INTO alerts VALUES(2541,1773072956.097419978,'{"timestamp": "2026-03-09T17:15:56.097420+0100", "flow_id": 1262841102783139, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64896, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29679, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:15:56.097420+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64896, "dest_port": 53}}'); INSERT INTO alerts VALUES(2542,1773072967.358797073,'{"timestamp": "2026-03-09T17:16:07.358797+0100", "flow_id": 2103975291516792, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63002, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52378, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:16:07.358797+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63002, "dest_port": 53}}'); INSERT INTO alerts VALUES(2543,1773072970.239392996,'{"timestamp": "2026-03-09T17:16:10.239393+0100", "flow_id": 746710661900022, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56098, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:16:10.239393+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53367, "dest_port": 53}}'); INSERT INTO alerts VALUES(2544,1773072975.458998919,'{"timestamp": "2026-03-09T17:16:15.458999+0100", "flow_id": 1971386968465812, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:16:15.458999+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2545,1773072975.458998919,'{"timestamp": "2026-03-09T17:16:15.458999+0100", "flow_id": 1971388552583018, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:16:15.458999+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2546,1773072979.709584951,'{"timestamp": "2026-03-09T17:16:19.709585+0100", "flow_id": 1077323042975762, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57623, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29994, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:16:19.709585+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57623, "dest_port": 53}}'); INSERT INTO alerts VALUES(2547,1773072981.290563106,'{"timestamp": "2026-03-09T17:16:21.290563+0100", "flow_id": 1439713006704526, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 51352, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:16:21.269673+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 51352, "dest_port": 853}}'); INSERT INTO alerts VALUES(2548,1773072984.674045086,'{"timestamp": "2026-03-09T17:16:24.674045+0100", "flow_id": 80254335501458, "event_type": "alert", "src_ip": "193.163.125.193", "src_port": 34609, "dest_ip": "134.19.55.199", "dest_port": 9901, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:16:24.674045+0100", "src_ip": "193.163.125.193", "dest_ip": "134.19.55.199", "src_port": 34609, "dest_port": 9901}}'); INSERT INTO alerts VALUES(2549,1773072984.988351107,'{"timestamp": "2026-03-09T17:16:24.988351+0100", "flow_id": 22813134559369, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58092, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51933, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:16:24.988351+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58092, "dest_port": 53}}'); INSERT INTO alerts VALUES(2550,1773072984.988351107,'{"timestamp": "2026-03-09T17:16:24.988351+0100", "flow_id": 22812070890364, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50401, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19769, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:16:24.988351+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50401, "dest_port": 53}}'); INSERT INTO alerts VALUES(2551,1773072985.278007031,'{"timestamp": "2026-03-09T17:16:25.278007+0100", "flow_id": 349609534503136, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 52945, "dest_ip": "134.19.55.199", "dest_port": 48027, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:16:25.278007+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 52945, "dest_port": 48027}}'); INSERT INTO alerts VALUES(2552,1773072991.227478027,'{"timestamp": "2026-03-09T17:16:31.227478+0100", "flow_id": 2102913739725863, "event_type": "alert", "src_ip": "167.94.146.42", "src_port": 10270, "dest_ip": "134.19.55.199", "dest_port": 4185, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:16:31.227478+0100", "src_ip": "167.94.146.42", "dest_ip": "134.19.55.199", "src_port": 10270, "dest_port": 4185}}'); INSERT INTO alerts VALUES(2553,1773072991.721276045,'{"timestamp": "2026-03-09T17:16:31.721276+0100", "flow_id": 1971961088125564, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53429, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47416, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:16:31.721276+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53429, "dest_port": 53}}'); INSERT INTO alerts VALUES(2554,1773072994.277246953,'{"timestamp": "2026-03-09T17:16:34.277247+0100", "flow_id": 627817330302493, "event_type": "alert", "src_ip": "64.89.163.137", "src_port": 52804, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:16:34.277247+0100", "src_ip": "64.89.163.137", "dest_ip": "134.19.55.199", "src_port": 52804, "dest_port": 5432}}'); INSERT INTO alerts VALUES(2555,1773072994.277246953,'{"timestamp": "2026-03-09T17:16:34.277247+0100", "flow_id": 627817330302493, "event_type": "alert", "src_ip": "64.89.163.137", "src_port": 52804, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:16:34.277247+0100", "src_ip": "64.89.163.137", "dest_ip": "134.19.55.199", "src_port": 52804, "dest_port": 5432}}'); INSERT INTO alerts VALUES(2556,1773073006.111291886,'{"timestamp": "2026-03-09T17:16:46.111292+0100", "flow_id": 1885371658428820, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:16:46.111292+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2557,1773073006.111291886,'{"timestamp": "2026-03-09T17:16:46.111292+0100", "flow_id": 1885373242546026, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:16:46.111292+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2558,1773073007.494004965,'{"timestamp": "2026-03-09T17:16:47.494005+0100", "flow_id": 2121738880643072, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50490, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41191, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:16:47.494005+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50490, "dest_port": 53}}'); INSERT INTO alerts VALUES(2559,1773073007.494004965,'{"timestamp": "2026-03-09T17:16:47.494005+0100", "flow_id": 2121739056557423, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54933, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60925, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:16:47.494005+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54933, "dest_port": 53}}'); INSERT INTO alerts VALUES(2560,1773073014.467597008,'{"timestamp": "2026-03-09T17:16:54.467597+0100", "flow_id": 1726841048530348, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52060, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45043, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:16:54.467597+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52060, "dest_port": 53}}'); INSERT INTO alerts VALUES(2561,1773073025.959409952,'{"timestamp": "2026-03-09T17:17:05.959410+0100", "flow_id": 461461495797411, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62881, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:17:05.959410+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62881, "dest_port": 53}}'); INSERT INTO alerts VALUES(2562,1773073031.014695883,'{"timestamp": "2026-03-09T17:17:11.014696+0100", "flow_id": 2033447418704412, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62175, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24645, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:17:11.014696+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62175, "dest_port": 53}}'); INSERT INTO alerts VALUES(2563,1773073031.014695883,'{"timestamp": "2026-03-09T17:17:11.014696+0100", "flow_id": 2033447439030267, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55653, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60412, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:17:11.014696+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55653, "dest_port": 53}}'); INSERT INTO alerts VALUES(2564,1773073036.12095189,'{"timestamp": "2026-03-09T17:17:16.120952+0100", "flow_id": 1363911089086868, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:17:16.120952+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2565,1773073036.120953084,'{"timestamp": "2026-03-09T17:17:16.120953+0100", "flow_id": 1363916968171370, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:17:16.120953+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2566,1773073060.332201004,'{"timestamp": "2026-03-09T17:17:40.332201+0100", "flow_id": 1145320799557854, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53016, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45048, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:17:40.332201+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53016, "dest_port": 53}}'); INSERT INTO alerts VALUES(2567,1773073067.518682004,'{"timestamp": "2026-03-09T17:17:47.518682+0100", "flow_id": 1101823594750356, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:17:47.518682+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2568,1773073067.518682956,'{"timestamp": "2026-03-09T17:17:47.518683+0100", "flow_id": 1101829473834858, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:17:47.518683+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2569,1773073083.00701189,'{"timestamp": "2026-03-09T17:18:03.007012+0100", "flow_id": 874545102283124, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62223, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36387, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:18:03.007012+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62223, "dest_port": 53}}'); INSERT INTO alerts VALUES(2570,1773073086.07052803,'{"timestamp": "2026-03-09T17:18:06.070528+0100", "flow_id": 1710293892338049, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14938, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:18:06.070528+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2571,1773073093.200088025,'{"timestamp": "2026-03-09T17:18:13.200088+0100", "flow_id": 1422322743314576, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56184, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33659, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:18:13.200088+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56184, "dest_port": 53}}'); INSERT INTO alerts VALUES(2572,1773073097.631654025,'{"timestamp": "2026-03-09T17:18:17.631654+0100", "flow_id": 461134733271444, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:18:17.631654+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2573,1773073097.631654025,'{"timestamp": "2026-03-09T17:18:17.631654+0100", "flow_id": 461136317388650, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:18:17.631654+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2574,1773073099.088294982,'{"timestamp": "2026-03-09T17:18:19.088295+0100", "flow_id": 942175995001239, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 11314, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:18:19.088295+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 11314}}'); INSERT INTO alerts VALUES(2575,1773073099.787748098,'{"timestamp": "2026-03-09T17:18:19.787748+0100", "flow_id": 850079316159609, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52388, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64765, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:18:19.787748+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52388, "dest_port": 53}}'); INSERT INTO alerts VALUES(2576,1773073099.787748098,'{"timestamp": "2026-03-09T17:18:19.787748+0100", "flow_id": 850077664540960, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57838, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51853, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:18:19.787748+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57838, "dest_port": 53}}'); INSERT INTO alerts VALUES(2577,1773073101.294612885,'{"timestamp": "2026-03-09T17:18:21.294613+0100", "flow_id": 1457395571012095, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53498, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:18:21.273790+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 53498, "dest_port": 853}}'); INSERT INTO alerts VALUES(2578,1773073105.774807929,'{"timestamp": "2026-03-09T17:18:25.774808+0100", "flow_id": 513028584894322, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65113, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58932, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:18:25.774808+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65113, "dest_port": 53}}'); INSERT INTO alerts VALUES(2579,1773073120.446547031,'{"timestamp": "2026-03-09T17:18:40.446547+0100", "flow_id": 229056253468346, "event_type": "alert", "src_ip": "87.121.84.85", "src_port": 59288, "dest_ip": "134.19.55.199", "dest_port": 2011, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:18:40.446547+0100", "src_ip": "87.121.84.85", "dest_ip": "134.19.55.199", "src_port": 59288, "dest_port": 2011}}'); INSERT INTO alerts VALUES(2580,1773073120.878793001,'{"timestamp": "2026-03-09T17:18:40.878793+0100", "flow_id": 115216560152574, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62113, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52539, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:18:40.878793+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62113, "dest_port": 53}}'); INSERT INTO alerts VALUES(2581,1773073120.880117894,'{"timestamp": "2026-03-09T17:18:40.880118+0100", "flow_id": 120905612647541, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53706, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21483, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:18:40.880118+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53706, "dest_port": 53}}'); INSERT INTO alerts VALUES(2582,1773073122.259219885,'{"timestamp": "2026-03-09T17:18:42.259220+0100", "flow_id": 831867410326965, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63968, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27184, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:18:42.259220+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63968, "dest_port": 53}}'); INSERT INTO alerts VALUES(2583,1773073122.259221076,'{"timestamp": "2026-03-09T17:18:42.259221+0100", "flow_id": 831873232769692, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55057, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16830, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:18:42.259221+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55057, "dest_port": 53}}'); INSERT INTO alerts VALUES(2584,1773073128.826133012,'{"timestamp": "2026-03-09T17:18:48.826133+0100", "flow_id": 170515771187604, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:18:48.826133+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2585,1773073128.826947927,'{"timestamp": "2026-03-09T17:18:48.826948+0100", "flow_id": 174017753651050, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:18:48.826948+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2586,1773073140.587152005,'{"timestamp": "2026-03-09T17:19:00.587152+0100", "flow_id": 1395900575495096, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65140, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6712, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:19:00.587152+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65140, "dest_port": 53}}'); INSERT INTO alerts VALUES(2587,1773073159.574815034,'{"timestamp": "2026-03-09T17:19:19.574815+0100", "flow_id": 2187337924108692, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:19:19.574815+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2588,1773073159.574815989,'{"timestamp": "2026-03-09T17:19:19.574816+0100", "flow_id": 2187343803193194, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:19:19.574816+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2589,1773073163.397079945,'{"timestamp": "2026-03-09T17:19:23.397080+0100", "flow_id": 861024408587543, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65013, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:19:23.397080+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53006, "dest_port": 53}}'); INSERT INTO alerts VALUES(2590,1773073189.64599204,'{"timestamp": "2026-03-09T17:19:49.645992+0100", "flow_id": 1648615881204116, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:19:49.645992+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2591,1773073189.645992994,'{"timestamp": "2026-03-09T17:19:49.645993+0100", "flow_id": 1648621760288618, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:19:49.645993+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2592,1773073221.127767086,'{"timestamp": "2026-03-09T17:20:21.127767+0100", "flow_id": 1674656267919764, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:20:21.127767+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2593,1773073221.127767086,'{"timestamp": "2026-03-09T17:20:21.127767+0100", "flow_id": 1674657852036970, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:20:21.127767+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2594,1773073221.296749114,'{"timestamp": "2026-03-09T17:20:21.296749+0100", "flow_id": 1465791675439244, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 59356, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:20:21.275745+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 59356, "dest_port": 853}}'); INSERT INTO alerts VALUES(2595,1773073228.080043077,'{"timestamp": "2026-03-09T17:20:28.080043+0100", "flow_id": 1188207580826758, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58711, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:20:28.080043+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58711, "dest_port": 53}}'); INSERT INTO alerts VALUES(2596,1773073228.080043077,'{"timestamp": "2026-03-09T17:20:28.080043+0100", "flow_id": 1188209209569006, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58835, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17299, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:20:28.080043+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58835, "dest_port": 53}}'); INSERT INTO alerts VALUES(2597,1773073251.169718027,'{"timestamp": "2026-03-09T17:20:51.169718+0100", "flow_id": 1010409510822292, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:20:51.169718+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2598,1773073251.169718027,'{"timestamp": "2026-03-09T17:20:51.169718+0100", "flow_id": 1010411094939498, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:20:51.169718+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2599,1773073251.98227191,'{"timestamp": "2026-03-09T17:20:51.982272+0100", "flow_id": 1122603955733776, "event_type": "alert", "src_ip": "88.210.63.191", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 11111, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:20:51.982272+0100", "src_ip": "88.210.63.191", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 11111}}'); INSERT INTO alerts VALUES(2600,1773073252.851166964,'{"timestamp": "2026-03-09T17:20:52.851167+0100", "flow_id": 1403936873911989, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60657, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12528, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:20:52.851167+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60657, "dest_port": 53}}'); INSERT INTO alerts VALUES(2601,1773073252.851520061,'{"timestamp": "2026-03-09T17:20:52.851520+0100", "flow_id": 1405454857547361, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56429, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8309, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:20:52.851520+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56429, "dest_port": 53}}'); INSERT INTO alerts VALUES(2602,1773073255.042117119,'{"timestamp": "2026-03-09T17:20:55.042117+0100", "flow_id": 2151218089083029, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59603, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18568, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:20:55.042117+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59603, "dest_port": 53}}'); INSERT INTO alerts VALUES(2603,1773073266.184917927,'{"timestamp": "2026-03-09T17:21:06.184918+0100", "flow_id": 794219863967822, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51661, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9167, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:21:06.184918+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51661, "dest_port": 53}}'); INSERT INTO alerts VALUES(2604,1773073281.204093934,'{"timestamp": "2026-03-09T17:21:21.204094+0100", "flow_id": 313628376457620, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:21:21.204094+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2605,1773073281.204093934,'{"timestamp": "2026-03-09T17:21:21.204094+0100", "flow_id": 313629960574826, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:21:21.204094+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2606,1773073297.417006016,'{"timestamp": "2026-03-09T17:21:37.417006+0100", "flow_id": 383654183041091, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50812, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59168, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T17:21:37.417006+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50812, "dest_port": 53}}'); INSERT INTO alerts VALUES(2607,1773073297.634598017,'{"timestamp": "2026-03-09T17:21:37.634598+0100", "flow_id": 473780641821295, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62853, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41645, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:21:37.634598+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62853, "dest_port": 53}}'); INSERT INTO alerts VALUES(2608,1773073297.634864092,'{"timestamp": "2026-03-09T17:21:37.634864+0100", "flow_id": 474924234608759, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56069, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53909, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:21:37.634864+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56069, "dest_port": 53}}'); INSERT INTO alerts VALUES(2609,1773073312.237215996,'{"timestamp": "2026-03-09T17:21:52.237216+0100", "flow_id": 174411306525076, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:21:52.237216+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2610,1773073312.23721695,'{"timestamp": "2026-03-09T17:21:52.237217+0100", "flow_id": 174417185609578, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:21:52.237217+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2611,1773073322.066894055,'{"timestamp": "2026-03-09T17:22:02.066894+0100", "flow_id": 568783836154279, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59877, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406000001, "rev": 1, "signature": "IPFire DBL [Phishing] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 1, "metadata": {"dbl": ["phishing.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6046, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cm.mgid.com", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 57, "bytes_toclient": 0, "start": "2026-03-09T17:22:02.066894+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59877, "dest_port": 53}}'); INSERT INTO alerts VALUES(2612,1773073322.06792903,'{"timestamp": "2026-03-09T17:22:02.067929+0100", "flow_id": 573229265474765, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49676, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406000001, "rev": 1, "signature": "IPFire DBL [Phishing] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 1, "metadata": {"dbl": ["phishing.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62505, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cm.mgid.com", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 57, "bytes_toclient": 0, "start": "2026-03-09T17:22:02.067929+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49676, "dest_port": 53}}'); INSERT INTO alerts VALUES(2613,1773073338.765985966,'{"timestamp": "2026-03-09T17:22:18.765986+0100", "flow_id": 756612419510116, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 12000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:22:18.765986+0100", "src_ip": "185.156.73.86", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 12000}}'); INSERT INTO alerts VALUES(2614,1773073343.433615922,'{"timestamp": "2026-03-09T17:22:23.433616+0100", "flow_id": 2143842790302100, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:22:23.433616+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2615,1773073343.434161902,'{"timestamp": "2026-03-09T17:22:23.434162+0100", "flow_id": 2146189426562922, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:22:23.434162+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2616,1773073346.443149089,'{"timestamp": "2026-03-09T17:22:26.443149+0100", "flow_id": 777413316249212, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50835, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27097, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:22:26.443149+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50835, "dest_port": 53}}'); INSERT INTO alerts VALUES(2617,1773073357.79310608,'{"timestamp": "2026-03-09T17:22:37.793106+0100", "flow_id": 1436041023067922, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53219, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53202, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:22:37.793106+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53219, "dest_port": 53}}'); INSERT INTO alerts VALUES(2618,1773073374.455080986,'{"timestamp": "2026-03-09T17:22:54.455081+0100", "flow_id": 1954559286600084, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:22:54.455081+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2619,1773073374.45508194,'{"timestamp": "2026-03-09T17:22:54.455082+0100", "flow_id": 1954565165684586, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:22:54.455082+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2620,1773073374.500297069,'{"timestamp": "2026-03-09T17:22:54.500297+0100", "flow_id": 1867285007757353, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56238, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406000001, "rev": 1, "signature": "IPFire DBL [Phishing] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 1, "metadata": {"dbl": ["phishing.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52628, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cm.mgid.com", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 57, "bytes_toclient": 0, "start": "2026-03-09T17:22:54.500297+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56238, "dest_port": 53}}'); INSERT INTO alerts VALUES(2621,1773073374.500298023,'{"timestamp": "2026-03-09T17:22:54.500298+0100", "flow_id": 1867291424833731, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61864, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406000001, "rev": 1, "signature": "IPFire DBL [Phishing] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 1, "metadata": {"dbl": ["phishing.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62633, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cm.mgid.com", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 57, "bytes_toclient": 0, "start": "2026-03-09T17:22:54.500298+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61864, "dest_port": 53}}'); INSERT INTO alerts VALUES(2622,1773073389.587049007,'{"timestamp": "2026-03-09T17:23:09.587049+0100", "flow_id": 1570595043153419, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39040, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:23:09.562290+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 39040, "dest_port": 853}}'); INSERT INTO alerts VALUES(2623,1773073390.435841083,'{"timestamp": "2026-03-09T17:23:10.435841+0100", "flow_id": 1871926422322329, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56896, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2027757, "rev": 5, "signature": "ET DNS Query for .to TLD", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2019_07_26"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "updated_at": ["2020_09_17"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11630, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "p.cpx.to", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 54, "bytes_toclient": 0, "start": "2026-03-09T17:23:10.435841+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56896, "dest_port": 53}}'); INSERT INTO alerts VALUES(2624,1773073390.435841083,'{"timestamp": "2026-03-09T17:23:10.435841+0100", "flow_id": 1871927103464156, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2027757, "rev": 5, "signature": "ET DNS Query for .to TLD", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2019_07_26"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "updated_at": ["2020_09_17"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27035, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "p.cpx.to", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 54, "bytes_toclient": 0, "start": "2026-03-09T17:23:10.435841+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55468, "dest_port": 53}}'); INSERT INTO alerts VALUES(2625,1773073392.325781106,'{"timestamp": "2026-03-09T17:23:12.325781+0100", "flow_id": 273320780135215, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61605, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56722, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:23:12.325781+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61605, "dest_port": 53}}'); INSERT INTO alerts VALUES(2626,1773073403.560117006,'{"timestamp": "2026-03-09T17:23:23.560117+0100", "flow_id": 998310851573213, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63970, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21717, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:23:23.560117+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63970, "dest_port": 53}}'); INSERT INTO alerts VALUES(2627,1773073404.574822903,'{"timestamp": "2026-03-09T17:23:24.574823+0100", "flow_id": 1342947353715092, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:23:24.574823+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2628,1773073404.574824095,'{"timestamp": "2026-03-09T17:23:24.574824+0100", "flow_id": 1342953232799594, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:23:24.574824+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2629,1773073426.702687025,'{"timestamp": "2026-03-09T17:23:46.702687+0100", "flow_id": 766218356605717, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61104, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38267, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:23:46.702687+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61104, "dest_port": 53}}'); INSERT INTO alerts VALUES(2630,1773073435.241451025,'{"timestamp": "2026-03-09T17:23:55.241451+0100", "flow_id": 1037025423155604, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:23:55.241451+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55278, "dest_port": 53}}'); INSERT INTO alerts VALUES(2631,1773073435.241451979,'{"timestamp": "2026-03-09T17:23:55.241452+0100", "flow_id": 1037031302240106, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60419, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:23:55.241452+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60419, "dest_port": 53}}'); INSERT INTO alerts VALUES(2632,1773073439.054403067,'{"timestamp": "2026-03-09T17:23:59.054403+0100", "flow_id": 2203986550337467, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57095, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406000001, "rev": 1, "signature": "IPFire DBL [Phishing] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 1, "metadata": {"dbl": ["phishing.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54231, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cm.mgid.com", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 57, "bytes_toclient": 0, "start": "2026-03-09T17:23:59.054403+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57095, "dest_port": 53}}'); INSERT INTO alerts VALUES(2633,1773073439.054404021,'{"timestamp": "2026-03-09T17:23:59.054404+0100", "flow_id": 2203992124590058, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61787, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406000001, "rev": 1, "signature": "IPFire DBL [Phishing] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 1, "metadata": {"dbl": ["phishing.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10370, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cm.mgid.com", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 57, "bytes_toclient": 0, "start": "2026-03-09T17:23:59.054404+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61787, "dest_port": 53}}'); INSERT INTO alerts VALUES(2634,1773073452.436026097,'{"timestamp": "2026-03-09T17:24:12.436026+0100", "flow_id": 1309770142753499, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 33270, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T17:24:12.436026+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 33270, "dest_port": 8545}}'); INSERT INTO alerts VALUES(2635,1773073452.436026097,'{"timestamp": "2026-03-09T17:24:12.436026+0100", "flow_id": 1309770142753499, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 33270, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T17:24:12.436026+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 33270, "dest_port": 8545}}'); INSERT INTO alerts VALUES(2636,1773073462.805495978,'{"timestamp": "2026-03-09T17:24:22.805496+0100", "flow_id": 1770732183666169, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51949, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32033, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:24:22.805496+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51949, "dest_port": 53}}'); INSERT INTO alerts VALUES(2637,1773073468.227909089,'{"timestamp": "2026-03-09T17:24:28.227909+0100", "flow_id": 1260339554834610, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62200, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30534, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:24:28.227909+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62200, "dest_port": 53}}'); INSERT INTO alerts VALUES(2638,1773073468.228430987,'{"timestamp": "2026-03-09T17:24:28.228431+0100", "flow_id": 1262580707118641, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62154, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33625, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:24:28.228431+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62154, "dest_port": 53}}'); INSERT INTO alerts VALUES(2639,1773073472.005587101,'{"timestamp": "2026-03-09T17:24:32.005587+0100", "flow_id": 23999465195845, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:24:32.005587+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2640,1773073494.777668,'{"timestamp": "2026-03-09T17:24:54.777668+0100", "flow_id": 1932687124099899, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:24:54.777668+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2641,1773073494.777668952,'{"timestamp": "2026-03-09T17:24:54.777669+0100", "flow_id": 1932689087890964, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:24:54.777669+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2642,1773073509.5866189,'{"timestamp": "2026-03-09T17:25:09.586619+0100", "flow_id": 1579819538868889, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 41774, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:25:09.564438+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 41774, "dest_port": 853}}'); INSERT INTO alerts VALUES(2643,1773073533.730840921,'{"timestamp": "2026-03-09T17:25:33.730841+0100", "flow_id": 1450091816225093, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:25:33.730841+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2644,1773073555.373862029,'{"timestamp": "2026-03-09T17:25:55.373862+0100", "flow_id": 1042777308410084, "event_type": "alert", "src_ip": "176.65.149.232", "src_port": 45059, "dest_ip": "134.19.55.199", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:25:55.373862+0100", "src_ip": "176.65.149.232", "dest_ip": "134.19.55.199", "src_port": 45059, "dest_port": 8088}}'); INSERT INTO alerts VALUES(2645,1773073556.977598906,'{"timestamp": "2026-03-09T17:25:56.977599+0100", "flow_id": 1384009347003195, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:25:56.977599+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2646,1773073556.977600097,'{"timestamp": "2026-03-09T17:25:56.977600+0100", "flow_id": 1384011310794260, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:25:56.977600+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2647,1773073564.078440905,'{"timestamp": "2026-03-09T17:26:04.078441+0100", "flow_id": 1181329942710597, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:26:04.078441+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2648,1773073571.568887949,'{"timestamp": "2026-03-09T17:26:11.568888+0100", "flow_id": 1035981983217149, "event_type": "alert", "src_ip": "193.163.125.213", "src_port": 47258, "dest_ip": "134.19.55.199", "dest_port": 21301, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:26:11.568888+0100", "src_ip": "193.163.125.213", "dest_ip": "134.19.55.199", "src_port": 47258, "dest_port": 21301}}'); INSERT INTO alerts VALUES(2649,1773073582.419414043,'{"timestamp": "2026-03-09T17:26:22.419414+0100", "flow_id": 1711870591684378, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 55822, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:26:22.398575+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 55822, "dest_port": 853}}'); INSERT INTO alerts VALUES(2650,1773073588.320611001,'{"timestamp": "2026-03-09T17:26:28.320611+0100", "flow_id": 1377017140245307, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:26:28.320611+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2651,1773073588.320611001,'{"timestamp": "2026-03-09T17:26:28.320611+0100", "flow_id": 1377014809069076, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:26:28.320611+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2652,1773073593.585618972,'{"timestamp": "2026-03-09T17:26:33.585619+0100", "flow_id": 544892573659155, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 29000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:26:33.585619+0100", "src_ip": "185.156.73.181", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 29000}}'); INSERT INTO alerts VALUES(2653,1773073594.464653016,'{"timestamp": "2026-03-09T17:26:34.464653+0100", "flow_id": 588298038348101, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:26:34.464653+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2654,1773073595.03261304,'{"timestamp": "2026-03-09T17:26:35.032613+0100", "flow_id": 984498494931522, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53780, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22332, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T17:26:35.032613+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53780, "dest_port": 53}}'); INSERT INTO alerts VALUES(2655,1773073606.031223058,'{"timestamp": "2026-03-09T17:26:46.031223+0100", "flow_id": 1822953713787139, "event_type": "alert", "src_ip": "198.235.24.192", "src_port": 52263, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:26:46.031223+0100", "src_ip": "198.235.24.192", "dest_ip": "134.19.55.199", "src_port": 52263, "dest_port": 1433}}'); INSERT INTO alerts VALUES(2656,1773073606.031223058,'{"timestamp": "2026-03-09T17:26:46.031223+0100", "flow_id": 1822953713787139, "event_type": "alert", "src_ip": "198.235.24.192", "src_port": 52263, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:26:46.031223+0100", "src_ip": "198.235.24.192", "dest_ip": "134.19.55.199", "src_port": 52263, "dest_port": 1433}}'); INSERT INTO alerts VALUES(2657,1773073619.571747065,'{"timestamp": "2026-03-09T17:26:59.571747+0100", "flow_id": 1048263163540283, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:26:59.571747+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2658,1773073619.571747065,'{"timestamp": "2026-03-09T17:26:59.571747+0100", "flow_id": 1048260832364052, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:26:59.571747+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2659,1773073623.14154911,'{"timestamp": "2026-03-09T17:27:03.141549+0100", "flow_id": 2015323506815419, "event_type": "alert", "src_ip": "198.235.24.253", "src_port": 56230, "dest_ip": "134.19.55.199", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:27:03.141549+0100", "src_ip": "198.235.24.253", "dest_ip": "134.19.55.199", "src_port": 56230, "dest_port": 161}}'); INSERT INTO alerts VALUES(2660,1773073623.14154911,'{"timestamp": "2026-03-09T17:27:03.141549+0100", "flow_id": 2015323506815419, "event_type": "alert", "src_ip": "198.235.24.253", "src_port": 56230, "dest_ip": "134.19.55.199", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:27:03.141549+0100", "src_ip": "198.235.24.253", "dest_ip": "134.19.55.199", "src_port": 56230, "dest_port": 161}}'); INSERT INTO alerts VALUES(2661,1773073625.810139895,'{"timestamp": "2026-03-09T17:27:05.810140+0100", "flow_id": 383303544277317, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:27:05.810140+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2662,1773073628.335596084,'{"timestamp": "2026-03-09T17:27:08.335596+0100", "flow_id": 1159902871783685, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58078, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6523, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:27:08.335596+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58078, "dest_port": 53}}'); INSERT INTO alerts VALUES(2663,1773073650.325284005,'{"timestamp": "2026-03-09T17:27:30.325284+0100", "flow_id": 834137568998203, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:27:30.325284+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2664,1773073650.325576067,'{"timestamp": "2026-03-09T17:27:30.325576+0100", "flow_id": 835389368272404, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:27:30.325576+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2665,1773073653.638777971,'{"timestamp": "2026-03-09T17:27:33.638778+0100", "flow_id": 1617634076587755, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64845, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42722, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:27:33.638778+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64845, "dest_port": 53}}'); INSERT INTO alerts VALUES(2666,1773073653.6393919,'{"timestamp": "2026-03-09T17:27:33.639392+0100", "flow_id": 1620269885770783, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62136, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:27:33.639392+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62136, "dest_port": 53}}'); INSERT INTO alerts VALUES(2667,1773073656.317779064,'{"timestamp": "2026-03-09T17:27:36.317779+0100", "flow_id": 238953988426053, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:27:36.317779+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2668,1773073680.361524106,'{"timestamp": "2026-03-09T17:28:00.361524+0100", "flow_id": 145362253673275, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:28:00.361524+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2669,1773073680.361525058,'{"timestamp": "2026-03-09T17:28:00.361525+0100", "flow_id": 145364217464340, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:28:00.361525+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2670,1773073687.062580109,'{"timestamp": "2026-03-09T17:28:07.062580+0100", "flow_id": 2239105603384034, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49735, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30400, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:28:07.062580+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49735, "dest_port": 53}}'); INSERT INTO alerts VALUES(2671,1773073687.558516025,'{"timestamp": "2026-03-09T17:28:07.558516+0100", "flow_id": 2117336460495173, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:28:07.558516+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2672,1773073702.424830914,'{"timestamp": "2026-03-09T17:28:22.424831+0100", "flow_id": 1731792128778652, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 52380, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:28:22.403214+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 52380, "dest_port": 853}}'); INSERT INTO alerts VALUES(2673,1773073711.470056056,'{"timestamp": "2026-03-09T17:28:31.470056+0100", "flow_id": 2018878527796027, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:28:31.470056+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2674,1773073711.470705986,'{"timestamp": "2026-03-09T17:28:31.470706+0100", "flow_id": 2021667925362196, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:28:31.470706+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2675,1773073712.217801095,'{"timestamp": "2026-03-09T17:28:32.217801+0100", "flow_id": 91024326289802, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64052, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27284, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:28:32.217801+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64052, "dest_port": 53}}'); INSERT INTO alerts VALUES(2676,1773073712.217801095,'{"timestamp": "2026-03-09T17:28:32.217801+0100", "flow_id": 91026760027704, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52010, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17122, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:28:32.217801+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52010, "dest_port": 53}}'); INSERT INTO alerts VALUES(2677,1773073718.21809411,'{"timestamp": "2026-03-09T17:28:38.218094+0100", "flow_id": 1781135010498885, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:28:38.218094+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2678,1773073733.787919045,'{"timestamp": "2026-03-09T17:28:53.787919+0100", "flow_id": 1413762218071051, "event_type": "alert", "src_ip": "167.94.146.74", "src_port": 3973, "dest_ip": "134.19.55.199", "dest_port": 11660, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:28:53.787919+0100", "src_ip": "167.94.146.74", "dest_ip": "134.19.55.199", "src_port": 3973, "dest_port": 11660}}'); INSERT INTO alerts VALUES(2679,1773073741.769901991,'{"timestamp": "2026-03-09T17:29:01.769902+0100", "flow_id": 1617857431368507, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:29:01.769902+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2680,1773073741.769902944,'{"timestamp": "2026-03-09T17:29:01.769903+0100", "flow_id": 1617859395159572, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:29:01.769903+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2681,1773073745.713145018,'{"timestamp": "2026-03-09T17:29:05.713145+0100", "flow_id": 529663743223549, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63935, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23592, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:29:05.713145+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63935, "dest_port": 53}}'); INSERT INTO alerts VALUES(2682,1773073749.433480978,'{"timestamp": "2026-03-09T17:29:09.433481+0100", "flow_id": 1580315224639813, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:29:09.433481+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2683,1773073771.787822009,'{"timestamp": "2026-03-09T17:29:31.787822+0100", "flow_id": 850398315180859, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:29:31.787822+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2684,1773073771.787822961,'{"timestamp": "2026-03-09T17:29:31.787823+0100", "flow_id": 850400278971924, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:29:31.787823+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2685,1773073772.867976904,'{"timestamp": "2026-03-09T17:29:32.867977+0100", "flow_id": 1194659438325810, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12199, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:29:32.867977+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2686,1773073779.446801901,'{"timestamp": "2026-03-09T17:29:39.446802+0100", "flow_id": 1074578530568517, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:29:39.446802+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2687,1773073785.787866115,'{"timestamp": "2026-03-09T17:29:45.787866+0100", "flow_id": 287635333384336, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56184, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33659, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:29:45.787866+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56184, "dest_port": 53}}'); INSERT INTO alerts VALUES(2688,1773073802.586666107,'{"timestamp": "2026-03-09T17:30:02.586666+0100", "flow_id": 830864803918651, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:30:02.586666+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2689,1773073802.587308883,'{"timestamp": "2026-03-09T17:30:02.587309+0100", "flow_id": 833624136713748, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:30:02.587309+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2690,1773073809.447006941,'{"timestamp": "2026-03-09T17:30:09.447007+0100", "flow_id": 512509045442885, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:30:09.447007+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2691,1773073815.699362994,'{"timestamp": "2026-03-09T17:30:15.699363+0100", "flow_id": 2159319798649611, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59061, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29055, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:30:15.699363+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59061, "dest_port": 53}}'); INSERT INTO alerts VALUES(2692,1773073821.593269109,'{"timestamp": "2026-03-09T17:30:21.593269+0100", "flow_id": 1422175014785011, "event_type": "alert", "src_ip": "45.142.154.10", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 9200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:30:21.593269+0100", "src_ip": "45.142.154.10", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 9200}}'); INSERT INTO alerts VALUES(2693,1773073822.428668022,'{"timestamp": "2026-03-09T17:30:22.428668+0100", "flow_id": 1751492741126604, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 49230, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:30:22.407801+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 49230, "dest_port": 853}}'); INSERT INTO alerts VALUES(2694,1773073869.160685062,'{"timestamp": "2026-03-09T17:31:09.160685+0100", "flow_id": 1534563725353404, "event_type": "alert", "src_ip": "167.94.146.73", "src_port": 38310, "dest_ip": "134.19.55.199", "dest_port": 64458, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:31:09.160685+0100", "src_ip": "167.94.146.73", "dest_ip": "134.19.55.199", "src_port": 38310, "dest_port": 64458}}'); INSERT INTO alerts VALUES(2695,1773073891.269866944,'{"timestamp": "2026-03-09T17:31:31.269867+0100", "flow_id": 877597292945803, "event_type": "alert", "src_ip": "167.94.138.146", "src_port": 24242, "dest_ip": "134.19.55.199", "dest_port": 47809, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 45, "bytes_toclient": 0, "start": "2026-03-09T17:31:31.269867+0100", "src_ip": "167.94.138.146", "dest_ip": "134.19.55.199", "src_port": 24242, "dest_port": 47809}}'); INSERT INTO alerts VALUES(2696,1773073893.896135092,'{"timestamp": "2026-03-09T17:31:33.896135+0100", "flow_id": 1597074187028805, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:31:33.896135+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2697,1773073893.896135092,'{"timestamp": "2026-03-09T17:31:33.896135+0100", "flow_id": 1597074084623163, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:31:33.896135+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2698,1773073893.896136045,'{"timestamp": "2026-03-09T17:31:33.896136+0100", "flow_id": 1597076048414228, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:31:33.896136+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2699,1773073940.670072078,'{"timestamp": "2026-03-09T17:32:20.670072+0100", "flow_id": 1189089117807075, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59687, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51182, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:32:20.670072+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59687, "dest_port": 53}}'); INSERT INTO alerts VALUES(2700,1773073940.670072078,'{"timestamp": "2026-03-09T17:32:20.670072+0100", "flow_id": 1189090139460515, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52772, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45920, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:32:20.670072+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52772, "dest_port": 53}}'); INSERT INTO alerts VALUES(2701,1773073942.431236029,'{"timestamp": "2026-03-09T17:32:22.431236+0100", "flow_id": 1761156458773846, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 51354, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:32:22.410051+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 51354, "dest_port": 853}}'); INSERT INTO alerts VALUES(2702,1773073946.591448068,'{"timestamp": "2026-03-09T17:32:26.591448+0100", "flow_id": 569926353881232, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56184, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33659, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:32:26.591448+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56184, "dest_port": 53}}'); INSERT INTO alerts VALUES(2703,1773073946.591449023,'{"timestamp": "2026-03-09T17:32:26.591449+0100", "flow_id": 569929887490333, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53286, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46608, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:32:26.591449+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53286, "dest_port": 53}}'); INSERT INTO alerts VALUES(2704,1773073948.825838088,'{"timestamp": "2026-03-09T17:32:28.825838+0100", "flow_id": 1295149981299276, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56639, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:32:28.825838+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56639, "dest_port": 53}}'); INSERT INTO alerts VALUES(2705,1773073948.838502884,'{"timestamp": "2026-03-09T17:32:28.838503+0100", "flow_id": 1349544744413257, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56457, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62123, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:32:28.838503+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56457, "dest_port": 53}}'); INSERT INTO alerts VALUES(2706,1773073955.358644963,'{"timestamp": "2026-03-09T17:32:35.358645+0100", "flow_id": 977422075365701, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:32:35.358645+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2707,1773073955.358644963,'{"timestamp": "2026-03-09T17:32:35.358645+0100", "flow_id": 977421972960059, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:32:35.358645+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2708,1773073955.358645916,'{"timestamp": "2026-03-09T17:32:35.358646+0100", "flow_id": 977423936751124, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:32:35.358646+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2709,1773073985.872962952,'{"timestamp": "2026-03-09T17:33:05.872963+0100", "flow_id": 371651298003269, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:33:05.872963+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53181, "dest_port": 53}}'); INSERT INTO alerts VALUES(2710,1773073985.872963905,'{"timestamp": "2026-03-09T17:33:05.872964+0100", "flow_id": 371655490564923, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:33:05.872964+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52849, "dest_port": 53}}'); INSERT INTO alerts VALUES(2711,1773073985.872963905,'{"timestamp": "2026-03-09T17:33:05.872964+0100", "flow_id": 371653159388692, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:33:05.872964+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62449, "dest_port": 53}}'); INSERT INTO alerts VALUES(2712,1773073997.403099061,'{"timestamp": "2026-03-09T17:33:17.403099+0100", "flow_id": 1449822351365856, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63798, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36647, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:33:17.403099+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63798, "dest_port": 53}}'); INSERT INTO alerts VALUES(2713,1773074005.348964929,'{"timestamp": "2026-03-09T17:33:25.348965+0100", "flow_id": 1498796839327372, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62357, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35276, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:33:25.348965+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62357, "dest_port": 53}}'); INSERT INTO alerts VALUES(2714,1773074012.357207059,'{"timestamp": "2026-03-09T17:33:32.357207+0100", "flow_id": 1252720793894255, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 8000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:33:32.357207+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 8000}}'); INSERT INTO alerts VALUES(2715,1773074012.357207059,'{"timestamp": "2026-03-09T17:33:32.357207+0100", "flow_id": 1252720793894255, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 8000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:33:32.357207+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 8000}}'); INSERT INTO alerts VALUES(2716,1773074016.196981907,'{"timestamp": "2026-03-09T17:33:36.196982+0100", "flow_id": 1610187370903, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54210, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23775, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:33:36.196982+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54210, "dest_port": 53}}'); INSERT INTO alerts VALUES(2717,1773074027.039477109,'{"timestamp": "2026-03-09T17:33:47.039477+0100", "flow_id": 1013977785546469, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54167, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27430, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:33:47.039477+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54167, "dest_port": 53}}'); INSERT INTO alerts VALUES(2718,1773074037.901918889,'{"timestamp": "2026-03-09T17:33:57.901919+0100", "flow_id": 1621913577347017, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51070, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16084, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:33:57.901919+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51070, "dest_port": 53}}'); INSERT INTO alerts VALUES(2719,1773074048.750603915,'{"timestamp": "2026-03-09T17:34:08.750604+0100", "flow_id": 127595801333260, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60291, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5606, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:34:08.750604+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60291, "dest_port": 53}}'); INSERT INTO alerts VALUES(2720,1773074059.412131072,'{"timestamp": "2026-03-09T17:34:19.412131+0100", "flow_id": 925667496134958, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55749, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38832, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:34:19.412131+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55749, "dest_port": 53}}'); INSERT INTO alerts VALUES(2721,1773074062.43635106,'{"timestamp": "2026-03-09T17:34:22.436351+0100", "flow_id": 1773677238627609, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 41610, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:34:22.412966+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 41610, "dest_port": 853}}'); INSERT INTO alerts VALUES(2722,1773074067.821806907,'{"timestamp": "2026-03-09T17:34:27.821807+0100", "flow_id": 996362267229270, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53613, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41497, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:34:27.821807+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53613, "dest_port": 53}}'); INSERT INTO alerts VALUES(2723,1773074080.704401969,'{"timestamp": "2026-03-09T17:34:40.704402+0100", "flow_id": 210634159858913, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55002, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37210, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:34:40.704402+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55002, "dest_port": 53}}'); INSERT INTO alerts VALUES(2724,1773074092.08317709,'{"timestamp": "2026-03-09T17:34:52.083177+0100", "flow_id": 1201668935836817, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63142, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32729, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:34:52.083177+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63142, "dest_port": 53}}'); INSERT INTO alerts VALUES(2725,1773074093.920317889,'{"timestamp": "2026-03-09T17:34:53.920318+0100", "flow_id": 1419461339581187, "event_type": "alert", "src_ip": "85.217.140.17", "src_port": 58168, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T17:34:53.920318+0100", "src_ip": "85.217.140.17", "dest_ip": "134.19.55.199", "src_port": 58168, "dest_port": 1433}}'); INSERT INTO alerts VALUES(2726,1773074102.63606906,'{"timestamp": "2026-03-09T17:35:02.636069+0100", "flow_id": 1887472443799738, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56370, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60391, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:35:02.636069+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56370, "dest_port": 53}}'); INSERT INTO alerts VALUES(2727,1773074104.587887049,'{"timestamp": "2026-03-09T17:35:04.587887+0100", "flow_id": 273157815869311, "event_type": "alert", "src_ip": "185.156.73.182", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 55555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:35:04.587887+0100", "src_ip": "185.156.73.182", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 55555}}'); INSERT INTO alerts VALUES(2728,1773074113.495769024,'{"timestamp": "2026-03-09T17:35:13.495769+0100", "flow_id": 440463724419899, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60062, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2968, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:35:13.495769+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60062, "dest_port": 53}}'); INSERT INTO alerts VALUES(2729,1773074124.324703932,'{"timestamp": "2026-03-09T17:35:24.324704+0100", "flow_id": 1394593765383339, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49440, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5111, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:35:24.324704+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49440, "dest_port": 53}}'); INSERT INTO alerts VALUES(2730,1773074135.1940279,'{"timestamp": "2026-03-09T17:35:35.194028+0100", "flow_id": 2240721664453883, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55386, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56699, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:35:35.194028+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55386, "dest_port": 53}}'); INSERT INTO alerts VALUES(2731,1773074146.042049884,'{"timestamp": "2026-03-09T17:35:46.042050+0100", "flow_id": 743555354880427, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54750, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21840, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:35:46.042050+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54750, "dest_port": 53}}'); INSERT INTO alerts VALUES(2732,1773074156.036571026,'{"timestamp": "2026-03-09T17:35:56.036571+0100", "flow_id": 1282974032272169, "event_type": "alert", "src_ip": "130.12.180.52", "src_port": 59044, "dest_ip": "134.19.55.199", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:35:56.036571+0100", "src_ip": "130.12.180.52", "dest_ip": "134.19.55.199", "src_port": 59044, "dest_port": 8888}}'); INSERT INTO alerts VALUES(2733,1773074156.036571026,'{"timestamp": "2026-03-09T17:35:56.036571+0100", "flow_id": 1282974032272169, "event_type": "alert", "src_ip": "130.12.180.52", "src_port": 59044, "dest_ip": "134.19.55.199", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:35:56.036571+0100", "src_ip": "130.12.180.52", "dest_ip": "134.19.55.199", "src_port": 59044, "dest_port": 8888}}'); INSERT INTO alerts VALUES(2734,1773074156.878951073,'{"timestamp": "2026-03-09T17:35:56.878951+0100", "flow_id": 1241793449689281, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59718, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37767, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:35:56.878951+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59718, "dest_port": 53}}'); INSERT INTO alerts VALUES(2735,1773074167.738723994,'{"timestamp": "2026-03-09T17:36:07.738724+0100", "flow_id": 2046898625159121, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60755, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57256, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:36:07.738724+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60755, "dest_port": 53}}'); INSERT INTO alerts VALUES(2736,1773074177.751614094,'{"timestamp": "2026-03-09T17:36:17.751614+0100", "flow_id": 413409226151214, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 26814, "dest_ip": "134.19.55.199", "dest_port": 54908, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:36:17.751614+0100", "src_ip": "167.94.146.32", "dest_ip": "134.19.55.199", "src_port": 26814, "dest_port": 54908}}'); INSERT INTO alerts VALUES(2737,1773074178.59253192,'{"timestamp": "2026-03-09T17:36:18.592532+0100", "flow_id": 574581948309257, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53895, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10231, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:36:18.592532+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53895, "dest_port": 53}}'); INSERT INTO alerts VALUES(2738,1773074182.437112092,'{"timestamp": "2026-03-09T17:36:22.437112+0100", "flow_id": 1779500016722672, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 49752, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:36:22.414322+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 49752, "dest_port": 853}}'); INSERT INTO alerts VALUES(2739,1773074189.451426983,'{"timestamp": "2026-03-09T17:36:29.451427+0100", "flow_id": 1657393114832894, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60295, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26991, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:36:29.451427+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60295, "dest_port": 53}}'); INSERT INTO alerts VALUES(2740,1773074192.14754796,'{"timestamp": "2026-03-09T17:36:32.147548+0100", "flow_id": 70768050089090, "event_type": "alert", "src_ip": "195.184.76.217", "src_port": 42846, "dest_ip": "134.19.55.199", "dest_port": 5314, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:36:32.147548+0100", "src_ip": "195.184.76.217", "dest_ip": "134.19.55.199", "src_port": 42846, "dest_port": 5314}}'); INSERT INTO alerts VALUES(2741,1773074200.310173034,'{"timestamp": "2026-03-09T17:36:40.310173+0100", "flow_id": 206283931776201, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61374, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36388, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:36:40.310173+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61374, "dest_port": 53}}'); INSERT INTO alerts VALUES(2742,1773074205.066381931,'{"timestamp": "2026-03-09T17:36:45.066382+0100", "flow_id": 1411009227148452, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65368, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51510, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:36:45.066382+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65368, "dest_port": 53}}'); INSERT INTO alerts VALUES(2743,1773074218.944233895,'{"timestamp": "2026-03-09T17:36:58.944234+0100", "flow_id": 677755633327996, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56995, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1069, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:36:58.944234+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56995, "dest_port": 53}}'); INSERT INTO alerts VALUES(2744,1773074225.470154047,'{"timestamp": "2026-03-09T17:37:05.470154+0100", "flow_id": 330447899325611, "event_type": "alert", "src_ip": "45.142.154.87", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 3119, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:37:05.470154+0100", "src_ip": "45.142.154.87", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 3119}}'); INSERT INTO alerts VALUES(2745,1773074228.985586882,'{"timestamp": "2026-03-09T17:37:08.985587+0100", "flow_id": 1136842991996614, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58298, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36841, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:37:08.985587+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58298, "dest_port": 53}}'); INSERT INTO alerts VALUES(2746,1773074239.017081023,'{"timestamp": "2026-03-09T17:37:19.017081+0100", "flow_id": 2043687301652585, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65487, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59596, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:37:19.017081+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65487, "dest_port": 53}}'); INSERT INTO alerts VALUES(2747,1773074249.667047023,'{"timestamp": "2026-03-09T17:37:29.667047+0100", "flow_id": 331674206051242, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52948, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 543, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:37:29.667047+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52948, "dest_port": 53}}'); INSERT INTO alerts VALUES(2748,1773074260.517813921,'{"timestamp": "2026-03-09T17:37:40.517814+0100", "flow_id": 1379572015575230, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60470, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:37:40.517814+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60470, "dest_port": 53}}'); INSERT INTO alerts VALUES(2749,1773074271.369973898,'{"timestamp": "2026-03-09T17:37:51.369974+0100", "flow_id": 2151980395190718, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54930, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41753, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:37:51.369974+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54930, "dest_port": 53}}'); INSERT INTO alerts VALUES(2750,1773074282.2124691,'{"timestamp": "2026-03-09T17:38:02.212469+0100", "flow_id": 631073483872786, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49661, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60348, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:38:02.212469+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49661, "dest_port": 53}}'); INSERT INTO alerts VALUES(2751,1773074292.883311034,'{"timestamp": "2026-03-09T17:38:12.883311+0100", "flow_id": 1260518739509294, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55948, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19646, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:38:12.883311+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55948, "dest_port": 53}}'); INSERT INTO alerts VALUES(2752,1773074302.44587493,'{"timestamp": "2026-03-09T17:38:22.445875+0100", "flow_id": 1820368511530938, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 41618, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:38:22.423837+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 41618, "dest_port": 853}}'); INSERT INTO alerts VALUES(2753,1773074303.748765946,'{"timestamp": "2026-03-09T17:38:23.748766+0100", "flow_id": 2090028094793442, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53063, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44423, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:38:23.748766+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53063, "dest_port": 53}}'); INSERT INTO alerts VALUES(2754,1773074314.574390888,'{"timestamp": "2026-03-09T17:38:34.574391+0100", "flow_id": 778143454527422, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51499, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:38:34.574391+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51499, "dest_port": 53}}'); INSERT INTO alerts VALUES(2755,1773074325.448811054,'{"timestamp": "2026-03-09T17:38:45.448811+0100", "flow_id": 1646153658541111, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54737, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8958, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:38:45.448811+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54737, "dest_port": 53}}'); INSERT INTO alerts VALUES(2756,1773074327.514070988,'{"timestamp": "2026-03-09T17:38:47.514071+0100", "flow_id": 2207918747142144, "event_type": "alert", "src_ip": "198.235.24.107", "src_port": 53764, "dest_ip": "134.19.55.199", "dest_port": 10011, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:38:47.514071+0100", "src_ip": "198.235.24.107", "dest_ip": "134.19.55.199", "src_port": 53764, "dest_port": 10011}}'); INSERT INTO alerts VALUES(2757,1773074336.921257019,'{"timestamp": "2026-03-09T17:38:56.921257+0100", "flow_id": 1394593557646330, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57430, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 2, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 2, "id": 42224, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 1, "bytes_toserver": 157, "bytes_toclient": 145, "start": "2026-03-09T17:35:24.324704+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57430, "dest_port": 53}}'); INSERT INTO alerts VALUES(2758,1773074342.208739996,'{"timestamp": "2026-03-09T17:39:02.208740+0100", "flow_id": 1740959654149277, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50203, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6794, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:39:02.208740+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50203, "dest_port": 53}}'); INSERT INTO alerts VALUES(2759,1773074342.208740949,'{"timestamp": "2026-03-09T17:39:02.208741+0100", "flow_id": 1740963958895271, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65384, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37416, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:39:02.208741+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65384, "dest_port": 53}}'); INSERT INTO alerts VALUES(2760,1773074347.556551934,'{"timestamp": "2026-03-09T17:39:07.556552+0100", "flow_id": 983001822802531, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54600, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26692, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:39:07.556552+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54600, "dest_port": 53}}'); INSERT INTO alerts VALUES(2761,1773074358.416737079,'{"timestamp": "2026-03-09T17:39:18.416737+0100", "flow_id": 1789872318051151, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51907, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19862, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:39:18.416737+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51907, "dest_port": 53}}'); INSERT INTO alerts VALUES(2762,1773074360.894318103,'{"timestamp": "2026-03-09T17:39:20.894318+0100", "flow_id": 181895962265343, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52093, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 564, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "edge-050.deber3.ce.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-09T17:39:20.894318+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52093, "dest_port": 53}}'); INSERT INTO alerts VALUES(2763,1773074369.273792983,'{"timestamp": "2026-03-09T17:39:29.273793+0100", "flow_id": 331511208148923, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51247, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52637, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:39:29.273793+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51247, "dest_port": 53}}'); INSERT INTO alerts VALUES(2764,1773074372.308672905,'{"timestamp": "2026-03-09T17:39:32.308673+0100", "flow_id": 1325744669001928, "event_type": "alert", "src_ip": "205.210.31.221", "src_port": 54511, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:39:32.308673+0100", "src_ip": "205.210.31.221", "dest_ip": "134.19.55.199", "src_port": 54511, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2765,1773074372.308672905,'{"timestamp": "2026-03-09T17:39:32.308673+0100", "flow_id": 1325744669001928, "event_type": "alert", "src_ip": "205.210.31.221", "src_port": 54511, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:39:32.308673+0100", "src_ip": "205.210.31.221", "dest_ip": "134.19.55.199", "src_port": 54511, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2766,1773074379.301681995,'{"timestamp": "2026-03-09T17:39:39.301682+0100", "flow_id": 1014240078954718, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51053, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30316, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:39:39.301682+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51053, "dest_port": 53}}'); INSERT INTO alerts VALUES(2767,1773074389.345918894,'{"timestamp": "2026-03-09T17:39:49.345919+0100", "flow_id": 1485711646154388, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58710, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23134, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:39:49.345919+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58710, "dest_port": 53}}'); INSERT INTO alerts VALUES(2768,1773074390.458395004,'{"timestamp": "2026-03-09T17:39:50.458395+0100", "flow_id": 1968795635260919, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62212, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16168, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "edge-050.deber3.ce.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-09T17:39:50.458395+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62212, "dest_port": 53}}'); INSERT INTO alerts VALUES(2769,1773074399.378523112,'{"timestamp": "2026-03-09T17:39:59.378523+0100", "flow_id": 2188694311798295, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59340, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37003, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:39:59.378523+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59340, "dest_port": 53}}'); INSERT INTO alerts VALUES(2770,1773074408.848597049,'{"timestamp": "2026-03-09T17:40:08.848597+0100", "flow_id": 266997745592422, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56466, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:40:08.848597+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56466, "dest_port": 53}}'); INSERT INTO alerts VALUES(2771,1773074408.848597049,'{"timestamp": "2026-03-09T17:40:08.848597+0100", "flow_id": 266996705852443, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44047, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:40:08.848597+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61596, "dest_port": 53}}'); INSERT INTO alerts VALUES(2772,1773074410.23449111,'{"timestamp": "2026-03-09T17:40:10.234491+0100", "flow_id": 725660266442359, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50337, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24254, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:40:10.234491+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50337, "dest_port": 53}}'); INSERT INTO alerts VALUES(2773,1773074421.088645935,'{"timestamp": "2026-03-09T17:40:21.088646+0100", "flow_id": 1506633259404022, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52197, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24071, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:40:21.088646+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52197, "dest_port": 53}}'); INSERT INTO alerts VALUES(2774,1773074422.449809075,'{"timestamp": "2026-03-09T17:40:22.449809+0100", "flow_id": 1835443046848925, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 48484, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:40:22.427347+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 48484, "dest_port": 853}}'); INSERT INTO alerts VALUES(2775,1773074431.947809935,'{"timestamp": "2026-03-09T17:40:31.947810+0100", "flow_id": 2100489086167574, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63016, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23467, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:40:31.947810+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63016, "dest_port": 53}}'); INSERT INTO alerts VALUES(2776,1773074436.712845087,'{"timestamp": "2026-03-09T17:40:36.712845+0100", "flow_id": 1372798128223219, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55280, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:40:36.712845+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55280, "dest_port": 53}}'); INSERT INTO alerts VALUES(2777,1773074436.712846041,'{"timestamp": "2026-03-09T17:40:36.712846+0100", "flow_id": 1372803357819911, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60525, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59925, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:40:36.712846+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60525, "dest_port": 53}}'); INSERT INTO alerts VALUES(2778,1773074442.795718909,'{"timestamp": "2026-03-09T17:40:42.795719+0100", "flow_id": 602841601124225, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59951, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50105, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:40:42.795719+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59951, "dest_port": 53}}'); INSERT INTO alerts VALUES(2779,1773074449.23773098,'{"timestamp": "2026-03-09T17:40:49.237731+0100", "flow_id": 458098100935325, "event_type": "alert", "src_ip": "185.241.208.163", "src_port": 50251, "dest_ip": "134.19.55.199", "dest_port": 33900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:40:49.237731+0100", "src_ip": "185.241.208.163", "dest_ip": "134.19.55.199", "src_port": 50251, "dest_port": 33900}}'); INSERT INTO alerts VALUES(2780,1773074453.650563955,'{"timestamp": "2026-03-09T17:40:53.650564+0100", "flow_id": 1668254864827007, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58571, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53290, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:40:53.650564+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58571, "dest_port": 53}}'); INSERT INTO alerts VALUES(2781,1773074464.50643897,'{"timestamp": "2026-03-09T17:41:04.506439+0100", "flow_id": 204818105292520, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57951, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26661, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:41:04.506439+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57951, "dest_port": 53}}'); INSERT INTO alerts VALUES(2782,1773074475.970283986,'{"timestamp": "2026-03-09T17:41:15.970284+0100", "flow_id": 1071116374070737, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51274, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40659, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:41:15.970284+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51274, "dest_port": 53}}'); INSERT INTO alerts VALUES(2783,1773074486.836947918,'{"timestamp": "2026-03-09T17:41:26.836948+0100", "flow_id": 1905814708858193, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56403, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6872, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:41:26.836948+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56403, "dest_port": 53}}'); INSERT INTO alerts VALUES(2784,1773074495.439152956,'{"timestamp": "2026-03-09T17:41:35.439153+0100", "flow_id": 2167626370412191, "event_type": "alert", "src_ip": "167.94.146.78", "src_port": 20936, "dest_ip": "134.19.55.199", "dest_port": 708, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:41:35.439153+0100", "src_ip": "167.94.146.78", "dest_ip": "134.19.55.199", "src_port": 20936, "dest_port": 708}}'); INSERT INTO alerts VALUES(2785,1773074497.694269896,'{"timestamp": "2026-03-09T17:41:37.694270+0100", "flow_id": 448596445956202, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55409, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60177, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:41:37.694270+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55409, "dest_port": 53}}'); INSERT INTO alerts VALUES(2786,1773074499.437865018,'{"timestamp": "2026-03-09T17:41:39.437865+0100", "flow_id": 1036192951301107, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55280, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:41:39.437865+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55280, "dest_port": 53}}'); INSERT INTO alerts VALUES(2787,1773074499.437865018,'{"timestamp": "2026-03-09T17:41:39.437865+0100", "flow_id": 1036193885930503, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60525, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59925, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:41:39.437865+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60525, "dest_port": 53}}'); INSERT INTO alerts VALUES(2788,1773074507.821579934,'{"timestamp": "2026-03-09T17:41:47.821580+0100", "flow_id": 995385544288358, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56466, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:41:47.821580+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56466, "dest_port": 53}}'); INSERT INTO alerts VALUES(2789,1773074507.821579934,'{"timestamp": "2026-03-09T17:41:47.821580+0100", "flow_id": 995384504548379, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44047, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:41:47.821580+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61596, "dest_port": 53}}'); INSERT INTO alerts VALUES(2790,1773074508.552793979,'{"timestamp": "2026-03-09T17:41:48.552794+0100", "flow_id": 1248332255952877, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52423, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21125, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:41:48.552794+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52423, "dest_port": 53}}'); INSERT INTO alerts VALUES(2791,1773074519.394364119,'{"timestamp": "2026-03-09T17:41:59.394364+0100", "flow_id": 1975259661769034, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57411, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34707, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:41:59.394364+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57411, "dest_port": 53}}'); INSERT INTO alerts VALUES(2792,1773074529.423650027,'{"timestamp": "2026-03-09T17:42:09.423650+0100", "flow_id": 412188771683978, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55081, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27370, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:42:09.423650+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55081, "dest_port": 53}}'); INSERT INTO alerts VALUES(2793,1773074534.905599118,'{"timestamp": "2026-03-09T17:42:14.905599+0100", "flow_id": 1919194456778429, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 47461, "dest_ip": "134.19.55.199", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:42:14.905599+0100", "src_ip": "87.121.84.57", "dest_ip": "134.19.55.199", "src_port": 47461, "dest_port": 8888}}'); INSERT INTO alerts VALUES(2794,1773074539.125233889,'{"timestamp": "2026-03-09T17:42:19.125234+0100", "flow_id": 1100826991405158, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56466, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:42:19.125234+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56466, "dest_port": 53}}'); INSERT INTO alerts VALUES(2795,1773074539.125233889,'{"timestamp": "2026-03-09T17:42:19.125234+0100", "flow_id": 1100825951665179, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44047, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:42:19.125234+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61596, "dest_port": 53}}'); INSERT INTO alerts VALUES(2796,1773074542.456368923,'{"timestamp": "2026-03-09T17:42:22.456369+0100", "flow_id": 1865711328052269, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 35764, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:42:22.434394+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 35764, "dest_port": 853}}'); INSERT INTO alerts VALUES(2797,1773074544.991200924,'{"timestamp": "2026-03-09T17:42:24.991201+0100", "flow_id": 35055468229100, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58093, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19153, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:42:24.991201+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58093, "dest_port": 53}}'); INSERT INTO alerts VALUES(2798,1773074555.648643017,'{"timestamp": "2026-03-09T17:42:35.648643+0100", "flow_id": 1097054811904388, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56441, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15050, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:42:35.648643+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56441, "dest_port": 53}}'); INSERT INTO alerts VALUES(2799,1773074561.882350921,'{"timestamp": "2026-03-09T17:42:41.882351+0100", "flow_id": 411973190113269, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63486, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15960, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:42:41.882351+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63486, "dest_port": 53}}'); INSERT INTO alerts VALUES(2800,1773074561.884396076,'{"timestamp": "2026-03-09T17:42:41.884396+0100", "flow_id": 420755132188407, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62593, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40715, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:42:41.884396+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62593, "dest_port": 53}}'); INSERT INTO alerts VALUES(2801,1773074562.125678063,'{"timestamp": "2026-03-09T17:42:42.125678+0100", "flow_id": 821261009228619, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58490, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60356, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T17:42:42.125678+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58490, "dest_port": 53}}'); INSERT INTO alerts VALUES(2802,1773074566.498648881,'{"timestamp": "2026-03-09T17:42:46.498649+0100", "flow_id": 1860209821692819, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49704, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30413, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:42:46.498649+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49704, "dest_port": 53}}'); INSERT INTO alerts VALUES(2803,1773074567.586690902,'{"timestamp": "2026-03-09T17:42:47.586691+0100", "flow_id": 2238346285222782, "event_type": "alert", "src_ip": "167.94.138.106", "src_port": 34334, "dest_ip": "134.19.55.199", "dest_port": 53709, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:42:47.586691+0100", "src_ip": "167.94.138.106", "dest_ip": "134.19.55.199", "src_port": 34334, "dest_port": 53709}}'); INSERT INTO alerts VALUES(2804,1773074569.839286088,'{"timestamp": "2026-03-09T17:42:49.839286+0100", "flow_id": 508482281810022, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56466, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:42:49.839286+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56466, "dest_port": 53}}'); INSERT INTO alerts VALUES(2805,1773074569.839286088,'{"timestamp": "2026-03-09T17:42:49.839286+0100", "flow_id": 508481242070043, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44047, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:42:49.839286+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61596, "dest_port": 53}}'); INSERT INTO alerts VALUES(2806,1773074577.34948492,'{"timestamp": "2026-03-09T17:42:57.349485+0100", "flow_id": 375128577573355, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55793, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24779, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:42:57.349485+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55793, "dest_port": 53}}'); INSERT INTO alerts VALUES(2807,1773074583.016592026,'{"timestamp": "2026-03-09T17:43:03.016592+0100", "flow_id": 2041589676045612, "event_type": "alert", "src_ip": "64.89.163.141", "src_port": 54489, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:43:03.016592+0100", "src_ip": "64.89.163.141", "dest_ip": "134.19.55.199", "src_port": 54489, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2808,1773074583.016592026,'{"timestamp": "2026-03-09T17:43:03.016592+0100", "flow_id": 2041589676045612, "event_type": "alert", "src_ip": "64.89.163.141", "src_port": 54489, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:43:03.016592+0100", "src_ip": "64.89.163.141", "dest_ip": "134.19.55.199", "src_port": 54489, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2809,1773074588.200092078,'{"timestamp": "2026-03-09T17:43:08.200092+0100", "flow_id": 1140866805493326, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58283, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55291, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:43:08.200092+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58283, "dest_port": 53}}'); INSERT INTO alerts VALUES(2810,1773074599.668752908,'{"timestamp": "2026-03-09T17:43:19.668753+0100", "flow_id": 2027849712326802, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49652, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46394, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:43:19.668753+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49652, "dest_port": 53}}'); INSERT INTO alerts VALUES(2811,1773074600.385437011,'{"timestamp": "2026-03-09T17:43:20.385437+0100", "flow_id": 248065529751654, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56466, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:43:20.385437+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56466, "dest_port": 53}}'); INSERT INTO alerts VALUES(2812,1773074600.385437965,'{"timestamp": "2026-03-09T17:43:20.385438+0100", "flow_id": 248068784978971, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44047, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:43:20.385438+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61596, "dest_port": 53}}'); INSERT INTO alerts VALUES(2813,1773074610.534681082,'{"timestamp": "2026-03-09T17:43:30.534681+0100", "flow_id": 607588661704088, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53081, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9560, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:43:30.534681+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53081, "dest_port": 53}}'); INSERT INTO alerts VALUES(2814,1773074621.388371945,'{"timestamp": "2026-03-09T17:43:41.388372+0100", "flow_id": 1668049140194074, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60169, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59760, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:43:41.388372+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60169, "dest_port": 53}}'); INSERT INTO alerts VALUES(2815,1773074631.125442982,'{"timestamp": "2026-03-09T17:43:51.125443+0100", "flow_id": 2227624546412646, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56466, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:43:51.125443+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56466, "dest_port": 53}}'); INSERT INTO alerts VALUES(2816,1773074631.125443935,'{"timestamp": "2026-03-09T17:43:51.125444+0100", "flow_id": 2227627801639963, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44047, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:43:51.125444+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61596, "dest_port": 53}}'); INSERT INTO alerts VALUES(2817,1773074632.854562045,'{"timestamp": "2026-03-09T17:43:52.854562+0100", "flow_id": 11143220667287, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49433, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15752, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:43:52.854562+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49433, "dest_port": 53}}'); INSERT INTO alerts VALUES(2818,1773074643.704647065,'{"timestamp": "2026-03-09T17:44:03.704647+0100", "flow_id": 1056113236156631, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63109, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31088, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:44:03.704647+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63109, "dest_port": 53}}'); INSERT INTO alerts VALUES(2819,1773074649.45378089,'{"timestamp": "2026-03-09T17:44:09.453781+0100", "flow_id": 541601858660079, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51280, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53929, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:44:09.453781+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51280, "dest_port": 53}}'); INSERT INTO alerts VALUES(2820,1773074654.56440711,'{"timestamp": "2026-03-09T17:44:14.564407+0100", "flow_id": 1861162369646220, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60668, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:44:14.564407+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61876, "dest_port": 53}}'); INSERT INTO alerts VALUES(2821,1773074662.461941958,'{"timestamp": "2026-03-09T17:44:22.461942+0100", "flow_id": 1887451811417207, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 49982, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:44:22.439456+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 49982, "dest_port": 853}}'); INSERT INTO alerts VALUES(2822,1773074665.431145907,'{"timestamp": "2026-03-09T17:44:25.431146+0100", "flow_id": 444384392782419, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57371, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63617, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:44:25.431146+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57371, "dest_port": 53}}'); INSERT INTO alerts VALUES(2823,1773074676.268508912,'{"timestamp": "2026-03-09T17:44:36.268509+0100", "flow_id": 1153238008937079, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52225, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35796, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:44:36.268509+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52225, "dest_port": 53}}'); INSERT INTO alerts VALUES(2824,1773074687.953704119,'{"timestamp": "2026-03-09T17:44:47.953704+0100", "flow_id": 2125806544375876, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49741, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11927, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:44:47.953704+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49741, "dest_port": 53}}'); INSERT INTO alerts VALUES(2825,1773074689.40145111,'{"timestamp": "2026-03-09T17:44:49.401451+0100", "flow_id": 316847273342546, "event_type": "alert", "src_ip": "185.242.226.60", "src_port": 33822, "dest_ip": "134.19.55.199", "dest_port": 8015, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:44:49.401451+0100", "src_ip": "185.242.226.60", "dest_ip": "134.19.55.199", "src_port": 33822, "dest_port": 8015}}'); INSERT INTO alerts VALUES(2826,1773074695.598828077,'{"timestamp": "2026-03-09T17:44:55.598828+0100", "flow_id": 2008997826144358, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56466, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:44:55.598828+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56466, "dest_port": 53}}'); INSERT INTO alerts VALUES(2827,1773074695.598829031,'{"timestamp": "2026-03-09T17:44:55.598829+0100", "flow_id": 2009001081371675, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44047, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:44:55.598829+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61596, "dest_port": 53}}'); INSERT INTO alerts VALUES(2828,1773074698.806384087,'{"timestamp": "2026-03-09T17:44:58.806384+0100", "flow_id": 648647019529911, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62580, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58375, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:44:58.806384+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62580, "dest_port": 53}}'); INSERT INTO alerts VALUES(2829,1773074699.489149094,'{"timestamp": "2026-03-09T17:44:59.489149+0100", "flow_id": 974981444509348, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 52607, "dest_ip": "134.19.55.199", "dest_port": 54015, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:44:59.489149+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 52607, "dest_port": 54015}}'); INSERT INTO alerts VALUES(2830,1773074724.806771993,'{"timestamp": "2026-03-09T17:45:24.806772+0100", "flow_id": 1213260368510918, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49786, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2198, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:45:24.806772+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49786, "dest_port": 53}}'); INSERT INTO alerts VALUES(2831,1773074726.979691983,'{"timestamp": "2026-03-09T17:45:26.979692+0100", "flow_id": 1955946390104166, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56466, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:45:26.979692+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56466, "dest_port": 53}}'); INSERT INTO alerts VALUES(2832,1773074726.979692936,'{"timestamp": "2026-03-09T17:45:26.979693+0100", "flow_id": 1955949645331483, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44047, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:45:26.979693+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61596, "dest_port": 53}}'); INSERT INTO alerts VALUES(2833,1773074735.678600073,'{"timestamp": "2026-03-09T17:45:35.678600+0100", "flow_id": 2070142885522194, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62578, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36687, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:45:35.678600+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62578, "dest_port": 53}}'); INSERT INTO alerts VALUES(2834,1773074746.527776957,'{"timestamp": "2026-03-09T17:45:46.527777+0100", "flow_id": 577937164183886, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57366, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56584, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:45:46.527777+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57366, "dest_port": 53}}'); INSERT INTO alerts VALUES(2835,1773074757.377055884,'{"timestamp": "2026-03-09T17:45:57.377056+0100", "flow_id": 1619444129536126, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61589, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15726, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:45:57.377056+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61589, "dest_port": 53}}'); INSERT INTO alerts VALUES(2836,1773074766.299400092,'{"timestamp": "2026-03-09T17:46:06.299400+0100", "flow_id": 1848865213460818, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:46:06.299400+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2837,1773074768.242211103,'{"timestamp": "2026-03-09T17:46:08.242211+0100", "flow_id": 195867466020069, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56352, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52846, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:46:08.242211+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56352, "dest_port": 53}}'); INSERT INTO alerts VALUES(2838,1773074774.984782934,'{"timestamp": "2026-03-09T17:46:14.984783+0100", "flow_id": 1696338719299006, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53149, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8658, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:46:14.984783+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53149, "dest_port": 53}}'); INSERT INTO alerts VALUES(2839,1773074793.008162022,'{"timestamp": "2026-03-09T17:46:33.008162+0100", "flow_id": 316531599745640, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60409, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25674, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:46:33.008162+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60409, "dest_port": 53}}'); INSERT INTO alerts VALUES(2840,1773074797.077614069,'{"timestamp": "2026-03-09T17:46:37.077614+0100", "flow_id": 1459252134911574, "event_type": "alert", "src_ip": "185.242.226.68", "src_port": 55559, "dest_ip": "134.19.55.199", "dest_port": 7681, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-09T17:46:37.077614+0100", "src_ip": "185.242.226.68", "dest_ip": "134.19.55.199", "src_port": 55559, "dest_port": 7681}}'); INSERT INTO alerts VALUES(2841,1773074803.85878706,'{"timestamp": "2026-03-09T17:46:43.858787+0100", "flow_id": 873714834610573, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59104, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28335, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:46:43.858787+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59104, "dest_port": 53}}'); INSERT INTO alerts VALUES(2842,1773074813.69598198,'{"timestamp": "2026-03-09T17:46:53.695982+0100", "flow_id": 1581846148687974, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56466, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:46:53.695982+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56466, "dest_port": 53}}'); INSERT INTO alerts VALUES(2843,1773074813.69598198,'{"timestamp": "2026-03-09T17:46:53.695982+0100", "flow_id": 1581845108947995, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44047, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:46:53.695982+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61596, "dest_port": 53}}'); INSERT INTO alerts VALUES(2844,1773074813.69598198,'{"timestamp": "2026-03-09T17:46:53.695982+0100", "flow_id": 1581849146147202, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50637, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43442, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:46:53.695982+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50637, "dest_port": 53}}'); INSERT INTO alerts VALUES(2845,1773074813.695982933,'{"timestamp": "2026-03-09T17:46:53.695983+0100", "flow_id": 1581850776853088, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51654, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18589, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:46:53.695983+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51654, "dest_port": 53}}'); INSERT INTO alerts VALUES(2846,1773074814.731967927,'{"timestamp": "2026-03-09T17:46:54.731968+0100", "flow_id": 1736406758451475, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63337, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56261, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:46:54.731968+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63337, "dest_port": 53}}'); INSERT INTO alerts VALUES(2847,1773074825.571683883,'{"timestamp": "2026-03-09T17:47:05.571684+0100", "flow_id": 485042444525396, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54936, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26087, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:47:05.571684+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54936, "dest_port": 53}}'); INSERT INTO alerts VALUES(2848,1773074829.016359091,'{"timestamp": "2026-03-09T17:47:09.016359+0100", "flow_id": 1477638305165650, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:47:09.016359+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2849,1773074836.412565947,'{"timestamp": "2026-03-09T17:47:16.412566+0100", "flow_id": 1209011787704203, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64966, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15712, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:47:16.412566+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64966, "dest_port": 53}}'); INSERT INTO alerts VALUES(2850,1773074847.080007077,'{"timestamp": "2026-03-09T17:47:27.080007+0100", "flow_id": 2032481340386905, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59508, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14900, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:47:27.080007+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59508, "dest_port": 53}}'); INSERT INTO alerts VALUES(2851,1773074857.937203885,'{"timestamp": "2026-03-09T17:47:37.937204+0100", "flow_id": 366088449562032, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55132, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34388, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:47:37.937204+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55132, "dest_port": 53}}'); INSERT INTO alerts VALUES(2852,1773074860.505141019,'{"timestamp": "2026-03-09T17:47:40.505141+0100", "flow_id": 1325141196353874, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:47:40.505141+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2853,1773074866.952805043,'{"timestamp": "2026-03-09T17:47:46.952805+0100", "flow_id": 714566691909676, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 28000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:47:46.952805+0100", "src_ip": "88.210.63.69", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 28000}}'); INSERT INTO alerts VALUES(2854,1773074868.779346943,'{"timestamp": "2026-03-09T17:47:48.779347+0100", "flow_id": 1376949016295156, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57421, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3674, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:47:48.779347+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57421, "dest_port": 53}}'); INSERT INTO alerts VALUES(2855,1773074869.540375948,'{"timestamp": "2026-03-09T17:47:49.540376+0100", "flow_id": 1476473972888143, "event_type": "alert", "src_ip": "91.196.152.185", "src_port": 58192, "dest_ip": "134.19.55.199", "dest_port": 20135, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:47:49.540376+0100", "src_ip": "91.196.152.185", "dest_ip": "134.19.55.199", "src_port": 58192, "dest_port": 20135}}'); INSERT INTO alerts VALUES(2856,1773074879.444412946,'{"timestamp": "2026-03-09T17:47:59.444413+0100", "flow_id": 2190216031163527, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59524, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9323, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:47:59.444413+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59524, "dest_port": 53}}'); INSERT INTO alerts VALUES(2857,1773074880.472263098,'{"timestamp": "2026-03-09T17:48:00.472263+0100", "flow_id": 58030092592384, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 51893, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:48:00.472263+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 51893, "dest_port": 3389}}'); INSERT INTO alerts VALUES(2858,1773074890.291207076,'{"timestamp": "2026-03-09T17:48:10.291207+0100", "flow_id": 687774950836601, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58768, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37124, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:10.291207+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58768, "dest_port": 53}}'); INSERT INTO alerts VALUES(2859,1773074891.456667901,'{"timestamp": "2026-03-09T17:48:11.456668+0100", "flow_id": 1116951246614866, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:11.456668+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2860,1773074901.131392002,'{"timestamp": "2026-03-09T17:48:21.131392+0100", "flow_id": 1408752662975570, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:21.131392+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2861,1773074902.218698979,'{"timestamp": "2026-03-09T17:48:22.218699+0100", "flow_id": 1783731180969838, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:48:22.218699+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2862,1773074902.219002962,'{"timestamp": "2026-03-09T17:48:22.219003+0100", "flow_id": 1785039941956650, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:48:22.219003+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2863,1773074912.542102098,'{"timestamp": "2026-03-09T17:48:32.542102+0100", "flow_id": 76514046028576, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60413, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5977, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:32.542102+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60413, "dest_port": 53}}'); INSERT INTO alerts VALUES(2864,1773074912.662844897,'{"timestamp": "2026-03-09T17:48:32.662845+0100", "flow_id": 32151931306370, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50637, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43442, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:32.662845+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50637, "dest_port": 53}}'); INSERT INTO alerts VALUES(2865,1773074912.662846089,'{"timestamp": "2026-03-09T17:48:32.662846+0100", "flow_id": 32153562012256, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51654, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18589, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:32.662846+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51654, "dest_port": 53}}'); INSERT INTO alerts VALUES(2866,1773074912.662846089,'{"timestamp": "2026-03-09T17:48:32.662846+0100", "flow_id": 32153912449739, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60471, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28237, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:32.662846+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60471, "dest_port": 53}}'); INSERT INTO alerts VALUES(2867,1773074912.662846089,'{"timestamp": "2026-03-09T17:48:32.662846+0100", "flow_id": 32152938250038, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56575, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41528, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:32.662846+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56575, "dest_port": 53}}'); INSERT INTO alerts VALUES(2868,1773074922.802814006,'{"timestamp": "2026-03-09T17:48:42.802814+0100", "flow_id": 633312159281490, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:42.802814+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2869,1773074924.593101025,'{"timestamp": "2026-03-09T17:48:44.593101+0100", "flow_id": 1139975535913680, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50827, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65533, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:44.593101+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50827, "dest_port": 53}}'); INSERT INTO alerts VALUES(2870,1773074924.593101979,'{"timestamp": "2026-03-09T17:48:44.593102+0100", "flow_id": 1139978895688143, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57586, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32259, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:44.593102+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57586, "dest_port": 53}}'); INSERT INTO alerts VALUES(2871,1773074939.461779118,'{"timestamp": "2026-03-09T17:48:59.461779+0100", "flow_id": 857427177262452, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51083, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13830, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:59.461779+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51083, "dest_port": 53}}'); INSERT INTO alerts VALUES(2872,1773074939.461780071,'{"timestamp": "2026-03-09T17:48:59.461780+0100", "flow_id": 857432198212773, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52891, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54526, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:48:59.461780+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52891, "dest_port": 53}}'); INSERT INTO alerts VALUES(2873,1773074943.803116083,'{"timestamp": "2026-03-09T17:49:03.803116+0100", "flow_id": 2041983570041781, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50676, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9081, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:49:03.803116+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50676, "dest_port": 53}}'); INSERT INTO alerts VALUES(2874,1773074945.186053991,'{"timestamp": "2026-03-09T17:49:05.186054+0100", "flow_id": 517622019691052, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57172, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6785, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:49:05.186054+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57172, "dest_port": 53}}'); INSERT INTO alerts VALUES(2875,1773074948.984421015,'{"timestamp": "2026-03-09T17:49:08.984421+0100", "flow_id": 1131832962909794, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51583, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23624, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:49:08.984421+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51583, "dest_port": 53}}'); INSERT INTO alerts VALUES(2876,1773074948.984421015,'{"timestamp": "2026-03-09T17:49:08.984421+0100", "flow_id": 1131835414517786, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65535, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53689, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:49:08.984421+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65535, "dest_port": 53}}'); INSERT INTO alerts VALUES(2877,1773074953.330977916,'{"timestamp": "2026-03-09T17:49:13.330978+0100", "flow_id": 295641830469970, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:49:13.330978+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2878,1773074964.354927063,'{"timestamp": "2026-03-09T17:49:24.354927+0100", "flow_id": 1242928270644306, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:49:24.354927+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2879,1773074964.612706899,'{"timestamp": "2026-03-09T17:49:24.612707+0100", "flow_id": 1224182734747475, "event_type": "alert", "src_ip": "198.235.24.55", "src_port": 54541, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:49:24.612707+0100", "src_ip": "198.235.24.55", "dest_ip": "134.19.55.199", "src_port": 54541, "dest_port": 22}}'); INSERT INTO alerts VALUES(2880,1773074965.832806111,'{"timestamp": "2026-03-09T17:49:25.832806+0100", "flow_id": 1606550895107950, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:49:25.832806+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2881,1773074965.832806111,'{"timestamp": "2026-03-09T17:49:25.832806+0100", "flow_id": 1606553986036778, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:49:25.832806+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2882,1773074972.503479958,'{"timestamp": "2026-03-09T17:49:32.503480+0100", "flow_id": 1318007898323979, "event_type": "alert", "src_ip": "91.196.152.33", "src_port": 7408, "dest_ip": "134.19.55.199", "dest_port": 20082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:49:32.503480+0100", "src_ip": "91.196.152.33", "dest_ip": "134.19.55.199", "src_port": 7408, "dest_port": 20082}}'); INSERT INTO alerts VALUES(2883,1773074979.998439074,'{"timestamp": "2026-03-09T17:49:39.998439+0100", "flow_id": 910565404733932, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49811, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60615, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:49:39.998439+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49811, "dest_port": 53}}'); INSERT INTO alerts VALUES(2884,1773074984.595046044,'{"timestamp": "2026-03-09T17:49:44.595046+0100", "flow_id": 22428896661250, "event_type": "alert", "src_ip": "195.184.76.137", "src_port": 37020, "dest_ip": "134.19.55.199", "dest_port": 6510, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:49:44.595046+0100", "src_ip": "195.184.76.137", "dest_ip": "134.19.55.199", "src_port": 37020, "dest_port": 6510}}'); INSERT INTO alerts VALUES(2885,1773074984.75364995,'{"timestamp": "2026-03-09T17:49:44.753650+0100", "flow_id": 140679410430290, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:49:44.753650+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2886,1773074994.370688916,'{"timestamp": "2026-03-09T17:49:54.370689+0100", "flow_id": 747675591742546, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:49:54.370689+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2887,1773074996.276002883,'{"timestamp": "2026-03-09T17:49:56.276003+0100", "flow_id": 1185425056767854, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:49:56.276003+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2888,1773074996.276004077,'{"timestamp": "2026-03-09T17:49:56.276004+0100", "flow_id": 1185432442663978, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:49:56.276004+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2889,1773075001.144399881,'{"timestamp": "2026-03-09T17:50:01.144400+0100", "flow_id": 338722463405491, "event_type": "alert", "src_ip": "195.184.76.169", "src_port": 12513, "dest_ip": "134.19.55.199", "dest_port": 6200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:50:01.144400+0100", "src_ip": "195.184.76.169", "dest_ip": "134.19.55.199", "src_port": 12513, "dest_port": 6200}}'); INSERT INTO alerts VALUES(2890,1773075006.635648012,'{"timestamp": "2026-03-09T17:50:06.635648+0100", "flow_id": 1885664617710834, "event_type": "alert", "src_ip": "195.184.76.161", "src_port": 56115, "dest_ip": "134.19.55.199", "dest_port": 6072, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:50:06.635648+0100", "src_ip": "195.184.76.161", "dest_ip": "134.19.55.199", "src_port": 56115, "dest_port": 6072}}'); INSERT INTO alerts VALUES(2891,1773075010.722290992,'{"timestamp": "2026-03-09T17:50:10.722291+0100", "flow_id": 568943831741486, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52099, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62418, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:50:10.722291+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52099, "dest_port": 53}}'); INSERT INTO alerts VALUES(2892,1773075010.722291947,'{"timestamp": "2026-03-09T17:50:10.722292+0100", "flow_id": 568949332012964, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52062, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41819, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:50:10.722292+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52062, "dest_port": 53}}'); INSERT INTO alerts VALUES(2893,1773075015.493911028,'{"timestamp": "2026-03-09T17:50:15.493911+0100", "flow_id": 2121333643751762, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:50:15.493911+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2894,1773075017.249469041,'{"timestamp": "2026-03-09T17:50:17.249469+0100", "flow_id": 508514032488616, "event_type": "alert", "src_ip": "91.196.152.177", "src_port": 39818, "dest_ip": "134.19.55.199", "dest_port": 2142, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:50:17.249469+0100", "src_ip": "91.196.152.177", "dest_ip": "134.19.55.199", "src_port": 39818, "dest_port": 2142}}'); INSERT INTO alerts VALUES(2895,1773075024.4916749,'{"timestamp": "2026-03-09T17:50:24.491675+0100", "flow_id": 141406598173778, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:50:24.491675+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2896,1773075026.278301,'{"timestamp": "2026-03-09T17:50:26.278301+0100", "flow_id": 632344938192750, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:50:26.278301+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2897,1773075026.278301954,'{"timestamp": "2026-03-09T17:50:26.278302+0100", "flow_id": 632352324088874, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:50:26.278302+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2898,1773075036.678042888,'{"timestamp": "2026-03-09T17:50:36.678043+0100", "flow_id": 1223325261020245, "event_type": "alert", "src_ip": "195.184.76.113", "src_port": 57179, "dest_ip": "134.19.55.199", "dest_port": 60002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:50:36.678043+0100", "src_ip": "195.184.76.113", "dest_ip": "134.19.55.199", "src_port": 57179, "dest_port": 60002}}'); INSERT INTO alerts VALUES(2899,1773075046.366993905,'{"timestamp": "2026-03-09T17:50:46.366994+0100", "flow_id": 1857704256155986, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:50:46.366994+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2900,1773075055.753711938,'{"timestamp": "2026-03-09T17:50:55.753712+0100", "flow_id": 2111271873647698, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:50:55.753712+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2901,1773075057.673937083,'{"timestamp": "2026-03-09T17:50:57.673937+0100", "flow_id": 361263782338414, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:50:57.673937+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2902,1773075057.673937083,'{"timestamp": "2026-03-09T17:50:57.673937+0100", "flow_id": 361266873267242, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:50:57.673937+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2903,1773075076.656503915,'{"timestamp": "2026-03-09T17:51:16.656504+0100", "flow_id": 1130815401046354, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:51:16.656504+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2904,1773075081.363954068,'{"timestamp": "2026-03-09T17:51:21.363954+0100", "flow_id": 437271862020274, "event_type": "alert", "src_ip": "195.184.76.33", "src_port": 44192, "dest_ip": "134.19.55.199", "dest_port": 7003, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:51:21.363954+0100", "src_ip": "195.184.76.33", "dest_ip": "134.19.55.199", "src_port": 44192, "dest_port": 7003}}'); INSERT INTO alerts VALUES(2905,1773075087.159425021,'{"timestamp": "2026-03-09T17:51:27.159425+0100", "flow_id": 2092103434605650, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:51:27.159425+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2906,1773075087.772507905,'{"timestamp": "2026-03-09T17:51:27.772508+0100", "flow_id": 2191997887225710, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:51:27.772508+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2907,1773075087.772507905,'{"timestamp": "2026-03-09T17:51:27.772508+0100", "flow_id": 2192000978154538, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:51:27.772508+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2908,1773075107.728693008,'{"timestamp": "2026-03-09T17:51:47.728693+0100", "flow_id": 877914841755986, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:51:47.728693+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2909,1773075116.839293956,'{"timestamp": "2026-03-09T17:51:56.839294+0100", "flow_id": 1262481615720962, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 48486, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:51:56.818232+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 48486, "dest_port": 853}}'); INSERT INTO alerts VALUES(2910,1773075116.848582983,'{"timestamp": "2026-03-09T17:51:56.848583+0100", "flow_id": 1300569453375739, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 56496, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T17:51:56.827100+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 56496, "dest_port": 853}}'); INSERT INTO alerts VALUES(2911,1773075118.179871082,'{"timestamp": "2026-03-09T17:51:58.179871+0100", "flow_id": 1898443359229010, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:51:58.179871+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2912,1773075118.180736064,'{"timestamp": "2026-03-09T17:51:58.180736+0100", "flow_id": 1902156314222446, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:51:58.180736+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2913,1773075118.181003093,'{"timestamp": "2026-03-09T17:51:58.181003+0100", "flow_id": 1903306161419306, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:51:58.181003+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2914,1773075121.953135014,'{"timestamp": "2026-03-09T17:52:01.953135+0100", "flow_id": 434510051733264, "event_type": "alert", "src_ip": "195.184.76.129", "src_port": 27209, "dest_ip": "134.19.55.199", "dest_port": 8005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:52:01.953135+0100", "src_ip": "195.184.76.129", "dest_ip": "134.19.55.199", "src_port": 27209, "dest_port": 8005}}'); INSERT INTO alerts VALUES(2915,1773075138.667990923,'{"timestamp": "2026-03-09T17:52:18.667991+0100", "flow_id": 617201736954194, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:52:18.667991+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2916,1773075143.961345911,'{"timestamp": "2026-03-09T17:52:23.961346+0100", "flow_id": 2158627652082901, "event_type": "alert", "src_ip": "46.151.182.162", "src_port": 54967, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:52:23.961346+0100", "src_ip": "46.151.182.162", "dest_ip": "134.19.55.199", "src_port": 54967, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2917,1773075143.961345911,'{"timestamp": "2026-03-09T17:52:23.961346+0100", "flow_id": 2158627652082901, "event_type": "alert", "src_ip": "46.151.182.162", "src_port": 54967, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:52:23.961346+0100", "src_ip": "46.151.182.162", "dest_ip": "134.19.55.199", "src_port": 54967, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2918,1773075148.285329104,'{"timestamp": "2026-03-09T17:52:28.285329+0100", "flow_id": 1225482113487954, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:52:28.285329+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2919,1773075148.285330058,'{"timestamp": "2026-03-09T17:52:28.285330+0100", "flow_id": 1225484216737646, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:52:28.285330+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2920,1773075148.285330058,'{"timestamp": "2026-03-09T17:52:28.285330+0100", "flow_id": 1225487307666474, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:52:28.285330+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2921,1773075178.920713902,'{"timestamp": "2026-03-09T17:52:58.920714+0100", "flow_id": 576740188329042, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:52:58.920714+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2922,1773075178.921340942,'{"timestamp": "2026-03-09T17:52:58.921341+0100", "flow_id": 579430941106030, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:52:58.921341+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2923,1773075178.921341897,'{"timestamp": "2026-03-09T17:52:58.921342+0100", "flow_id": 579438327002154, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:52:58.921342+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2924,1773075193.891438961,'{"timestamp": "2026-03-09T17:53:13.891439+0100", "flow_id": 451004683540204, "event_type": "alert", "src_ip": "205.210.31.42", "src_port": 54976, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:53:13.891439+0100", "src_ip": "205.210.31.42", "dest_ip": "134.19.55.199", "src_port": 54976, "dest_port": 5060}}'); INSERT INTO alerts VALUES(2925,1773075200.727431059,'{"timestamp": "2026-03-09T17:53:20.727431+0100", "flow_id": 28068992404852, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51083, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13830, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:53:20.727431+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51083, "dest_port": 53}}'); INSERT INTO alerts VALUES(2926,1773075202.886851072,'{"timestamp": "2026-03-09T17:53:22.886851+0100", "flow_id": 712773349224786, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:53:22.886851+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2927,1773075209.327246904,'{"timestamp": "2026-03-09T17:53:29.327247+0100", "flow_id": 561093622469714, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:53:29.327247+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2928,1773075209.327248097,'{"timestamp": "2026-03-09T17:53:29.327248+0100", "flow_id": 561095725719406, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:53:29.327248+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2929,1773075209.327248097,'{"timestamp": "2026-03-09T17:53:29.327248+0100", "flow_id": 561098816648234, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:53:29.327248+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2930,1773075214.579284907,'{"timestamp": "2026-03-09T17:53:34.579285+0100", "flow_id": 1925061337122983, "event_type": "alert", "src_ip": "193.163.125.205", "src_port": 43333, "dest_ip": "134.19.55.199", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:53:34.579285+0100", "src_ip": "193.163.125.205", "dest_ip": "134.19.55.199", "src_port": 43333, "dest_port": 1521}}'); INSERT INTO alerts VALUES(2931,1773075214.579284907,'{"timestamp": "2026-03-09T17:53:34.579285+0100", "flow_id": 1925061337122983, "event_type": "alert", "src_ip": "193.163.125.205", "src_port": 43333, "dest_ip": "134.19.55.199", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:53:34.579285+0100", "src_ip": "193.163.125.205", "dest_ip": "134.19.55.199", "src_port": 43333, "dest_port": 1521}}'); INSERT INTO alerts VALUES(2932,1773075233.523936987,'{"timestamp": "2026-03-09T17:53:53.523937+0100", "flow_id": 561444471517522, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:53:53.523937+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2933,1773075240.588212013,'{"timestamp": "2026-03-09T17:54:00.588212+0100", "flow_id": 274554879317074, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:54:00.588212+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2934,1773075240.588212013,'{"timestamp": "2026-03-09T17:54:00.588212+0100", "flow_id": 274552687599470, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:54:00.588212+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2935,1773075240.588212013,'{"timestamp": "2026-03-09T17:54:00.588212+0100", "flow_id": 274555778528298, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:54:00.588212+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2936,1773075242.249891997,'{"timestamp": "2026-03-09T17:54:02.249892+0100", "flow_id": 791805937216199, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61378, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53808, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:54:02.249892+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61378, "dest_port": 53}}'); INSERT INTO alerts VALUES(2937,1773075259.238897086,'{"timestamp": "2026-03-09T17:54:19.238897+0100", "flow_id": 1026057793480621, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65322, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55434, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:54:19.238897+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65322, "dest_port": 53}}'); INSERT INTO alerts VALUES(2938,1773075259.239343881,'{"timestamp": "2026-03-09T17:54:19.239344+0100", "flow_id": 1027976570442759, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59284, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14541, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:54:19.239344+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59284, "dest_port": 53}}'); INSERT INTO alerts VALUES(2939,1773075260.066421986,'{"timestamp": "2026-03-09T17:54:20.066422+0100", "flow_id": 1129706233306231, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56925, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37291, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:54:20.066422+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56925, "dest_port": 53}}'); INSERT INTO alerts VALUES(2940,1773075263.783632993,'{"timestamp": "2026-03-09T17:54:23.783633+0100", "flow_id": 2239780251840850, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:54:23.783633+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2941,1773075271.752883912,'{"timestamp": "2026-03-09T17:54:31.752884+0100", "flow_id": 2107715640726610, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:54:31.752884+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2942,1773075271.752885103,'{"timestamp": "2026-03-09T17:54:31.752885+0100", "flow_id": 2107717743976302, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:54:31.752885+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2943,1773075271.753186941,'{"timestamp": "2026-03-09T17:54:31.753187+0100", "flow_id": 2109017915028522, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:54:31.753187+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2944,1773075276.912864924,'{"timestamp": "2026-03-09T17:54:36.912865+0100", "flow_id": 1387451945251955, "event_type": "alert", "src_ip": "43.228.157.11", "src_port": 55273, "dest_ip": "134.19.55.199", "dest_port": 3132, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T17:54:36.912865+0100", "src_ip": "43.228.157.11", "dest_ip": "134.19.55.199", "src_port": 55273, "dest_port": 3132}}'); INSERT INTO alerts VALUES(2945,1773075277.050137043,'{"timestamp": "2026-03-09T17:54:37.050137+0100", "flow_id": 1622715410202362, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59989, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29681, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:54:37.050137+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59989, "dest_port": 53}}'); INSERT INTO alerts VALUES(2946,1773075277.050137043,'{"timestamp": "2026-03-09T17:54:37.050137+0100", "flow_id": 1622712036555064, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55885, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26670, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:54:37.050137+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55885, "dest_port": 53}}'); INSERT INTO alerts VALUES(2947,1773075294.252001047,'{"timestamp": "2026-03-09T17:54:54.252001+0100", "flow_id": 1926763035308370, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:54:54.252001+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2948,1773075302.859850884,'{"timestamp": "2026-03-09T17:55:02.859851+0100", "flow_id": 1722710477345874, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:55:02.859851+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2949,1773075302.859852075,'{"timestamp": "2026-03-09T17:55:02.859852+0100", "flow_id": 1722712580595566, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:55:02.859852+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2950,1773075302.859852075,'{"timestamp": "2026-03-09T17:55:02.859852+0100", "flow_id": 1722715671524394, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:55:02.859852+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2951,1773075324.907731056,'{"timestamp": "2026-03-09T17:55:24.907731+0100", "flow_id": 1365402219786578, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:55:24.907731+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2952,1773075333.778808116,'{"timestamp": "2026-03-09T17:55:33.778808+0100", "flow_id": 1656108419486802, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:55:33.778808+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2953,1773075333.778808116,'{"timestamp": "2026-03-09T17:55:33.778808+0100", "flow_id": 1656106227769198, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:55:33.778808+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2954,1773075333.778809071,'{"timestamp": "2026-03-09T17:55:33.778809+0100", "flow_id": 1656113613665322, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:55:33.778809+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2955,1773075356.378817081,'{"timestamp": "2026-03-09T17:55:56.378817+0100", "flow_id": 1345533701075282, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:55:56.378817+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2956,1773075363.783804894,'{"timestamp": "2026-03-09T17:56:03.783805+0100", "flow_id": 1114620417643602, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:56:03.783805+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2957,1773075363.783804894,'{"timestamp": "2026-03-09T17:56:03.783805+0100", "flow_id": 1114618225925998, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:56:03.783805+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2958,1773075363.783806086,'{"timestamp": "2026-03-09T17:56:03.783806+0100", "flow_id": 1114625611822122, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:56:03.783806+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2959,1773075370.137243033,'{"timestamp": "2026-03-09T17:56:10.137243+0100", "flow_id": 589455696186236, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50401, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62729, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:56:10.137243+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50401, "dest_port": 53}}'); INSERT INTO alerts VALUES(2960,1773075370.138458014,'{"timestamp": "2026-03-09T17:56:10.138458+0100", "flow_id": 594673626986620, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54975, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63972, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:56:10.138458+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54975, "dest_port": 53}}'); INSERT INTO alerts VALUES(2961,1773075386.979588032,'{"timestamp": "2026-03-09T17:56:26.979588+0100", "flow_id": 829600754643282, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:56:26.979588+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2962,1773075391.326095104,'{"timestamp": "2026-03-09T17:56:31.326095+0100", "flow_id": 2244993084018536, "event_type": "alert", "src_ip": "167.94.146.46", "src_port": 56989, "dest_ip": "134.19.55.199", "dest_port": 53452, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:56:31.326095+0100", "src_ip": "167.94.146.46", "dest_ip": "134.19.55.199", "src_port": 56989, "dest_port": 53452}}'); INSERT INTO alerts VALUES(2963,1773075394.586374045,'{"timestamp": "2026-03-09T17:56:34.586374+0100", "flow_id": 829610682848338, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:56:34.586374+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2964,1773075394.586374998,'{"timestamp": "2026-03-09T17:56:34.586375+0100", "flow_id": 829612786098030, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:56:34.586375+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2965,1773075394.586374998,'{"timestamp": "2026-03-09T17:56:34.586375+0100", "flow_id": 829615877026858, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:56:34.586375+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2966,1773075406.009896039,'{"timestamp": "2026-03-09T17:56:46.009896+0100", "flow_id": 1731354237750644, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51083, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13830, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:56:46.009896+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51083, "dest_port": 53}}'); INSERT INTO alerts VALUES(2967,1773075418.46668005,'{"timestamp": "2026-03-09T17:56:58.466680+0100", "flow_id": 597002505761106, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:56:58.466680+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2968,1773075424.537363052,'{"timestamp": "2026-03-09T17:57:04.537363+0100", "flow_id": 56158680357784, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54494, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16573, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:57:04.537363+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54494, "dest_port": 53}}'); INSERT INTO alerts VALUES(2969,1773075424.545923948,'{"timestamp": "2026-03-09T17:57:04.545924+0100", "flow_id": 92929014219153, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61414, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48452, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:57:04.545924+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61414, "dest_port": 53}}'); INSERT INTO alerts VALUES(2970,1773075425.581516028,'{"timestamp": "2026-03-09T17:57:05.581516+0100", "flow_id": 1873315796883074, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64002, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 2, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 2, "id": 39347, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 1, "bytes_toserver": 134, "bytes_toclient": 146, "start": "2026-03-09T17:53:34.305093+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64002, "dest_port": 53}}'); INSERT INTO alerts VALUES(2971,1773075425.583784104,'{"timestamp": "2026-03-09T17:57:05.583784+0100", "flow_id": 537010466131494, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51721, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34507, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T17:57:05.583784+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51721, "dest_port": 53}}'); INSERT INTO alerts VALUES(2972,1773075426.014157056,'{"timestamp": "2026-03-09T17:57:06.014157+0100", "flow_id": 623757195318354, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:57:06.014157+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2973,1773075426.014158011,'{"timestamp": "2026-03-09T17:57:06.014158+0100", "flow_id": 623759298568046, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:57:06.014158+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2974,1773075426.014158964,'{"timestamp": "2026-03-09T17:57:06.014159+0100", "flow_id": 623766684464170, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:57:06.014159+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2975,1773075449.870523929,'{"timestamp": "2026-03-09T17:57:29.870524+0100", "flow_id": 361174441472338, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:57:29.870524+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2976,1773075456.019634008,'{"timestamp": "2026-03-09T17:57:36.019634+0100", "flow_id": 84330777777234, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:57:36.019634+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2977,1773075456.019634008,'{"timestamp": "2026-03-09T17:57:36.019634+0100", "flow_id": 84328586059630, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:57:36.019634+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2978,1773075456.020658016,'{"timestamp": "2026-03-09T17:57:36.020658+0100", "flow_id": 88729723499562, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:57:36.020658+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2979,1773075480.998321057,'{"timestamp": "2026-03-09T17:58:00.998321+0100", "flow_id": 65633446867282, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:58:00.998321+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2980,1773075482.875634909,'{"timestamp": "2026-03-09T17:58:02.875635+0100", "flow_id": 664599077263053, "event_type": "alert", "src_ip": "167.94.146.43", "src_port": 39712, "dest_ip": "134.19.55.199", "dest_port": 10336, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T17:58:02.875635+0100", "src_ip": "167.94.146.43", "dest_ip": "134.19.55.199", "src_port": 39712, "dest_port": 10336}}'); INSERT INTO alerts VALUES(2981,1773075487.128290891,'{"timestamp": "2026-03-09T17:58:07.128291+0100", "flow_id": 2239858899522642, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:58:07.128291+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2982,1773075487.128290891,'{"timestamp": "2026-03-09T17:58:07.128291+0100", "flow_id": 2239856707805038, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:58:07.128291+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2983,1773075487.128290891,'{"timestamp": "2026-03-09T17:58:07.128291+0100", "flow_id": 2239859798733866, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:58:07.128291+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2984,1773075490.809477091,'{"timestamp": "2026-03-09T17:58:10.809477+0100", "flow_id": 661929457720216, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54494, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16573, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:58:10.809477+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54494, "dest_port": 53}}'); INSERT INTO alerts VALUES(2985,1773075490.809478045,'{"timestamp": "2026-03-09T17:58:10.809478+0100", "flow_id": 661934871527825, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61414, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48452, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:58:10.809478+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61414, "dest_port": 53}}'); INSERT INTO alerts VALUES(2986,1773075493.610299111,'{"timestamp": "2026-03-09T17:58:13.610299+0100", "flow_id": 1495315720064372, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51083, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13830, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:58:13.610299+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51083, "dest_port": 53}}'); INSERT INTO alerts VALUES(2987,1773075512.259700059,'{"timestamp": "2026-03-09T17:58:32.259700+0100", "flow_id": 270980128256338, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:58:32.259700+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2988,1773075518.278481006,'{"timestamp": "2026-03-09T17:58:38.278481+0100", "flow_id": 1759020130866258, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:58:38.278481+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2989,1773075518.27848196,'{"timestamp": "2026-03-09T17:58:38.278482+0100", "flow_id": 1759022234115950, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:58:38.278482+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2990,1773075518.279612065,'{"timestamp": "2026-03-09T17:58:38.279612+0100", "flow_id": 1763878638089258, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:58:38.279612+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2991,1773075543.623963118,'{"timestamp": "2026-03-09T17:59:03.623963+0100", "flow_id": 2116952777109842, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:59:03.623963+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(2992,1773075549.346683026,'{"timestamp": "2026-03-09T17:59:09.346683+0100", "flow_id": 1488995536966738, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:59:09.346683+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(2993,1773075549.346683026,'{"timestamp": "2026-03-09T17:59:09.346683+0100", "flow_id": 1488993345249134, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:59:09.346683+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(2994,1773075549.346683979,'{"timestamp": "2026-03-09T17:59:09.346684+0100", "flow_id": 1489000731145258, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:59:09.346684+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(2995,1773075557.366455078,'{"timestamp": "2026-03-09T17:59:17.366455+0100", "flow_id": 1573913621581172, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51083, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13830, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:59:17.366455+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51083, "dest_port": 53}}'); INSERT INTO alerts VALUES(2996,1773075557.366455078,'{"timestamp": "2026-03-09T17:59:17.366455+0100", "flow_id": 1573914223418264, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54494, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16573, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:59:17.366455+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54494, "dest_port": 53}}'); INSERT INTO alerts VALUES(2997,1773075557.366456032,'{"timestamp": "2026-03-09T17:59:17.366456+0100", "flow_id": 1573919637225873, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61414, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48452, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:59:17.366456+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61414, "dest_port": 53}}'); INSERT INTO alerts VALUES(2998,1773075564.106841088,'{"timestamp": "2026-03-09T17:59:24.106841+0100", "flow_id": 1303306911494127, "event_type": "alert", "src_ip": "45.156.87.127", "src_port": 59020, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:59:24.106841+0100", "src_ip": "45.156.87.127", "dest_ip": "134.19.55.199", "src_port": 59020, "dest_port": 3306}}'); INSERT INTO alerts VALUES(2999,1773075564.106841088,'{"timestamp": "2026-03-09T17:59:24.106841+0100", "flow_id": 1303306911494127, "event_type": "alert", "src_ip": "45.156.87.127", "src_port": 59020, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T17:59:24.106841+0100", "src_ip": "45.156.87.127", "dest_ip": "134.19.55.199", "src_port": 59020, "dest_port": 3306}}'); INSERT INTO alerts VALUES(3000,1773075575.080558062,'{"timestamp": "2026-03-09T17:59:35.080558+0100", "flow_id": 2034845887312210, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:59:35.080558+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3001,1773075579.86321807,'{"timestamp": "2026-03-09T17:59:39.863218+0100", "flow_id": 892746702099538, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T17:59:39.863218+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(3002,1773075579.86321807,'{"timestamp": "2026-03-09T17:59:39.863218+0100", "flow_id": 892744510381934, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:59:39.863218+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(3003,1773075579.86321807,'{"timestamp": "2026-03-09T17:59:39.863218+0100", "flow_id": 892747601310762, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T17:59:39.863218+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3004,1773075603.269797087,'{"timestamp": "2026-03-09T18:00:03.269797+0100", "flow_id": 877297320322746, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64323, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46936, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:00:03.269797+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64323, "dest_port": 53}}'); INSERT INTO alerts VALUES(3005,1773075603.269798041,'{"timestamp": "2026-03-09T18:00:03.269798+0100", "flow_id": 877299951198606, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57785, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:00:03.269798+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57785, "dest_port": 53}}'); INSERT INTO alerts VALUES(3006,1773075605.110821009,'{"timestamp": "2026-03-09T18:00:05.110821+0100", "flow_id": 1601874529169746, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:00:05.110821+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3007,1773075609.866552114,'{"timestamp": "2026-03-09T18:00:09.866552+0100", "flow_id": 344116169643090, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:00:09.866552+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(3008,1773075609.867767095,'{"timestamp": "2026-03-09T18:00:09.867767+0100", "flow_id": 349332363190126, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:00:09.867767+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(3009,1773075609.868230105,'{"timestamp": "2026-03-09T18:00:09.868230+0100", "flow_id": 351324023977002, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:00:09.868230+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3010,1773075635.485946893,'{"timestamp": "2026-03-09T18:00:35.485947+0100", "flow_id": 961228617363794, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:00:35.485947+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3011,1773075643.2628901,'{"timestamp": "2026-03-09T18:00:43.262890+0100", "flow_id": 847632660558544, "event_type": "alert", "src_ip": "20.163.15.178", "src_port": 55004, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T18:00:43.262890+0100", "src_ip": "20.163.15.178", "dest_ip": "134.19.55.199", "src_port": 55004, "dest_port": 1433}}'); INSERT INTO alerts VALUES(3012,1773075666.945496082,'{"timestamp": "2026-03-09T18:01:06.945496+0100", "flow_id": 683176729588050, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:01:06.945496+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3013,1773075679.777551889,'{"timestamp": "2026-03-09T18:01:19.777552+0100", "flow_id": 2213663893984338, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:01:19.777552+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(3014,1773075679.777551889,'{"timestamp": "2026-03-09T18:01:19.777552+0100", "flow_id": 2213661702266734, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:01:19.777552+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(3015,1773075679.777553082,'{"timestamp": "2026-03-09T18:01:19.777553+0100", "flow_id": 2213669088162858, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:01:19.777553+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3016,1773075681.629713059,'{"timestamp": "2026-03-09T18:01:21.629713+0100", "flow_id": 452797103343547, "event_type": "alert", "src_ip": "34.197.70.90", "src_port": 55817, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T18:01:21.629713+0100", "src_ip": "34.197.70.90", "dest_ip": "134.19.55.199", "src_port": 55817, "dest_port": 1433}}'); INSERT INTO alerts VALUES(3017,1773075695.834737063,'{"timestamp": "2026-03-09T18:01:35.834737+0100", "flow_id": 2177794613333364, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51083, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13830, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:01:35.834737+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51083, "dest_port": 53}}'); INSERT INTO alerts VALUES(3018,1773075695.834737063,'{"timestamp": "2026-03-09T18:01:35.834737+0100", "flow_id": 2177795629447223, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56514, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31986, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:01:35.834737+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56514, "dest_port": 53}}'); INSERT INTO alerts VALUES(3019,1773075698.014403104,'{"timestamp": "2026-03-09T18:01:38.014403+0100", "flow_id": 624813637812059, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49988, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7789, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:01:38.014403+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49988, "dest_port": 53}}'); INSERT INTO alerts VALUES(3020,1773075698.272849083,'{"timestamp": "2026-03-09T18:01:38.272849+0100", "flow_id": 608929629942098, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:01:38.272849+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3021,1773075710.191494941,'{"timestamp": "2026-03-09T18:01:50.191495+0100", "flow_id": 1948368059077714, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:01:50.191495+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(3022,1773075710.191495896,'{"timestamp": "2026-03-09T18:01:50.191496+0100", "flow_id": 1948370162327406, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:01:50.191496+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(3023,1773075710.191495896,'{"timestamp": "2026-03-09T18:01:50.191496+0100", "flow_id": 1948373253256234, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:01:50.191496+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3024,1773075741.00624609,'{"timestamp": "2026-03-09T18:02:21.006246+0100", "flow_id": 1434204639171666, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:02:21.006246+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(3025,1773075741.00624609,'{"timestamp": "2026-03-09T18:02:21.006246+0100", "flow_id": 1434202447454062, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:02:21.006246+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(3026,1773075741.006247044,'{"timestamp": "2026-03-09T18:02:21.006247+0100", "flow_id": 1434209833350186, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:02:21.006247+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3027,1773075766.879908085,'{"timestamp": "2026-03-09T18:02:46.879908+0100", "flow_id": 1808853298131282, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:02:46.879908+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3028,1773075772.420533896,'{"timestamp": "2026-03-09T18:02:52.420534+0100", "flow_id": 1243233213322322, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:02:52.420534+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(3029,1773075772.420535087,'{"timestamp": "2026-03-09T18:02:52.420535+0100", "flow_id": 1243235316572014, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:02:52.420535+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(3030,1773075772.420535087,'{"timestamp": "2026-03-09T18:02:52.420535+0100", "flow_id": 1243238407500842, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:02:52.420535+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3031,1773075775.840095043,'{"timestamp": "2026-03-09T18:02:55.840095+0100", "flow_id": 2200808301093682, "event_type": "alert", "src_ip": "147.185.132.103", "src_port": 49255, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:02:55.840095+0100", "src_ip": "147.185.132.103", "dest_ip": "134.19.55.199", "src_port": 49255, "dest_port": 3389}}'); INSERT INTO alerts VALUES(3032,1773075784.393850089,'{"timestamp": "2026-03-09T18:03:04.393850+0100", "flow_id": 2724478739668, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 53141, "dest_ip": "134.19.55.199", "dest_port": 8022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:03:04.393850+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.55.199", "src_port": 53141, "dest_port": 8022}}'); INSERT INTO alerts VALUES(3033,1773075784.393850089,'{"timestamp": "2026-03-09T18:03:04.393850+0100", "flow_id": 2724478739668, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 53141, "dest_ip": "134.19.55.199", "dest_port": 8022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:03:04.393850+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.55.199", "src_port": 53141, "dest_port": 8022}}'); INSERT INTO alerts VALUES(3034,1773075796.985337019,'{"timestamp": "2026-03-09T18:03:16.985337+0100", "flow_id": 1135767498338642, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:03:16.985337+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3035,1773075803.145752906,'{"timestamp": "2026-03-09T18:03:23.145753+0100", "flow_id": 907482734892114, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:03:23.145753+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(3036,1773075803.145754099,'{"timestamp": "2026-03-09T18:03:23.145754+0100", "flow_id": 907484838141806, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:03:23.145754+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(3037,1773075803.146570921,'{"timestamp": "2026-03-09T18:03:23.146571+0100", "flow_id": 910996917351466, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:03:23.146571+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3038,1773075833.292213917,'{"timestamp": "2026-03-09T18:03:53.292214+0100", "flow_id": 410628033188946, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:03:53.292214+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(3039,1773075833.292213917,'{"timestamp": "2026-03-09T18:03:53.292214+0100", "flow_id": 410625841471342, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:03:53.292214+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(3040,1773075833.292215108,'{"timestamp": "2026-03-09T18:03:53.292215+0100", "flow_id": 410633227367466, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:03:53.292215+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3041,1773075837.266942977,'{"timestamp": "2026-03-09T18:03:57.266943+0100", "flow_id": 1427988770384758, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53459, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61811, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:03:57.266943+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53459, "dest_port": 53}}'); INSERT INTO alerts VALUES(3042,1773075864.335556983,'{"timestamp": "2026-03-09T18:04:24.335557+0100", "flow_id": 33834847278162, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56700, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:04:24.335557+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56700, "dest_port": 53}}'); INSERT INTO alerts VALUES(3043,1773075864.335557937,'{"timestamp": "2026-03-09T18:04:24.335558+0100", "flow_id": 33836950527854, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53174, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:04:24.335558+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53174, "dest_port": 53}}'); INSERT INTO alerts VALUES(3044,1773075864.335557937,'{"timestamp": "2026-03-09T18:04:24.335558+0100", "flow_id": 33840041456682, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:04:24.335558+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3045,1773075871.192573071,'{"timestamp": "2026-03-09T18:04:31.192573+0100", "flow_id": 2234470440088591, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53640, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60072, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:04:31.192573+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53640, "dest_port": 53}}'); INSERT INTO alerts VALUES(3046,1773075873.318846941,'{"timestamp": "2026-03-09T18:04:33.318847+0100", "flow_id": 525014558912850, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:04:33.318847+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3047,1773075883.394254922,'{"timestamp": "2026-03-09T18:04:43.394255+0100", "flow_id": 848888008219539, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50326, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22024, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:04:43.394255+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50326, "dest_port": 53}}'); INSERT INTO alerts VALUES(3048,1773075894.233416081,'{"timestamp": "2026-03-09T18:04:54.233416+0100", "flow_id": 1846942039842721, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52510, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29889, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:04:54.233416+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52510, "dest_port": 53}}'); INSERT INTO alerts VALUES(3049,1773075905.08155489,'{"timestamp": "2026-03-09T18:05:05.081555+0100", "flow_id": 350277689438955, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55727, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3474, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:05:05.081555+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55727, "dest_port": 53}}'); INSERT INTO alerts VALUES(3050,1773075915.612994909,'{"timestamp": "2026-03-09T18:05:15.612995+0100", "flow_id": 943945613197853, "event_type": "alert", "src_ip": "64.89.163.86", "src_port": 55790, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:05:15.612995+0100", "src_ip": "64.89.163.86", "dest_ip": "134.19.55.199", "src_port": 55790, "dest_port": 27017}}'); INSERT INTO alerts VALUES(3051,1773075915.946387052,'{"timestamp": "2026-03-09T18:05:15.946387+0100", "flow_id": 968479703990771, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54975, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23409, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:05:15.946387+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54975, "dest_port": 53}}'); INSERT INTO alerts VALUES(3052,1773075919.111918926,'{"timestamp": "2026-03-09T18:05:19.111919+0100", "flow_id": 2169542064252609, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 47855, "dest_ip": "134.19.55.199", "dest_port": 3492, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:05:19.111919+0100", "src_ip": "45.142.193.7", "dest_ip": "134.19.55.199", "src_port": 47855, "dest_port": 3492}}'); INSERT INTO alerts VALUES(3053,1773075926.793565034,'{"timestamp": "2026-03-09T18:05:26.793565+0100", "flow_id": 1719488947039345, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55357, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27276, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:05:26.793565+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55357, "dest_port": 53}}'); INSERT INTO alerts VALUES(3054,1773075937.645603895,'{"timestamp": "2026-03-09T18:05:37.645604+0100", "flow_id": 521049406254349, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56614, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41199, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:05:37.645604+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56614, "dest_port": 53}}'); INSERT INTO alerts VALUES(3055,1773075948.510581971,'{"timestamp": "2026-03-09T18:05:48.510582+0100", "flow_id": 1348509635599581, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55397, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50878, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:05:48.510582+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55397, "dest_port": 53}}'); INSERT INTO alerts VALUES(3056,1773075959.369689941,'{"timestamp": "2026-03-09T18:05:59.369690+0100", "flow_id": 2150758129656061, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51657, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5644, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:05:59.369690+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51657, "dest_port": 53}}'); INSERT INTO alerts VALUES(3057,1773075964.646933078,'{"timestamp": "2026-03-09T18:06:04.646933+0100", "flow_id": 1371183245766994, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:06:04.646933+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3058,1773075970.218564987,'{"timestamp": "2026-03-09T18:06:10.218565+0100", "flow_id": 657257005343371, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58631, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45527, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:06:10.218565+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58631, "dest_port": 53}}'); INSERT INTO alerts VALUES(3059,1773075976.166835069,'{"timestamp": "2026-03-09T18:06:16.166835+0100", "flow_id": 153601298732086, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63156, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36421, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:06:16.166835+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63156, "dest_port": 53}}'); INSERT INTO alerts VALUES(3060,1773075978.520014048,'{"timestamp": "2026-03-09T18:06:18.520014+0100", "flow_id": 826071079377591, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62660, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10697, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "unlinkability.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-09T18:06:18.520014+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62660, "dest_port": 53}}'); INSERT INTO alerts VALUES(3061,1773075979.122972011,'{"timestamp": "2026-03-09T18:06:19.122972+0100", "flow_id": 1091112978687628, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57503, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56966, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "attester.gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 80, "bytes_toclient": 0, "start": "2026-03-09T18:06:19.122972+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57503, "dest_port": 53}}'); INSERT INTO alerts VALUES(3062,1773075980.167891025,'{"timestamp": "2026-03-09T18:06:20.167891+0100", "flow_id": 1284037887907172, "event_type": "alert", "src_ip": "198.235.24.235", "src_port": 54859, "dest_ip": "134.19.55.199", "dest_port": 2121, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:06:20.167891+0100", "src_ip": "198.235.24.235", "dest_ip": "134.19.55.199", "src_port": 54859, "dest_port": 2121}}'); INSERT INTO alerts VALUES(3063,1773075993.976140976,'{"timestamp": "2026-03-09T18:06:33.976141+0100", "flow_id": 533321118099121, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51125, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9370, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:06:33.976141+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51125, "dest_port": 53}}'); INSERT INTO alerts VALUES(3064,1773075996.059020042,'{"timestamp": "2026-03-09T18:06:36.059020+0100", "flow_id": 1379390928269650, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:06:36.059020+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3065,1773076000.847554922,'{"timestamp": "2026-03-09T18:06:40.847555+0100", "flow_id": 262521396239510, "event_type": "alert", "src_ip": "193.163.125.184", "src_port": 36637, "dest_ip": "134.19.55.199", "dest_port": 38888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:06:40.847555+0100", "src_ip": "193.163.125.184", "dest_ip": "134.19.55.199", "src_port": 36637, "dest_port": 38888}}'); INSERT INTO alerts VALUES(3066,1773076001.855710983,'{"timestamp": "2026-03-09T18:06:41.855711+0100", "flow_id": 297552714695916, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58690, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8081, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:06:41.855711+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58690, "dest_port": 53}}'); INSERT INTO alerts VALUES(3067,1773076001.856662989,'{"timestamp": "2026-03-09T18:06:41.856663+0100", "flow_id": 301640559297771, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49331, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11880, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:06:41.856663+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49331, "dest_port": 53}}'); INSERT INTO alerts VALUES(3068,1773076004.613634109,'{"timestamp": "2026-03-09T18:06:44.613634+0100", "flow_id": 1228164870638522, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52930, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57444, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:06:44.613634+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52930, "dest_port": 53}}'); INSERT INTO alerts VALUES(3069,1773076012.932760001,'{"timestamp": "2026-03-09T18:06:52.932760+0100", "flow_id": 1191427274964481, "event_type": "alert", "src_ip": "193.163.125.183", "src_port": 47870, "dest_ip": "134.19.55.199", "dest_port": 4112, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:06:52.932760+0100", "src_ip": "193.163.125.183", "dest_ip": "134.19.55.199", "src_port": 47870, "dest_port": 4112}}'); INSERT INTO alerts VALUES(3070,1773076024.272730112,'{"timestamp": "2026-03-09T18:07:04.272730+0100", "flow_id": 45469704362853, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62381, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28624, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:07:04.272730+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62381, "dest_port": 53}}'); INSERT INTO alerts VALUES(3071,1773076026.390973092,'{"timestamp": "2026-03-09T18:07:06.390973+0100", "flow_id": 834793370104146, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:07:06.390973+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3072,1773076034.931252957,'{"timestamp": "2026-03-09T18:07:14.931253+0100", "flow_id": 622003782819037, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51631, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50825, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:07:14.931253+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51631, "dest_port": 53}}'); INSERT INTO alerts VALUES(3073,1773076039.854933978,'{"timestamp": "2026-03-09T18:07:19.854934+0100", "flow_id": 1983066967365799, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56818, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48251, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:07:19.854934+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56818, "dest_port": 53}}'); INSERT INTO alerts VALUES(3074,1773076049.699135065,'{"timestamp": "2026-03-09T18:07:29.699135+0100", "flow_id": 469487745758036, "event_type": "alert", "src_ip": "193.163.125.212", "src_port": 49303, "dest_ip": "134.19.55.199", "dest_port": 587, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:07:29.699135+0100", "src_ip": "193.163.125.212", "dest_ip": "134.19.55.199", "src_port": 49303, "dest_port": 587}}'); INSERT INTO alerts VALUES(3075,1773076050.491504907,'{"timestamp": "2026-03-09T18:07:30.491505+0100", "flow_id": 703624878696448, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52870, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59855, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:07:30.491505+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52870, "dest_port": 53}}'); INSERT INTO alerts VALUES(3076,1773076057.069971085,'{"timestamp": "2026-03-09T18:07:37.069971+0100", "flow_id": 300525208285522, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:07:37.069971+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3077,1773076061.95799303,'{"timestamp": "2026-03-09T18:07:41.957993+0100", "flow_id": 1581276940913963, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62870, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53853, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:07:41.957993+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62870, "dest_port": 53}}'); INSERT INTO alerts VALUES(3078,1773076072.81242299,'{"timestamp": "2026-03-09T18:07:52.812423+0100", "flow_id": 111631971316631, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65343, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28125, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:07:52.812423+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65343, "dest_port": 53}}'); INSERT INTO alerts VALUES(3079,1773076083.65862894,'{"timestamp": "2026-03-09T18:08:03.658629+0100", "flow_id": 858466705598912, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50023, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21750, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:08:03.658629+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50023, "dest_port": 53}}'); INSERT INTO alerts VALUES(3080,1773076088.034751893,'{"timestamp": "2026-03-09T18:08:08.034752+0100", "flow_id": 149260755087698, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:08:08.034752+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3081,1773076094.523332118,'{"timestamp": "2026-03-09T18:08:14.523332+0100", "flow_id": 1966220558692451, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53316, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43637, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:08:14.523332+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53316, "dest_port": 53}}'); INSERT INTO alerts VALUES(3082,1773076105.374285936,'{"timestamp": "2026-03-09T18:08:25.374286+0100", "flow_id": 481649352881318, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52453, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48554, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:08:25.374286+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52453, "dest_port": 53}}'); INSERT INTO alerts VALUES(3083,1773076116.226630926,'{"timestamp": "2026-03-09T18:08:36.226631+0100", "flow_id": 1254851235769024, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54488, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44963, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:08:36.226631+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54488, "dest_port": 53}}'); INSERT INTO alerts VALUES(3084,1773076118.745352983,'{"timestamp": "2026-03-09T18:08:38.745353+0100", "flow_id": 1793893927039314, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:08:38.745353+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3085,1773076127.095282078,'{"timestamp": "2026-03-09T18:08:47.095282+0100", "flow_id": 2098083874984048, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62848, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26834, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:08:47.095282+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62848, "dest_port": 53}}'); INSERT INTO alerts VALUES(3086,1773076137.952824115,'{"timestamp": "2026-03-09T18:08:57.952824+0100", "flow_id": 433174222416378, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51370, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21000, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:08:57.952824+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51370, "dest_port": 53}}'); INSERT INTO alerts VALUES(3087,1773076148.797111035,'{"timestamp": "2026-03-09T18:09:08.797111+0100", "flow_id": 1171769106904973, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58976, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55543, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:09:08.797111+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58976, "dest_port": 53}}'); INSERT INTO alerts VALUES(3088,1773076150.129928113,'{"timestamp": "2026-03-09T18:09:10.129928+0100", "flow_id": 1965413446005074, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:09:10.129928+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3089,1773076159.654638052,'{"timestamp": "2026-03-09T18:09:19.654638+0100", "flow_id": 2248702906598549, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64446, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60627, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:09:19.654638+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64446, "dest_port": 53}}'); INSERT INTO alerts VALUES(3090,1773076170.528445005,'{"timestamp": "2026-03-09T18:09:30.528445+0100", "flow_id": 580804653532715, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64211, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:09:30.528445+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64211, "dest_port": 53}}'); INSERT INTO alerts VALUES(3091,1773076181.230995894,'{"timestamp": "2026-03-09T18:09:41.230996+0100", "flow_id": 1555072270545234, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:09:41.230996+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3092,1773076181.357515096,'{"timestamp": "2026-03-09T18:09:41.357515+0100", "flow_id": 1535518366628570, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14168, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:09:41.357515+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3093,1773076186.855089903,'{"timestamp": "2026-03-09T18:09:46.855090+0100", "flow_id": 576361035687685, "event_type": "alert", "src_ip": "193.163.125.185", "src_port": 45171, "dest_ip": "134.19.55.199", "dest_port": 1103, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:09:46.855090+0100", "src_ip": "193.163.125.185", "dest_ip": "134.19.55.199", "src_port": 45171, "dest_port": 1103}}'); INSERT INTO alerts VALUES(3094,1773076192.010405064,'{"timestamp": "2026-03-09T18:09:52.010405+0100", "flow_id": 44692238764783, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49848, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19793, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:09:52.010405+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49848, "dest_port": 53}}'); INSERT INTO alerts VALUES(3095,1773076202.656425953,'{"timestamp": "2026-03-09T18:10:02.656426+0100", "flow_id": 567530166495795, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58773, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63086, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:10:02.656426+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58773, "dest_port": 53}}'); INSERT INTO alerts VALUES(3096,1773076211.567161084,'{"timestamp": "2026-03-09T18:10:11.567161+0100", "flow_id": 1028565132475429, "event_type": "alert", "src_ip": "195.184.76.179", "src_port": 52105, "dest_ip": "134.19.55.199", "dest_port": 5352, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:10:11.567161+0100", "src_ip": "195.184.76.179", "dest_ip": "134.19.55.199", "src_port": 52105, "dest_port": 5352}}'); INSERT INTO alerts VALUES(3097,1773076211.81003189,'{"timestamp": "2026-03-09T18:10:11.810032+0100", "flow_id": 945788209934674, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:10:11.810032+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3098,1773076223.76584506,'{"timestamp": "2026-03-09T18:10:23.765845+0100", "flow_id": 2163382284050981, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59050, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40466, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:10:23.765845+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59050, "dest_port": 53}}'); INSERT INTO alerts VALUES(3099,1773076234.607888936,'{"timestamp": "2026-03-09T18:10:34.607889+0100", "flow_id": 640540923073049, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49676, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40317, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:10:34.607889+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49676, "dest_port": 53}}'); INSERT INTO alerts VALUES(3100,1773076245.265512944,'{"timestamp": "2026-03-09T18:10:45.265513+0100", "flow_id": 1421847689954467, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49154, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22218, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:10:45.265513+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49154, "dest_port": 53}}'); INSERT INTO alerts VALUES(3101,1773076246.859980106,'{"timestamp": "2026-03-09T18:10:46.859980+0100", "flow_id": 1723265117869676, "event_type": "alert", "src_ip": "147.185.132.178", "src_port": 53279, "dest_ip": "134.19.55.199", "dest_port": 24794, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:10:46.859980+0100", "src_ip": "147.185.132.178", "dest_ip": "134.19.55.199", "src_port": 53279, "dest_port": 24794}}'); INSERT INTO alerts VALUES(3102,1773076255.911669015,'{"timestamp": "2026-03-09T18:10:55.911669+0100", "flow_id": 2226742201174761, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60010, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51924, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:10:55.911669+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60010, "dest_port": 53}}'); INSERT INTO alerts VALUES(3103,1773076263.617384911,'{"timestamp": "2026-03-09T18:11:03.617385+0100", "flow_id": 2088699010870799, "event_type": "alert", "src_ip": "167.94.138.158", "src_port": 47131, "dest_ip": "134.19.55.199", "dest_port": 20547, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:11:03.617385+0100", "src_ip": "167.94.138.158", "dest_ip": "134.19.55.199", "src_port": 47131, "dest_port": 20547}}'); INSERT INTO alerts VALUES(3104,1773076266.567996025,'{"timestamp": "2026-03-09T18:11:06.567996+0100", "flow_id": 750676706897924, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57731, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18659, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:11:06.567996+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57731, "dest_port": 53}}'); INSERT INTO alerts VALUES(3105,1773076277.41563201,'{"timestamp": "2026-03-09T18:11:17.415632+0100", "flow_id": 1503652997575884, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60250, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10796, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:11:17.415632+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60250, "dest_port": 53}}'); INSERT INTO alerts VALUES(3106,1773076288.276962042,'{"timestamp": "2026-03-09T18:11:28.276962+0100", "flow_id": 63643883320180, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50386, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6624, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:11:28.276962+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50386, "dest_port": 53}}'); INSERT INTO alerts VALUES(3107,1773076299.113184929,'{"timestamp": "2026-03-09T18:11:39.113185+0100", "flow_id": 1049076426138995, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62626, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59336, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:11:39.113185+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62626, "dest_port": 53}}'); INSERT INTO alerts VALUES(3108,1773076302.839234113,'{"timestamp": "2026-03-09T18:11:42.839234+0100", "flow_id": 1915635896650969, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52213, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26501, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:11:42.839234+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52213, "dest_port": 53}}'); INSERT INTO alerts VALUES(3109,1773076304.167623996,'{"timestamp": "2026-03-09T18:11:44.167624+0100", "flow_id": 156991696220498, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:11:44.167624+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3110,1773076313.665199995,'{"timestamp": "2026-03-09T18:11:53.665200+0100", "flow_id": 323741672428806, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61921, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12119, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:11:53.665200+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61921, "dest_port": 53}}'); INSERT INTO alerts VALUES(3111,1773076324.518929958,'{"timestamp": "2026-03-09T18:12:04.518930+0100", "flow_id": 1384366361849086, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57693, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 423, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:12:04.518930+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57693, "dest_port": 53}}'); INSERT INTO alerts VALUES(3112,1773076335.38142395,'{"timestamp": "2026-03-09T18:12:15.381424+0100", "flow_id": 2201155206171228, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52550, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36139, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:12:15.381424+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52550, "dest_port": 53}}'); INSERT INTO alerts VALUES(3113,1773076335.612641096,'{"timestamp": "2026-03-09T18:12:15.612641+0100", "flow_id": 2068325157384530, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:12:15.612641+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3114,1773076344.080683947,'{"timestamp": "2026-03-09T18:12:24.080684+0100", "flow_id": 65062041057573, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59256, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36225, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:12:24.080684+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59256, "dest_port": 53}}'); INSERT INTO alerts VALUES(3115,1773076354.62805605,'{"timestamp": "2026-03-09T18:12:34.628056+0100", "flow_id": 727156468424408, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50432, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53865, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:12:34.628056+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50432, "dest_port": 53}}'); INSERT INTO alerts VALUES(3116,1773076365.474740983,'{"timestamp": "2026-03-09T18:12:45.474741+0100", "flow_id": 1476047590748268, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63194, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49056, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:12:45.474741+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63194, "dest_port": 53}}'); INSERT INTO alerts VALUES(3117,1773076365.616761922,'{"timestamp": "2026-03-09T18:12:45.616762+0100", "flow_id": 1523074764190034, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:12:45.616762+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3118,1773076373.953927993,'{"timestamp": "2026-03-09T18:12:53.953928+0100", "flow_id": 1563817148783661, "event_type": "alert", "src_ip": "147.185.132.195", "src_port": 50476, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:12:53.953928+0100", "src_ip": "147.185.132.195", "dest_ip": "134.19.55.199", "src_port": 50476, "dest_port": 23}}'); INSERT INTO alerts VALUES(3119,1773076375.515090943,'{"timestamp": "2026-03-09T18:12:55.515091+0100", "flow_id": 2212303167826535, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63085, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15950, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:12:55.515091+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63085, "dest_port": 53}}'); INSERT INTO alerts VALUES(3120,1773076386.368199111,'{"timestamp": "2026-03-09T18:13:06.368199+0100", "flow_id": 736977839172990, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64412, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1779, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:13:06.368199+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64412, "dest_port": 53}}'); INSERT INTO alerts VALUES(3121,1773076396.76623106,'{"timestamp": "2026-03-09T18:13:16.766231+0100", "flow_id": 1320614300823890, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:13:16.766231+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3122,1773076397.224581956,'{"timestamp": "2026-03-09T18:13:17.224582+0100", "flow_id": 1527525824655719, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55051, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40370, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:13:17.224582+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55051, "dest_port": 53}}'); INSERT INTO alerts VALUES(3123,1773076408.073525906,'{"timestamp": "2026-03-09T18:13:28.073526+0100", "flow_id": 34320737153730, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60066, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42243, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:13:28.073526+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60066, "dest_port": 53}}'); INSERT INTO alerts VALUES(3124,1773076418.729060888,'{"timestamp": "2026-03-09T18:13:38.729061+0100", "flow_id": 598022118727279, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62233, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34590, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:13:38.729061+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62233, "dest_port": 53}}'); INSERT INTO alerts VALUES(3125,1773076419.713610888,'{"timestamp": "2026-03-09T18:13:39.713611+0100", "flow_id": 1094614131011007, "event_type": "alert", "src_ip": "176.65.148.95", "src_port": 48483, "dest_ip": "134.19.55.199", "dest_port": 13200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:13:39.713611+0100", "src_ip": "176.65.148.95", "dest_ip": "134.19.55.199", "src_port": 48483, "dest_port": 13200}}'); INSERT INTO alerts VALUES(3126,1773076419.713610888,'{"timestamp": "2026-03-09T18:13:39.713611+0100", "flow_id": 1094614131011007, "event_type": "alert", "src_ip": "176.65.148.95", "src_port": 48483, "dest_ip": "134.19.55.199", "dest_port": 13200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:13:39.713611+0100", "src_ip": "176.65.148.95", "dest_ip": "134.19.55.199", "src_port": 48483, "dest_port": 13200}}'); INSERT INTO alerts VALUES(3127,1773076427.855953931,'{"timestamp": "2026-03-09T18:13:47.855954+0100", "flow_id": 861546721390930, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:13:47.855954+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3128,1773076429.583652973,'{"timestamp": "2026-03-09T18:13:49.583653+0100", "flow_id": 1662346553417944, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56480, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37150, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:13:49.583653+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56480, "dest_port": 53}}'); INSERT INTO alerts VALUES(3129,1773076440.437840938,'{"timestamp": "2026-03-09T18:14:00.437841+0100", "flow_id": 191666462323031, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58209, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61856, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:14:00.437841+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58209, "dest_port": 53}}'); INSERT INTO alerts VALUES(3130,1773076451.08801794,'{"timestamp": "2026-03-09T18:14:11.088018+0100", "flow_id": 940987764325147, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50761, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24852, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:14:11.088018+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50761, "dest_port": 53}}'); INSERT INTO alerts VALUES(3131,1773076459.111821889,'{"timestamp": "2026-03-09T18:14:19.111822+0100", "flow_id": 1043223838011730, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:14:19.111822+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3132,1773076461.963937998,'{"timestamp": "2026-03-09T18:14:21.963938+0100", "flow_id": 1606808147887630, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58142, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17424, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:14:21.963938+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58142, "dest_port": 53}}'); INSERT INTO alerts VALUES(3133,1773076473.415674924,'{"timestamp": "2026-03-09T18:14:33.415675+0100", "flow_id": 377938459985923, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50078, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34498, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:14:33.415675+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50078, "dest_port": 53}}'); INSERT INTO alerts VALUES(3134,1773076484.270075083,'{"timestamp": "2026-03-09T18:14:44.270075+0100", "flow_id": 1159964794407295, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62560, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21751, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:14:44.270075+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62560, "dest_port": 53}}'); INSERT INTO alerts VALUES(3135,1773076485.315030097,'{"timestamp": "2026-03-09T18:14:45.315030+0100", "flow_id": 1634521464748020, "event_type": "alert", "src_ip": "45.142.154.99", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 50777, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:14:45.315030+0100", "src_ip": "45.142.154.99", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 50777}}'); INSERT INTO alerts VALUES(3136,1773076489.224828958,'{"timestamp": "2026-03-09T18:14:49.224829+0100", "flow_id": 402685300388178, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:14:49.224829+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3137,1773076494.925306082,'{"timestamp": "2026-03-09T18:14:54.925306+0100", "flow_id": 1722362468880005, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63897, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58779, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:14:54.925306+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63897, "dest_port": 53}}'); INSERT INTO alerts VALUES(3138,1773076541.423955918,'{"timestamp": "2026-03-09T18:15:41.423956+0100", "flow_id": 1539403576675236, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50194, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:15:41.423956+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54632, "dest_port": 53}}'); INSERT INTO alerts VALUES(3139,1773076542.778872014,'{"timestamp": "2026-03-09T18:15:42.778872+0100", "flow_id": 1937857790544522, "event_type": "alert", "src_ip": "147.185.132.108", "src_port": 54536, "dest_ip": "134.19.55.199", "dest_port": 7687, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:15:42.778872+0100", "src_ip": "147.185.132.108", "dest_ip": "134.19.55.199", "src_port": 54536, "dest_port": 7687}}'); INSERT INTO alerts VALUES(3140,1773076551.444998026,'{"timestamp": "2026-03-09T18:15:51.444998+0100", "flow_id": 2192729277587004, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55525, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28822, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:15:51.444998+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55525, "dest_port": 53}}'); INSERT INTO alerts VALUES(3141,1773076562.292124033,'{"timestamp": "2026-03-09T18:16:02.292124+0100", "flow_id": 691714407640044, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56423, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58487, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:16:02.292124+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56423, "dest_port": 53}}'); INSERT INTO alerts VALUES(3142,1773076572.031677961,'{"timestamp": "2026-03-09T18:16:12.031678+0100", "flow_id": 1261957932462418, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:16:12.031678+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3143,1773076573.148488044,'{"timestamp": "2026-03-09T18:16:13.148488+0100", "flow_id": 1482178777262597, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65122, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22403, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:16:13.148488+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65122, "dest_port": 53}}'); INSERT INTO alerts VALUES(3144,1773076582.672633886,'{"timestamp": "2026-03-09T18:16:22.672634+0100", "flow_id": 1763044395761499, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49988, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7789, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:16:22.672634+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49988, "dest_port": 53}}'); INSERT INTO alerts VALUES(3145,1773076582.672633886,'{"timestamp": "2026-03-09T18:16:22.672634+0100", "flow_id": 1763043522574391, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56514, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31986, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:16:22.672634+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56514, "dest_port": 53}}'); INSERT INTO alerts VALUES(3146,1773076582.672635079,'{"timestamp": "2026-03-09T18:16:22.672635+0100", "flow_id": 1763047347198833, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49924, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41191, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:16:22.672635+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49924, "dest_port": 53}}'); INSERT INTO alerts VALUES(3147,1773076582.672635079,'{"timestamp": "2026-03-09T18:16:22.672635+0100", "flow_id": 1763049553420734, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52183, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20907, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:16:22.672635+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52183, "dest_port": 53}}'); INSERT INTO alerts VALUES(3148,1773076584.026870013,'{"timestamp": "2026-03-09T18:16:24.026870+0100", "flow_id": 115407429855847, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52940, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35709, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:16:24.026870+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52940, "dest_port": 53}}'); INSERT INTO alerts VALUES(3149,1773076595.476140976,'{"timestamp": "2026-03-09T18:16:35.476141+0100", "flow_id": 919113539167673, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64913, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64485, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:16:35.476141+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64913, "dest_port": 53}}'); INSERT INTO alerts VALUES(3150,1773076603.273611068,'{"timestamp": "2026-03-09T18:16:43.273611+0100", "flow_id": 893677371732306, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:16:43.273611+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3151,1773076606.346390963,'{"timestamp": "2026-03-09T18:16:46.346391+0100", "flow_id": 1769214793282524, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51953, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15289, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:16:46.346391+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51953, "dest_port": 53}}'); INSERT INTO alerts VALUES(3152,1773076617.177326917,'{"timestamp": "2026-03-09T18:16:57.177327+0100", "flow_id": 480140819599191, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62216, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21168, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:16:57.177327+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62216, "dest_port": 53}}'); INSERT INTO alerts VALUES(3153,1773076628.036672115,'{"timestamp": "2026-03-09T18:17:08.036672+0100", "flow_id": 1283408590195315, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56387, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42690, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:17:08.036672+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56387, "dest_port": 53}}'); INSERT INTO alerts VALUES(3154,1773076629.7038939,'{"timestamp": "2026-03-09T18:17:09.703894+0100", "flow_id": 1615827807061553, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 52929, "dest_ip": "134.19.55.199", "dest_port": 50219, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:17:09.703894+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 52929, "dest_port": 50219}}'); INSERT INTO alerts VALUES(3155,1773076634.758023023,'{"timestamp": "2026-03-09T18:17:14.758023+0100", "flow_id": 722411255837010, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:17:14.758023+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3156,1773076636.492554904,'{"timestamp": "2026-03-09T18:17:16.492555+0100", "flow_id": 1271084613245809, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49924, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41191, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:17:16.492555+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49924, "dest_port": 53}}'); INSERT INTO alerts VALUES(3157,1773076636.492556095,'{"timestamp": "2026-03-09T18:17:16.492556+0100", "flow_id": 1271091114435006, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52183, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20907, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:17:16.492556+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52183, "dest_port": 53}}'); INSERT INTO alerts VALUES(3158,1773076636.492556095,'{"timestamp": "2026-03-09T18:17:16.492556+0100", "flow_id": 1271089898292691, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50729, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22194, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:17:16.492556+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50729, "dest_port": 53}}'); INSERT INTO alerts VALUES(3159,1773076636.492556095,'{"timestamp": "2026-03-09T18:17:16.492556+0100", "flow_id": 1271087363773389, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62702, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42397, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:17:16.492556+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62702, "dest_port": 53}}'); INSERT INTO alerts VALUES(3160,1773076638.891444922,'{"timestamp": "2026-03-09T18:17:18.891445+0100", "flow_id": 1858404354774507, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56521, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16073, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:17:18.891445+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56521, "dest_port": 53}}'); INSERT INTO alerts VALUES(3161,1773076649.743362903,'{"timestamp": "2026-03-09T18:17:29.743363+0100", "flow_id": 377973762518805, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65277, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60929, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:17:29.743363+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65277, "dest_port": 53}}'); INSERT INTO alerts VALUES(3162,1773076660.598673106,'{"timestamp": "2026-03-09T18:17:40.598673+0100", "flow_id": 1163907060836080, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54206, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52280, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:17:40.598673+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54206, "dest_port": 53}}'); INSERT INTO alerts VALUES(3163,1773076665.810708999,'{"timestamp": "2026-03-09T18:17:45.810709+0100", "flow_id": 385745949372754, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:17:45.810709+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3164,1773076671.252831936,'{"timestamp": "2026-03-09T18:17:51.252832+0100", "flow_id": 2211808807284520, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59305, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16733, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:17:51.252832+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59305, "dest_port": 53}}'); INSERT INTO alerts VALUES(3165,1773076682.101061106,'{"timestamp": "2026-03-09T18:18:02.101061+0100", "flow_id": 715529790200231, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59049, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5471, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:18:02.101061+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59049, "dest_port": 53}}'); INSERT INTO alerts VALUES(3166,1773076687.842268943,'{"timestamp": "2026-03-09T18:18:07.842269+0100", "flow_id": 2210143079581381, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49233, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 482, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:18:07.842269+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49233, "dest_port": 53}}'); INSERT INTO alerts VALUES(3167,1773076696.966845989,'{"timestamp": "2026-03-09T18:18:16.966846+0100", "flow_id": 211924327936338, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:18:16.966846+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3168,1773076700.245232106,'{"timestamp": "2026-03-09T18:18:20.245232+0100", "flow_id": 1334740388356367, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64797, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12617, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:18:20.245232+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64797, "dest_port": 53}}'); INSERT INTO alerts VALUES(3169,1773076702.881649017,'{"timestamp": "2026-03-09T18:18:22.881649+0100", "flow_id": 1816331701552595, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50729, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22194, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:18:22.881649+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50729, "dest_port": 53}}'); INSERT INTO alerts VALUES(3170,1773076702.881649017,'{"timestamp": "2026-03-09T18:18:22.881649+0100", "flow_id": 1816329167033293, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62702, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42397, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:18:22.881649+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62702, "dest_port": 53}}'); INSERT INTO alerts VALUES(3171,1773076702.881649971,'{"timestamp": "2026-03-09T18:18:22.881650+0100", "flow_id": 1816336784578311, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49754, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41743, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:18:22.881650+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49754, "dest_port": 53}}'); INSERT INTO alerts VALUES(3172,1773076702.881649971,'{"timestamp": "2026-03-09T18:18:22.881650+0100", "flow_id": 1816337233386542, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61547, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57904, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:18:22.881650+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61547, "dest_port": 53}}'); INSERT INTO alerts VALUES(3173,1773076734.211076022,'{"timestamp": "2026-03-09T18:18:54.211076+0100", "flow_id": 1750992998328339, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57341, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17314, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:18:54.211076+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57341, "dest_port": 53}}'); INSERT INTO alerts VALUES(3174,1773076734.211513043,'{"timestamp": "2026-03-09T18:18:54.211513+0100", "flow_id": 1752866753677415, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64778, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61744, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:18:54.211513+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64778, "dest_port": 53}}'); INSERT INTO alerts VALUES(3175,1773076734.493619919,'{"timestamp": "2026-03-09T18:18:54.493620+0100", "flow_id": 1838607088357488, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57257, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8950, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T18:18:54.493620+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57257, "dest_port": 53}}'); INSERT INTO alerts VALUES(3176,1773076734.494110108,'{"timestamp": "2026-03-09T18:18:54.494110+0100", "flow_id": 1840712740677811, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53275, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57579, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T18:18:54.494110+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53275, "dest_port": 53}}'); INSERT INTO alerts VALUES(3177,1773076736.402008057,'{"timestamp": "2026-03-09T18:18:56.402008+0100", "flow_id": 37762702399653, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58913, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4441, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:18:56.402008+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58913, "dest_port": 53}}'); INSERT INTO alerts VALUES(3178,1773076736.40230298,'{"timestamp": "2026-03-09T18:18:56.402303+0100", "flow_id": 39031298570573, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64885, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29712, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:18:56.402303+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64885, "dest_port": 53}}'); INSERT INTO alerts VALUES(3179,1773076762.7776649,'{"timestamp": "2026-03-09T18:19:22.777665+0100", "flow_id": 806773003465042, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:19:22.777665+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3180,1773076764.486077071,'{"timestamp": "2026-03-09T18:19:24.486077+0100", "flow_id": 1243262937887042, "event_type": "alert", "src_ip": "130.12.181.151", "src_port": 60967, "dest_ip": "134.19.55.199", "dest_port": 15814, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T18:19:24.486077+0100", "src_ip": "130.12.181.151", "dest_ip": "134.19.55.199", "src_port": 60967, "dest_port": 15814}}'); INSERT INTO alerts VALUES(3181,1773076764.486077071,'{"timestamp": "2026-03-09T18:19:24.486077+0100", "flow_id": 1243262937887042, "event_type": "alert", "src_ip": "130.12.181.151", "src_port": 60967, "dest_ip": "134.19.55.199", "dest_port": 15814, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500004, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 3", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T18:19:24.486077+0100", "src_ip": "130.12.181.151", "dest_ip": "134.19.55.199", "src_port": 60967, "dest_port": 15814}}'); INSERT INTO alerts VALUES(3182,1773076793.275477886,'{"timestamp": "2026-03-09T18:19:53.275478+0100", "flow_id": 338746122252626, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:19:53.275478+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3183,1773076798.618279934,'{"timestamp": "2026-03-09T18:19:58.618280+0100", "flow_id": 1811068799572133, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58913, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4441, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:19:58.618280+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58913, "dest_port": 53}}'); INSERT INTO alerts VALUES(3184,1773076798.618279934,'{"timestamp": "2026-03-09T18:19:58.618280+0100", "flow_id": 1811070380390733, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64885, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29712, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:19:58.618280+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64885, "dest_port": 53}}'); INSERT INTO alerts VALUES(3185,1773076805.957437038,'{"timestamp": "2026-03-09T18:20:05.957437+0100", "flow_id": 1578889019494857, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 14522, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:20:05.957437+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 14522}}'); INSERT INTO alerts VALUES(3186,1773076807.457798957,'{"timestamp": "2026-03-09T18:20:07.457799+0100", "flow_id": 2247710414886663, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49754, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41743, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:20:07.457799+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49754, "dest_port": 53}}'); INSERT INTO alerts VALUES(3187,1773076807.457798957,'{"timestamp": "2026-03-09T18:20:07.457799+0100", "flow_id": 2247710863694894, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61547, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57904, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:20:07.457799+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61547, "dest_port": 53}}'); INSERT INTO alerts VALUES(3188,1773076816.007628917,'{"timestamp": "2026-03-09T18:20:16.007629+0100", "flow_id": 32768297214223, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64797, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12617, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:20:16.007629+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64797, "dest_port": 53}}'); INSERT INTO alerts VALUES(3189,1773076816.007630109,'{"timestamp": "2026-03-09T18:20:16.007630+0100", "flow_id": 32771033876211, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49853, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19673, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:20:16.007630+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49853, "dest_port": 53}}'); INSERT INTO alerts VALUES(3190,1773076816.668431044,'{"timestamp": "2026-03-09T18:20:16.668431+0100", "flow_id": 56143500145011, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62160, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44017, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T18:20:16.668431+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62160, "dest_port": 53}}'); INSERT INTO alerts VALUES(3191,1773076816.668745994,'{"timestamp": "2026-03-09T18:20:16.668746+0100", "flow_id": 57494274127957, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60256, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47556, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T18:20:16.668746+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60256, "dest_port": 53}}'); INSERT INTO alerts VALUES(3192,1773076824.367258072,'{"timestamp": "2026-03-09T18:20:24.367258+0100", "flow_id": 169988267258194, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:20:24.367258+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3193,1773076831.169323922,'{"timestamp": "2026-03-09T18:20:31.169324+0100", "flow_id": 2134618052180467, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 56779, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:20:31.169324+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 56779, "dest_port": 3306}}'); INSERT INTO alerts VALUES(3194,1773076831.169323922,'{"timestamp": "2026-03-09T18:20:31.169324+0100", "flow_id": 2134618052180467, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 56779, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:20:31.169324+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 56779, "dest_port": 3306}}'); INSERT INTO alerts VALUES(3195,1773076836.650368929,'{"timestamp": "2026-03-09T18:20:36.650369+0100", "flow_id": 1385941950600752, "event_type": "alert", "src_ip": "167.94.138.145", "src_port": 22268, "dest_ip": "134.19.55.199", "dest_port": 33389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:20:36.650369+0100", "src_ip": "167.94.138.145", "dest_ip": "134.19.55.199", "src_port": 22268, "dest_port": 33389}}'); INSERT INTO alerts VALUES(3196,1773076855.813513994,'{"timestamp": "2026-03-09T18:20:55.813514+0100", "flow_id": 2086643192901970, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:20:55.813514+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3197,1773076861.875720977,'{"timestamp": "2026-03-09T18:21:01.875721+0100", "flow_id": 1509397513089162, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60980, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51909, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T18:21:01.875721+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60980, "dest_port": 53}}'); INSERT INTO alerts VALUES(3198,1773076861.875721932,'{"timestamp": "2026-03-09T18:21:01.875722+0100", "flow_id": 1509400365583908, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54787, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49531, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T18:21:01.875722+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54787, "dest_port": 53}}'); INSERT INTO alerts VALUES(3199,1773076868.735796929,'{"timestamp": "2026-03-09T18:21:08.735797+0100", "flow_id": 1189899504503067, "event_type": "alert", "src_ip": "130.12.181.151", "src_port": 42552, "dest_ip": "134.19.55.199", "dest_port": 19988, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500004, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 3", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T18:21:08.735797+0100", "src_ip": "130.12.181.151", "dest_ip": "134.19.55.199", "src_port": 42552, "dest_port": 19988}}'); INSERT INTO alerts VALUES(3200,1773076876.173683882,'{"timestamp": "2026-03-09T18:21:16.173684+0100", "flow_id": 1308918403192997, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58913, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4441, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:21:16.173684+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58913, "dest_port": 53}}'); INSERT INTO alerts VALUES(3201,1773076876.173683882,'{"timestamp": "2026-03-09T18:21:16.173684+0100", "flow_id": 1308919984011597, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64885, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29712, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:21:16.173684+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64885, "dest_port": 53}}'); INSERT INTO alerts VALUES(3202,1773076878.904412031,'{"timestamp": "2026-03-09T18:21:18.904412+0100", "flow_id": 1914095558543091, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49853, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19673, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:21:18.904412+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49853, "dest_port": 53}}'); INSERT INTO alerts VALUES(3203,1773076885.816261054,'{"timestamp": "2026-03-09T18:21:25.816261+0100", "flow_id": 1535491514642770, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:21:25.816261+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3204,1773076907.194327116,'{"timestamp": "2026-03-09T18:21:47.194327+0100", "flow_id": 1116106992856508, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57440, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16879, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:21:47.194327+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57440, "dest_port": 53}}'); INSERT INTO alerts VALUES(3205,1773076917.31558609,'{"timestamp": "2026-03-09T18:21:57.315586+0100", "flow_id": 1636908577403218, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:21:57.315586+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3206,1773076918.656524896,'{"timestamp": "2026-03-09T18:21:58.656525+0100", "flow_id": 1693853655875615, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59655, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:21:58.656525+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59655, "dest_port": 53}}'); INSERT INTO alerts VALUES(3207,1773076929.497278929,'{"timestamp": "2026-03-09T18:22:09.497279+0100", "flow_id": 446950824319284, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13129, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:22:09.497279+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59048, "dest_port": 53}}'); INSERT INTO alerts VALUES(3208,1773076940.161427021,'{"timestamp": "2026-03-09T18:22:20.161427+0100", "flow_id": 1256277371601216, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57068, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11633, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:22:20.161427+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57068, "dest_port": 53}}'); INSERT INTO alerts VALUES(3209,1773076947.015104055,'{"timestamp": "2026-03-09T18:22:27.015104+0100", "flow_id": 909299031384283, "event_type": "alert", "src_ip": "130.12.181.151", "src_port": 58469, "dest_ip": "134.19.55.199", "dest_port": 4297, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500004, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 3", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T18:22:27.015104+0100", "src_ip": "130.12.181.151", "dest_ip": "134.19.55.199", "src_port": 58469, "dest_port": 4297}}'); INSERT INTO alerts VALUES(3210,1773076948.378530026,'{"timestamp": "2026-03-09T18:22:28.378530+0100", "flow_id": 1344301045461330, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:22:28.378530+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3211,1773076951.01042509,'{"timestamp": "2026-03-09T18:22:31.010425+0100", "flow_id": 2015102066332136, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61247, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:22:31.010425+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61247, "dest_port": 53}}'); INSERT INTO alerts VALUES(3212,1773076951.601247072,'{"timestamp": "2026-03-09T18:22:31.601247+0100", "flow_id": 2019387156157080, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 43748, "dest_ip": "134.19.55.199", "dest_port": 24074, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:22:31.601247+0100", "src_ip": "167.94.146.37", "dest_ip": "134.19.55.199", "src_port": 43748, "dest_port": 24074}}'); INSERT INTO alerts VALUES(3213,1773076962.489523888,'{"timestamp": "2026-03-09T18:22:42.489524+0100", "flow_id": 695117977007803, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64280, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40761, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:22:42.489524+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64280, "dest_port": 53}}'); INSERT INTO alerts VALUES(3214,1773076973.331993103,'{"timestamp": "2026-03-09T18:22:53.331993+0100", "flow_id": 1425899389713146, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52530, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58071, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:22:53.331993+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52530, "dest_port": 53}}'); INSERT INTO alerts VALUES(3215,1773076979.010178089,'{"timestamp": "2026-03-09T18:22:59.010178+0100", "flow_id": 888141158887762, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:22:59.010178+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3216,1773076984.19035101,'{"timestamp": "2026-03-09T18:23:04.190351+0100", "flow_id": 254602914620272, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64957, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16030, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:23:04.190351+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64957, "dest_port": 53}}'); INSERT INTO alerts VALUES(3217,1773076995.046838999,'{"timestamp": "2026-03-09T18:23:15.046839+0100", "flow_id": 1045599940392433, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64175, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48906, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:23:15.046839+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64175, "dest_port": 53}}'); INSERT INTO alerts VALUES(3218,1773077005.906296969,'{"timestamp": "2026-03-09T18:23:25.906297+0100", "flow_id": 1640717876997544, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64344, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43328, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:23:25.906297+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64344, "dest_port": 53}}'); INSERT INTO alerts VALUES(3219,1773077010.178044081,'{"timestamp": "2026-03-09T18:23:30.178044+0100", "flow_id": 764695208866130, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:23:30.178044+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3220,1773077016.759458065,'{"timestamp": "2026-03-09T18:23:36.759458+0100", "flow_id": 165624008063580, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54758, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8888, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:23:36.759458+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54758, "dest_port": 53}}'); INSERT INTO alerts VALUES(3221,1773077019.77470994,'{"timestamp": "2026-03-09T18:23:39.774710+0100", "flow_id": 1075557228486952, "event_type": "alert", "src_ip": "167.94.138.153", "src_port": 35813, "dest_ip": "134.19.55.199", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:23:39.774710+0100", "src_ip": "167.94.138.153", "dest_ip": "134.19.55.199", "src_port": 35813, "dest_port": 25565}}'); INSERT INTO alerts VALUES(3222,1773077023.047632932,'{"timestamp": "2026-03-09T18:23:43.047633+0100", "flow_id": 2174907170027503, "event_type": "alert", "src_ip": "130.12.181.151", "src_port": 52675, "dest_ip": "134.19.55.199", "dest_port": 24685, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500004, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 3", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T18:23:43.047633+0100", "src_ip": "130.12.181.151", "dest_ip": "134.19.55.199", "src_port": 52675, "dest_port": 24685}}'); INSERT INTO alerts VALUES(3223,1773077027.616404056,'{"timestamp": "2026-03-09T18:23:47.616404+0100", "flow_id": 958588670926968, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49998, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24521, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:23:47.616404+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49998, "dest_port": 53}}'); INSERT INTO alerts VALUES(3224,1773077038.258128882,'{"timestamp": "2026-03-09T18:23:58.258129+0100", "flow_id": 1953083484902512, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57863, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22502, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:23:58.258129+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57863, "dest_port": 53}}'); INSERT INTO alerts VALUES(3225,1773077040.095746995,'{"timestamp": "2026-03-09T18:24:00.095747+0100", "flow_id": 129757748995242, "event_type": "alert", "src_ip": "14.103.243.93", "src_port": 65400, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:24:00.095747+0100", "src_ip": "14.103.243.93", "dest_ip": "134.19.55.199", "src_port": 65400, "dest_port": 5432}}'); INSERT INTO alerts VALUES(3226,1773077041.157529115,'{"timestamp": "2026-03-09T18:24:01.157529+0100", "flow_id": 129757748995242, "event_type": "alert", "src_ip": "14.103.243.93", "src_port": 65400, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 120, "bytes_toclient": 0, "start": "2026-03-09T18:24:00.095747+0100", "src_ip": "14.103.243.93", "dest_ip": "134.19.55.199", "src_port": 65400, "dest_port": 5432}}'); INSERT INTO alerts VALUES(3227,1773077041.479849101,'{"timestamp": "2026-03-09T18:24:01.479849+0100", "flow_id": 372087953371474, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:24:01.479849+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3228,1773077049.113538027,'{"timestamp": "2026-03-09T18:24:09.113538+0100", "flow_id": 487642787014131, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54135, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58463, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:24:09.113538+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54135, "dest_port": 53}}'); INSERT INTO alerts VALUES(3229,1773077059.144176959,'{"timestamp": "2026-03-09T18:24:19.144177+0100", "flow_id": 900711215845876, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49271, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41540, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:24:19.144177+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49271, "dest_port": 53}}'); INSERT INTO alerts VALUES(3230,1773077069.173444986,'{"timestamp": "2026-03-09T18:24:29.173445+0100", "flow_id": 1589366735065762, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64891, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42170, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:24:29.173445+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64891, "dest_port": 53}}'); INSERT INTO alerts VALUES(3231,1773077070.960896015,'{"timestamp": "2026-03-09T18:24:30.960896+0100", "flow_id": 1875219190829023, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50101, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6134, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:24:30.960896+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50101, "dest_port": 53}}'); INSERT INTO alerts VALUES(3232,1773077070.960896969,'{"timestamp": "2026-03-09T18:24:30.960897+0100", "flow_id": 1875221950693131, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62077, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41686, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:24:30.960897+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62077, "dest_port": 53}}'); INSERT INTO alerts VALUES(3233,1773077071.605487108,'{"timestamp": "2026-03-09T18:24:31.605487+0100", "flow_id": 2037598961348946, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:24:31.605487+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3234,1773077081.059262037,'{"timestamp": "2026-03-09T18:24:41.059262+0100", "flow_id": 536007248266984, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65371, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33565, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:24:41.059262+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65371, "dest_port": 53}}'); INSERT INTO alerts VALUES(3235,1773077081.059262037,'{"timestamp": "2026-03-09T18:24:41.059262+0100", "flow_id": 536003396599602, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59595, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63522, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:24:41.059262+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59595, "dest_port": 53}}'); INSERT INTO alerts VALUES(3236,1773077081.059262037,'{"timestamp": "2026-03-09T18:24:41.059262+0100", "flow_id": 536004229338158, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51146, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27025, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:24:41.059262+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51146, "dest_port": 53}}'); INSERT INTO alerts VALUES(3237,1773077091.924596071,'{"timestamp": "2026-03-09T18:24:51.924596+0100", "flow_id": 874886669718794, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65366, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48769, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:24:51.924596+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65366, "dest_port": 53}}'); INSERT INTO alerts VALUES(3238,1773077091.924596071,'{"timestamp": "2026-03-09T18:24:51.924596+0100", "flow_id": 874885845736225, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60529, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23839, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:24:51.924596+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60529, "dest_port": 53}}'); INSERT INTO alerts VALUES(3239,1773077091.924597024,'{"timestamp": "2026-03-09T18:24:51.924597+0100", "flow_id": 874891112473147, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59526, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19636, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:24:51.924597+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59526, "dest_port": 53}}'); INSERT INTO alerts VALUES(3240,1773077102.767652988,'{"timestamp": "2026-03-09T18:25:02.767653+0100", "flow_id": 1889673060570694, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64094, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34122, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:25:02.767653+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64094, "dest_port": 53}}'); INSERT INTO alerts VALUES(3241,1773077102.767652988,'{"timestamp": "2026-03-09T18:25:02.767653+0100", "flow_id": 1889670291249413, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61363, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39909, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:25:02.767653+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61363, "dest_port": 53}}'); INSERT INTO alerts VALUES(3242,1773077102.767652988,'{"timestamp": "2026-03-09T18:25:02.767653+0100", "flow_id": 1889670245585381, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60448, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42584, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:25:02.767653+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60448, "dest_port": 53}}'); INSERT INTO alerts VALUES(3243,1773077102.922835112,'{"timestamp": "2026-03-09T18:25:02.922835+0100", "flow_id": 1711748382536018, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:25:02.922835+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3244,1773077113.37866497,'{"timestamp": "2026-03-09T18:25:13.378665+0100", "flow_id": 500458059893414, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55370, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35380, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:25:13.378665+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55370, "dest_port": 53}}'); INSERT INTO alerts VALUES(3245,1773077113.379055976,'{"timestamp": "2026-03-09T18:25:13.379056+0100", "flow_id": 502135478094220, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52669, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38103, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:25:13.379056+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52669, "dest_port": 53}}'); INSERT INTO alerts VALUES(3246,1773077113.379055976,'{"timestamp": "2026-03-09T18:25:13.379056+0100", "flow_id": 502134772582160, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57594, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59115, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:25:13.379056+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57594, "dest_port": 53}}'); INSERT INTO alerts VALUES(3247,1773077124.275322914,'{"timestamp": "2026-03-09T18:25:24.275323+0100", "flow_id": 1182504009645383, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55905, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32398, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:25:24.275323+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55905, "dest_port": 53}}'); INSERT INTO alerts VALUES(3248,1773077124.275322914,'{"timestamp": "2026-03-09T18:25:24.275323+0100", "flow_id": 1182507037155131, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63323, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61224, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:25:24.275323+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63323, "dest_port": 53}}'); INSERT INTO alerts VALUES(3249,1773077124.275324107,'{"timestamp": "2026-03-09T18:25:24.275324+0100", "flow_id": 1182510485837039, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61529, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7715, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:25:24.275324+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61529, "dest_port": 53}}'); INSERT INTO alerts VALUES(3250,1773077131.548693896,'{"timestamp": "2026-03-09T18:25:31.548694+0100", "flow_id": 949251067043409, "event_type": "alert", "src_ip": "147.185.132.122", "src_port": 49614, "dest_ip": "134.19.55.199", "dest_port": 29890, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:25:31.548694+0100", "src_ip": "147.185.132.122", "dest_ip": "134.19.55.199", "src_port": 49614, "dest_port": 29890}}'); INSERT INTO alerts VALUES(3251,1773077133.014879942,'{"timestamp": "2026-03-09T18:25:33.014880+0100", "flow_id": 1471286048534866, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:25:33.014880+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3252,1773077135.126852036,'{"timestamp": "2026-03-09T18:25:35.126852+0100", "flow_id": 2233675985495776, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61236, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33985, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:25:35.126852+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61236, "dest_port": 53}}'); INSERT INTO alerts VALUES(3253,1773077135.126852036,'{"timestamp": "2026-03-09T18:25:35.126852+0100", "flow_id": 2233675455861428, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50239, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:25:35.126852+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50239, "dest_port": 53}}'); INSERT INTO alerts VALUES(3254,1773077135.126852036,'{"timestamp": "2026-03-09T18:25:35.126852+0100", "flow_id": 2233678748951267, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56642, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1596, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:25:35.126852+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56642, "dest_port": 53}}'); INSERT INTO alerts VALUES(3255,1773077142.573415041,'{"timestamp": "2026-03-09T18:25:42.573415+0100", "flow_id": 1899852396197951, "event_type": "alert", "src_ip": "147.185.132.197", "src_port": 55399, "dest_ip": "134.19.55.199", "dest_port": 15070, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:25:42.573415+0100", "src_ip": "147.185.132.197", "dest_ip": "134.19.55.199", "src_port": 55399, "dest_port": 15070}}'); INSERT INTO alerts VALUES(3256,1773077145.778578042,'{"timestamp": "2026-03-09T18:25:45.778578+0100", "flow_id": 529220671814787, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61794, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1633, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:25:45.778578+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61794, "dest_port": 53}}'); INSERT INTO alerts VALUES(3257,1773077145.778578042,'{"timestamp": "2026-03-09T18:25:45.778578+0100", "flow_id": 529221110632471, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60007, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43729, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:25:45.778578+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60007, "dest_port": 53}}'); INSERT INTO alerts VALUES(3258,1773077145.779752969,'{"timestamp": "2026-03-09T18:25:45.779753+0100", "flow_id": 534263927492063, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50092, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:25:45.779753+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65111, "dest_port": 53}}'); INSERT INTO alerts VALUES(3259,1773077146.043153048,'{"timestamp": "2026-03-09T18:25:46.043153+0100", "flow_id": 748292027078821, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58913, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4441, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:25:46.043153+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58913, "dest_port": 53}}'); INSERT INTO alerts VALUES(3260,1773077146.043154001,'{"timestamp": "2026-03-09T18:25:46.043154+0100", "flow_id": 748297902864717, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64885, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29712, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:25:46.043154+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64885, "dest_port": 53}}'); INSERT INTO alerts VALUES(3261,1773077146.043154001,'{"timestamp": "2026-03-09T18:25:46.043154+0100", "flow_id": 748298677147399, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49754, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41743, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:25:46.043154+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49754, "dest_port": 53}}'); INSERT INTO alerts VALUES(3262,1773077146.043154001,'{"timestamp": "2026-03-09T18:25:46.043154+0100", "flow_id": 748299125955630, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61547, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57904, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:25:46.043154+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61547, "dest_port": 53}}'); INSERT INTO alerts VALUES(3263,1773077146.043154954,'{"timestamp": "2026-03-09T18:25:46.043155+0100", "flow_id": 748299901438422, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:25:46.043155+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65176, "dest_port": 53}}'); INSERT INTO alerts VALUES(3264,1773077146.043154954,'{"timestamp": "2026-03-09T18:25:46.043155+0100", "flow_id": 748302332886063, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:25:46.043155+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3265,1773077146.043154954,'{"timestamp": "2026-03-09T18:25:46.043155+0100", "flow_id": 748301983456963, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:25:46.043155+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3266,1773077146.043646098,'{"timestamp": "2026-03-09T18:25:46.043646+0100", "flow_id": 750411687345970, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50123, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22453, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:25:46.043646+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50123, "dest_port": 53}}'); INSERT INTO alerts VALUES(3267,1773077156.634222985,'{"timestamp": "2026-03-09T18:25:56.634223+0100", "flow_id": 1316595145632412, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31627, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:25:56.634223+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52048, "dest_port": 53}}'); INSERT INTO alerts VALUES(3268,1773077156.634222985,'{"timestamp": "2026-03-09T18:25:56.634223+0100", "flow_id": 1316593846145686, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63329, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36429, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:25:56.634223+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63329, "dest_port": 53}}'); INSERT INTO alerts VALUES(3269,1773077156.634222985,'{"timestamp": "2026-03-09T18:25:56.634223+0100", "flow_id": 1316595344401593, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61494, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18645, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:25:56.634223+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61494, "dest_port": 53}}'); INSERT INTO alerts VALUES(3270,1773077164.491921902,'{"timestamp": "2026-03-09T18:26:04.491922+0100", "flow_id": 1268366023668050, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:26:04.491922+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3271,1773077167.483664989,'{"timestamp": "2026-03-09T18:26:07.483665+0100", "flow_id": 2077328187720023, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50710, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:26:07.483665+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50710, "dest_port": 53}}'); INSERT INTO alerts VALUES(3272,1773077167.483664989,'{"timestamp": "2026-03-09T18:26:07.483665+0100", "flow_id": 2077327721704242, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55895, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65088, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:26:07.483665+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55895, "dest_port": 53}}'); INSERT INTO alerts VALUES(3273,1773077167.483664989,'{"timestamp": "2026-03-09T18:26:07.483665+0100", "flow_id": 2077326758385840, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53226, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60502, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:26:07.483665+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53226, "dest_port": 53}}'); INSERT INTO alerts VALUES(3274,1773077177.789938927,'{"timestamp": "2026-03-09T18:26:17.789939+0100", "flow_id": 296537896690287, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53283, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38550, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:26:17.789939+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53283, "dest_port": 53}}'); INSERT INTO alerts VALUES(3275,1773077189.358294011,'{"timestamp": "2026-03-09T18:26:29.358294+0100", "flow_id": 1538862626389072, "event_type": "alert", "src_ip": "43.228.157.12", "src_port": 44451, "dest_ip": "134.19.55.199", "dest_port": 9163, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:26:29.358294+0100", "src_ip": "43.228.157.12", "dest_ip": "134.19.55.199", "src_port": 44451, "dest_port": 9163}}'); INSERT INTO alerts VALUES(3276,1773077195.770524978,'{"timestamp": "2026-03-09T18:26:35.770525+0100", "flow_id": 1057581913682258, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:26:35.770525+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3277,1773077198.020479918,'{"timestamp": "2026-03-09T18:26:38.020480+0100", "flow_id": 1776813718689335, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49457, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 960, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:26:38.020480+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49457, "dest_port": 53}}'); INSERT INTO alerts VALUES(3278,1773077198.020479918,'{"timestamp": "2026-03-09T18:26:38.020480+0100", "flow_id": 1776813994372549, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64486, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53338, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:26:38.020480+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64486, "dest_port": 53}}'); INSERT INTO alerts VALUES(3279,1773077213.181411982,'{"timestamp": "2026-03-09T18:26:53.181412+0100", "flow_id": 1623586603039791, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:26:53.181412+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3280,1773077213.181411982,'{"timestamp": "2026-03-09T18:26:53.181412+0100", "flow_id": 1623586253610691, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:26:53.181412+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3281,1773077233.322660923,'{"timestamp": "2026-03-09T18:27:13.322661+0100", "flow_id": 541395691347060, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49578, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21689, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "contacts.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:27:13.322661+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49578, "dest_port": 53}}'); INSERT INTO alerts VALUES(3282,1773077233.678118944,'{"timestamp": "2026-03-09T18:27:13.678119+0100", "flow_id": 379225732737701, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57902, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32332, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "caldav.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T18:27:13.678119+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57902, "dest_port": 53}}'); INSERT INTO alerts VALUES(3283,1773077244.279604912,'{"timestamp": "2026-03-09T18:27:24.279605+0100", "flow_id": 1200897396603951, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:27:24.279605+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3284,1773077244.279606103,'{"timestamp": "2026-03-09T18:27:24.279606+0100", "flow_id": 1200901342142147, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:27:24.279606+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3285,1773077255.23119402,'{"timestamp": "2026-03-09T18:27:35.231194+0100", "flow_id": 2118872910918198, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52634, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55243, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:27:35.231194+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52634, "dest_port": 53}}'); INSERT INTO alerts VALUES(3286,1773077255.23119402,'{"timestamp": "2026-03-09T18:27:35.231194+0100", "flow_id": 2118874535606794, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50489, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34409, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:27:35.231194+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50489, "dest_port": 53}}'); INSERT INTO alerts VALUES(3287,1773077268.519304037,'{"timestamp": "2026-03-09T18:27:48.519304+0100", "flow_id": 1385970818167122, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:27:48.519304+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3288,1773077298.646061897,'{"timestamp": "2026-03-09T18:28:18.646062+0100", "flow_id": 804492375830866, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:28:18.646062+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3289,1773077320.796142101,'{"timestamp": "2026-03-09T18:28:40.796142+0100", "flow_id": 41707198250031, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:28:40.796142+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3290,1773077320.796143055,'{"timestamp": "2026-03-09T18:28:40.796143+0100", "flow_id": 41711143788227, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:28:40.796143+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3291,1773077324.000267983,'{"timestamp": "2026-03-09T18:28:44.000268+0100", "flow_id": 1127051592436182, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:28:44.000268+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65176, "dest_port": 53}}'); INSERT INTO alerts VALUES(3292,1773077324.000268937,'{"timestamp": "2026-03-09T18:28:44.000269+0100", "flow_id": 1127058844368690, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50123, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22453, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:28:44.000269+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50123, "dest_port": 53}}'); INSERT INTO alerts VALUES(3293,1773077328.762514115,'{"timestamp": "2026-03-09T18:28:48.762514+0100", "flow_id": 178750000542034, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:28:48.762514+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3294,1773077330.489953041,'{"timestamp": "2026-03-09T18:28:50.489953+0100", "flow_id": 696960481159050, "event_type": "alert", "src_ip": "162.217.98.180", "src_port": 50413, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 414, "bytes_toclient": 0, "start": "2026-03-09T18:28:50.489953+0100", "src_ip": "162.217.98.180", "dest_ip": "134.19.55.199", "src_port": 50413, "dest_port": 5060}}'); INSERT INTO alerts VALUES(3295,1773077359.557250977,'{"timestamp": "2026-03-09T18:29:19.557251+0100", "flow_id": 2111901895569746, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:29:19.557251+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3296,1773077387.865366936,'{"timestamp": "2026-03-09T18:29:47.865367+0100", "flow_id": 901973831289302, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:29:47.865367+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65176, "dest_port": 53}}'); INSERT INTO alerts VALUES(3297,1773077387.865367889,'{"timestamp": "2026-03-09T18:29:47.865368+0100", "flow_id": 901981083221810, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50123, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22453, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:29:47.865368+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50123, "dest_port": 53}}'); INSERT INTO alerts VALUES(3298,1773077389.867284059,'{"timestamp": "2026-03-09T18:29:49.867284+0100", "flow_id": 1473158654275922, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:29:49.867284+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3299,1773077394.072611093,'{"timestamp": "2026-03-09T18:29:54.072611+0100", "flow_id": 593340761243159, "event_type": "alert", "src_ip": "3.111.239.186", "src_port": 60382, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:29:54.072611+0100", "src_ip": "3.111.239.186", "dest_ip": "134.19.55.199", "src_port": 60382, "dest_port": 5432}}'); INSERT INTO alerts VALUES(3300,1773077395.113555909,'{"timestamp": "2026-03-09T18:29:55.113556+0100", "flow_id": 593340761243159, "event_type": "alert", "src_ip": "3.111.239.186", "src_port": 60382, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 120, "bytes_toclient": 0, "start": "2026-03-09T18:29:54.072611+0100", "src_ip": "3.111.239.186", "dest_ip": "134.19.55.199", "src_port": 60382, "dest_port": 5432}}'); INSERT INTO alerts VALUES(3301,1773077417.884519101,'{"timestamp": "2026-03-09T18:30:17.884519+0100", "flow_id": 421281091520982, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:30:17.884519+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65176, "dest_port": 53}}'); INSERT INTO alerts VALUES(3302,1773077417.884519101,'{"timestamp": "2026-03-09T18:30:17.884519+0100", "flow_id": 421284048486194, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50123, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22453, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:30:17.884519+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50123, "dest_port": 53}}'); INSERT INTO alerts VALUES(3303,1773077420.279616117,'{"timestamp": "2026-03-09T18:30:20.279616+0100", "flow_id": 1200943627055442, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:30:20.279616+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3304,1773077440.914444923,'{"timestamp": "2026-03-09T18:30:40.914445+0100", "flow_id": 268339737558063, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:30:40.914445+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3305,1773077440.914446115,'{"timestamp": "2026-03-09T18:30:40.914446+0100", "flow_id": 268343683096259, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:30:40.914446+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3306,1773077447.021147013,'{"timestamp": "2026-03-09T18:30:47.021147+0100", "flow_id": 2061153010702782, "event_type": "alert", "src_ip": "193.163.125.197", "src_port": 34423, "dest_ip": "134.19.55.199", "dest_port": 20019, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:30:47.021147+0100", "src_ip": "193.163.125.197", "dest_ip": "134.19.55.199", "src_port": 34423, "dest_port": 20019}}'); INSERT INTO alerts VALUES(3307,1773077451.600583077,'{"timestamp": "2026-03-09T18:30:51.600583+0100", "flow_id": 890636534886738, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:30:51.600583+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3308,1773077496.289453984,'{"timestamp": "2026-03-09T18:31:36.289454+0100", "flow_id": 117298368726138, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 52807, "dest_ip": "134.19.55.199", "dest_port": 4949, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:31:36.289454+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 52807, "dest_port": 4949}}'); INSERT INTO alerts VALUES(3309,1773077496.289453984,'{"timestamp": "2026-03-09T18:31:36.289454+0100", "flow_id": 117298368726138, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 52807, "dest_ip": "134.19.55.199", "dest_port": 4949, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:31:36.289454+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 52807, "dest_port": 4949}}'); INSERT INTO alerts VALUES(3310,1773077511.415373086,'{"timestamp": "2026-03-09T18:31:51.415373+0100", "flow_id": 2065491493157935, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:31:51.415373+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3311,1773077511.415373086,'{"timestamp": "2026-03-09T18:31:51.415373+0100", "flow_id": 2065491143728835, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:31:51.415373+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3312,1773077524.844193936,'{"timestamp": "2026-03-09T18:32:04.844194+0100", "flow_id": 1373987859411282, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:32:04.844194+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3313,1773077524.844193936,'{"timestamp": "2026-03-09T18:32:04.844194+0100", "flow_id": 1373986019598272, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64378, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14433, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:32:04.844194+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64378, "dest_port": 53}}'); INSERT INTO alerts VALUES(3314,1773077540.413212061,'{"timestamp": "2026-03-09T18:32:20.413212+0100", "flow_id": 1211785883229142, "event_type": "alert", "src_ip": "176.65.139.31", "src_port": 59183, "dest_ip": "134.19.55.199", "dest_port": 389, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ldap", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-09T18:32:20.413212+0100", "src_ip": "176.65.139.31", "dest_ip": "134.19.55.199", "src_port": 59183, "dest_port": 389}}'); INSERT INTO alerts VALUES(3315,1773077542.035157919,'{"timestamp": "2026-03-09T18:32:22.035158+0100", "flow_id": 1839855386262575, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:32:22.035158+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3316,1773077542.035157919,'{"timestamp": "2026-03-09T18:32:22.035158+0100", "flow_id": 1839855036833475, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:32:22.035158+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3317,1773077542.035157919,'{"timestamp": "2026-03-09T18:32:22.035158+0100", "flow_id": 1839852954814934, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:32:22.035158+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65176, "dest_port": 53}}'); INSERT INTO alerts VALUES(3318,1773077542.035159111,'{"timestamp": "2026-03-09T18:32:22.035159+0100", "flow_id": 1839860206747442, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50123, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22453, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:32:22.035159+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50123, "dest_port": 53}}'); INSERT INTO alerts VALUES(3319,1773077550.791374921,'{"timestamp": "2026-03-09T18:32:30.791375+0100", "flow_id": 1710084043847946, "event_type": "alert", "src_ip": "205.210.31.132", "src_port": 53811, "dest_ip": "134.19.55.199", "dest_port": 2601, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:32:30.791375+0100", "src_ip": "205.210.31.132", "dest_ip": "134.19.55.199", "src_port": 53811, "dest_port": 2601}}'); INSERT INTO alerts VALUES(3320,1773077563.632957936,'{"timestamp": "2026-03-09T18:32:43.632958+0100", "flow_id": 1029686396038356, "event_type": "alert", "src_ip": "167.94.138.147", "src_port": 4729, "dest_ip": "134.19.55.199", "dest_port": 1024, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:32:43.632958+0100", "src_ip": "167.94.138.147", "dest_ip": "134.19.55.199", "src_port": 4729, "dest_port": 1024}}'); INSERT INTO alerts VALUES(3321,1773077573.451009989,'{"timestamp": "2026-03-09T18:32:53.451010+0100", "flow_id": 1655601289264175, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:32:53.451010+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3322,1773077573.451010942,'{"timestamp": "2026-03-09T18:32:53.451011+0100", "flow_id": 1655605234802371, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:32:53.451011+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3323,1773077573.451010942,'{"timestamp": "2026-03-09T18:32:53.451011+0100", "flow_id": 1655603152783830, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:32:53.451011+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65176, "dest_port": 53}}'); INSERT INTO alerts VALUES(3324,1773077583.487086058,'{"timestamp": "2026-03-09T18:33:03.487086+0100", "flow_id": 2092021898589138, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54675, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52481, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:33:03.487086+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54675, "dest_port": 53}}'); INSERT INTO alerts VALUES(3325,1773077598.963031053,'{"timestamp": "2026-03-09T18:33:18.963031+0100", "flow_id": 1884390263640066, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49805, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19120, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:33:18.963031+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49805, "dest_port": 53}}'); INSERT INTO alerts VALUES(3326,1773077604.418903112,'{"timestamp": "2026-03-09T18:33:24.418903+0100", "flow_id": 1236227797580847, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:33:24.418903+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3327,1773077604.418904066,'{"timestamp": "2026-03-09T18:33:24.418904+0100", "flow_id": 1236231743119043, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:33:24.418904+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3328,1773077604.418904066,'{"timestamp": "2026-03-09T18:33:24.418904+0100", "flow_id": 1236229661100502, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:33:24.418904+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65176, "dest_port": 53}}'); INSERT INTO alerts VALUES(3329,1773077616.470112085,'{"timestamp": "2026-03-09T18:33:36.470112+0100", "flow_id": 48790897008892, "event_type": "alert", "src_ip": "167.94.138.139", "src_port": 60008, "dest_ip": "134.19.55.199", "dest_port": 22922, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:33:36.470112+0100", "src_ip": "167.94.138.139", "dest_ip": "134.19.55.199", "src_port": 60008, "dest_port": 22922}}'); INSERT INTO alerts VALUES(3330,1773077621.203680993,'{"timestamp": "2026-03-09T18:33:41.203681+0100", "flow_id": 1437754422931352, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53897, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31015, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:33:41.203681+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53897, "dest_port": 53}}'); INSERT INTO alerts VALUES(3331,1773077621.203974008,'{"timestamp": "2026-03-09T18:33:41.203974+0100", "flow_id": 1439013504449012, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51699, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41555, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:33:41.203974+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51699, "dest_port": 53}}'); INSERT INTO alerts VALUES(3332,1773077627.964428901,'{"timestamp": "2026-03-09T18:33:47.964429+0100", "flow_id": 1045966482300864, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64378, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14433, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:33:47.964429+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64378, "dest_port": 53}}'); INSERT INTO alerts VALUES(3333,1773077627.964430093,'{"timestamp": "2026-03-09T18:33:47.964430+0100", "flow_id": 1045970945200393, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55846, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10035, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:33:47.964430+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55846, "dest_port": 53}}'); INSERT INTO alerts VALUES(3334,1773077628.606072902,'{"timestamp": "2026-03-09T18:33:48.606073+0100", "flow_id": 1195691665912930, "event_type": "alert", "src_ip": "193.163.125.199", "src_port": 35930, "dest_ip": "134.19.55.199", "dest_port": 7081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:33:48.606073+0100", "src_ip": "193.163.125.199", "dest_ip": "134.19.55.199", "src_port": 35930, "dest_port": 7081}}'); INSERT INTO alerts VALUES(3335,1773077631.511048079,'{"timestamp": "2026-03-09T18:33:51.511048+0100", "flow_id": 2194935101093311, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61143, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17635, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:33:51.511048+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61143, "dest_port": 53}}'); INSERT INTO alerts VALUES(3336,1773077633.576303006,'{"timestamp": "2026-03-09T18:33:53.576303+0100", "flow_id": 504881972189504, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54003, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54600, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:33:53.576303+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54003, "dest_port": 53}}'); INSERT INTO alerts VALUES(3337,1773077634.606829881,'{"timestamp": "2026-03-09T18:33:54.606830+0100", "flow_id": 635990801615318, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:33:54.606830+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65176, "dest_port": 53}}'); INSERT INTO alerts VALUES(3338,1773077665.830749988,'{"timestamp": "2026-03-09T18:34:25.830750+0100", "flow_id": 471819971693014, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:34:25.830750+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65176, "dest_port": 53}}'); INSERT INTO alerts VALUES(3339,1773077680.459832906,'{"timestamp": "2026-03-09T18:34:40.459833+0100", "flow_id": 4645925452847, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:34:40.459833+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3340,1773077680.459835053,'{"timestamp": "2026-03-09T18:34:40.459835+0100", "flow_id": 4654165958339, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:34:40.459835+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3341,1773077696.75876093,'{"timestamp": "2026-03-09T18:34:56.758761+0100", "flow_id": 162629571021270, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:34:56.758761+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65176, "dest_port": 53}}'); INSERT INTO alerts VALUES(3342,1773077707.436517001,'{"timestamp": "2026-03-09T18:35:07.436517+0100", "flow_id": 1030403102276242, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 28812, "dest_ip": "134.19.55.199", "dest_port": 42100, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:35:07.436517+0100", "src_ip": "167.94.146.40", "dest_ip": "134.19.55.199", "src_port": 28812, "dest_port": 42100}}'); INSERT INTO alerts VALUES(3343,1773077710.680885076,'{"timestamp": "2026-03-09T18:35:10.680885+0100", "flow_id": 1798481966300207, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:35:10.680885+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3344,1773077710.68088603,'{"timestamp": "2026-03-09T18:35:10.680886+0100", "flow_id": 1798485911838403, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:35:10.680886+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3345,1773077714.790769101,'{"timestamp": "2026-03-09T18:35:14.790769+0100", "flow_id": 581577395167412, "event_type": "alert", "src_ip": "91.196.152.164", "src_port": 5098, "dest_ip": "134.19.55.199", "dest_port": 1883, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:35:14.790769+0100", "src_ip": "91.196.152.164", "dest_ip": "134.19.55.199", "src_port": 5098, "dest_port": 1883}}'); INSERT INTO alerts VALUES(3346,1773077716.346004963,'{"timestamp": "2026-03-09T18:35:16.346005+0100", "flow_id": 1204606824444310, "event_type": "alert", "src_ip": "193.163.125.213", "src_port": 34506, "dest_ip": "134.19.55.199", "dest_port": 9200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:35:16.346005+0100", "src_ip": "193.163.125.213", "dest_ip": "134.19.55.199", "src_port": 34506, "dest_port": 9200}}'); INSERT INTO alerts VALUES(3347,1773077717.9675169,'{"timestamp": "2026-03-09T18:35:17.967517+0100", "flow_id": 1622179462664457, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55846, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10035, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:35:17.967517+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55846, "dest_port": 53}}'); INSERT INTO alerts VALUES(3348,1773077717.967518092,'{"timestamp": "2026-03-09T18:35:17.967518+0100", "flow_id": 1622186754990118, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55372, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56733, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:35:17.967518+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55372, "dest_port": 53}}'); INSERT INTO alerts VALUES(3349,1773077727.343544961,'{"timestamp": "2026-03-09T18:35:27.343545+0100", "flow_id": 2038465127483862, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:35:27.343545+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65176, "dest_port": 53}}'); INSERT INTO alerts VALUES(3350,1773077727.88463211,'{"timestamp": "2026-03-09T18:35:27.884632+0100", "flow_id": 2110616233231471, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 60326, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:35:27.884632+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 60326}}'); INSERT INTO alerts VALUES(3351,1773077727.88463211,'{"timestamp": "2026-03-09T18:35:27.884632+0100", "flow_id": 2110616233231471, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 60326, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:35:27.884632+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 60326}}'); INSERT INTO alerts VALUES(3352,1773077742.033041,'{"timestamp": "2026-03-09T18:35:42.033041+0100", "flow_id": 1830762940496943, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:35:42.033041+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3353,1773077742.033041,'{"timestamp": "2026-03-09T18:35:42.033041+0100", "flow_id": 1830762591067843, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:35:42.033041+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3354,1773077759.854042054,'{"timestamp": "2026-03-09T18:35:59.854042+0100", "flow_id": 1979234239237198, "event_type": "alert", "src_ip": "176.65.149.233", "src_port": 43905, "dest_ip": "134.19.55.199", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:35:59.854042+0100", "src_ip": "176.65.149.233", "dest_ip": "134.19.55.199", "src_port": 43905, "dest_port": 8088}}'); INSERT INTO alerts VALUES(3355,1773077763.937225104,'{"timestamp": "2026-03-09T18:36:03.937225+0100", "flow_id": 929129357271078, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55372, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56733, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:36:03.937225+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55372, "dest_port": 53}}'); INSERT INTO alerts VALUES(3356,1773077763.937226057,'{"timestamp": "2026-03-09T18:36:03.937226+0100", "flow_id": 929130413659440, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59245, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48023, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:36:03.937226+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59245, "dest_port": 53}}'); INSERT INTO alerts VALUES(3357,1773077773.001939058,'{"timestamp": "2026-03-09T18:36:13.001939+0100", "flow_id": 1415705427752619, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60925, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:36:13.001939+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59747, "dest_port": 53}}'); INSERT INTO alerts VALUES(3358,1773077800.714525939,'{"timestamp": "2026-03-09T18:36:40.714526+0100", "flow_id": 254119266057174, "event_type": "alert", "src_ip": "176.65.148.204", "src_port": 42706, "dest_ip": "134.19.55.199", "dest_port": 25591, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:36:40.714526+0100", "src_ip": "176.65.148.204", "dest_ip": "134.19.55.199", "src_port": 42706, "dest_port": 25591}}'); INSERT INTO alerts VALUES(3359,1773077800.714525939,'{"timestamp": "2026-03-09T18:36:40.714526+0100", "flow_id": 254119266057174, "event_type": "alert", "src_ip": "176.65.148.204", "src_port": 42706, "dest_ip": "134.19.55.199", "dest_port": 25591, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:36:40.714526+0100", "src_ip": "176.65.148.204", "dest_ip": "134.19.55.199", "src_port": 42706, "dest_port": 25591}}'); INSERT INTO alerts VALUES(3360,1773077803.828521967,'{"timestamp": "2026-03-09T18:36:43.828522+0100", "flow_id": 1025201523331405, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65531, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45570, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:36:43.828522+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65531, "dest_port": 53}}'); INSERT INTO alerts VALUES(3361,1773077810.230197907,'{"timestamp": "2026-03-09T18:36:50.230198+0100", "flow_id": 618606743211265, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 58168, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:36:50.209566+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 58168, "dest_port": 853}}'); INSERT INTO alerts VALUES(3362,1773077810.247374058,'{"timestamp": "2026-03-09T18:36:50.247374+0100", "flow_id": 685632758734586, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 60442, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:36:50.225172+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 60442, "dest_port": 853}}'); INSERT INTO alerts VALUES(3363,1773077853.888910056,'{"timestamp": "2026-03-09T18:37:33.888910+0100", "flow_id": 1566043828029932, "event_type": "alert", "src_ip": "45.142.154.86", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 35342, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:37:33.888910+0100", "src_ip": "45.142.154.86", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 35342}}'); INSERT INTO alerts VALUES(3364,1773077857.67326498,'{"timestamp": "2026-03-09T18:37:37.673265+0100", "flow_id": 358380626741082, "event_type": "alert", "src_ip": "147.185.132.51", "src_port": 53063, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:37:37.673265+0100", "src_ip": "147.185.132.51", "dest_ip": "134.19.55.199", "src_port": 53063, "dest_port": 5432}}'); INSERT INTO alerts VALUES(3365,1773077857.67326498,'{"timestamp": "2026-03-09T18:37:37.673265+0100", "flow_id": 358380626741082, "event_type": "alert", "src_ip": "147.185.132.51", "src_port": 53063, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:37:37.673265+0100", "src_ip": "147.185.132.51", "dest_ip": "134.19.55.199", "src_port": 53063, "dest_port": 5432}}'); INSERT INTO alerts VALUES(3366,1773077874.130307912,'{"timestamp": "2026-03-09T18:37:54.130308+0100", "flow_id": 841144518742333, "event_type": "alert", "src_ip": "45.153.34.187", "src_port": 59236, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:37:54.130308+0100", "src_ip": "45.153.34.187", "dest_ip": "134.19.55.199", "src_port": 59236, "dest_port": 80}}'); INSERT INTO alerts VALUES(3367,1773077891.773890973,'{"timestamp": "2026-03-09T18:38:11.773891+0100", "flow_id": 1072039787789359, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:38:11.773891+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63596, "dest_port": 53}}'); INSERT INTO alerts VALUES(3368,1773077891.773891925,'{"timestamp": "2026-03-09T18:38:11.773892+0100", "flow_id": 1072043733327555, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22360, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:38:11.773892+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56572, "dest_port": 53}}'); INSERT INTO alerts VALUES(3369,1773077891.773891925,'{"timestamp": "2026-03-09T18:38:11.773892+0100", "flow_id": 1072041651309014, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:38:11.773892+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65176, "dest_port": 53}}'); INSERT INTO alerts VALUES(3370,1773077891.773891925,'{"timestamp": "2026-03-09T18:38:11.773892+0100", "flow_id": 1072042994204019, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55114, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53930, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:38:11.773892+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55114, "dest_port": 53}}'); INSERT INTO alerts VALUES(3371,1773077891.773893118,'{"timestamp": "2026-03-09T18:38:11.773893+0100", "flow_id": 1072049260698549, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55015, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51704, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:38:11.773893+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55015, "dest_port": 53}}'); INSERT INTO alerts VALUES(3372,1773077891.773893118,'{"timestamp": "2026-03-09T18:38:11.773893+0100", "flow_id": 1072048631285022, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54976, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45553, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:38:11.773893+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54976, "dest_port": 53}}'); INSERT INTO alerts VALUES(3373,1773077891.804264069,'{"timestamp": "2026-03-09T18:38:11.804264+0100", "flow_id": 921015809229820, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52988, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3060, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:38:11.804264+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52988, "dest_port": 53}}'); INSERT INTO alerts VALUES(3374,1773077938.188950061,'{"timestamp": "2026-03-09T18:38:58.188950+0100", "flow_id": 811537987416237, "event_type": "alert", "src_ip": "205.210.31.129", "src_port": 54995, "dest_ip": "134.19.55.199", "dest_port": 1967, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 80, "bytes_toclient": 0, "start": "2026-03-09T18:38:58.188950+0100", "src_ip": "205.210.31.129", "dest_ip": "134.19.55.199", "src_port": 54995, "dest_port": 1967}}'); INSERT INTO alerts VALUES(3375,1773077962.407326937,'{"timestamp": "2026-03-09T18:39:22.407327+0100", "flow_id": 623559191356012, "event_type": "alert", "src_ip": "193.163.125.198", "src_port": 37481, "dest_ip": "134.19.55.199", "dest_port": 9300, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:39:22.407327+0100", "src_ip": "193.163.125.198", "dest_ip": "134.19.55.199", "src_port": 37481, "dest_port": 9300}}'); INSERT INTO alerts VALUES(3376,1773078011.469067096,'{"timestamp": "2026-03-09T18:40:11.469067+0100", "flow_id": 888729809038592, "event_type": "alert", "src_ip": "64.95.96.68", "src_port": 5246, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-09T18:40:11.469067+0100", "src_ip": "64.95.96.68", "dest_ip": "134.19.55.199", "src_port": 5246, "dest_port": 5060}}'); INSERT INTO alerts VALUES(3377,1773078011.469067096,'{"timestamp": "2026-03-09T18:40:11.469067+0100", "flow_id": 888729809038592, "event_type": "alert", "src_ip": "64.95.96.68", "src_port": 5246, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-09T18:40:11.469067+0100", "src_ip": "64.95.96.68", "dest_ip": "134.19.55.199", "src_port": 5246, "dest_port": 5060}}'); INSERT INTO alerts VALUES(3378,1773078012.543098926,'{"timestamp": "2026-03-09T18:40:12.543099+0100", "flow_id": 1206694378579229, "event_type": "alert", "src_ip": "64.95.96.69", "src_port": 5238, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-09T18:40:12.543099+0100", "src_ip": "64.95.96.69", "dest_ip": "134.19.55.199", "src_port": 5238, "dest_port": 5060}}'); INSERT INTO alerts VALUES(3379,1773078012.543098926,'{"timestamp": "2026-03-09T18:40:12.543099+0100", "flow_id": 1206694378579229, "event_type": "alert", "src_ip": "64.95.96.69", "src_port": 5238, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 432, "bytes_toclient": 0, "start": "2026-03-09T18:40:12.543099+0100", "src_ip": "64.95.96.69", "dest_ip": "134.19.55.199", "src_port": 5238, "dest_port": 5060}}'); INSERT INTO alerts VALUES(3380,1773078012.594069004,'{"timestamp": "2026-03-09T18:40:12.594069+0100", "flow_id": 1144135065289724, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52988, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3060, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:40:12.594069+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52988, "dest_port": 53}}'); INSERT INTO alerts VALUES(3381,1773078012.594069958,'{"timestamp": "2026-03-09T18:40:12.594070+0100", "flow_id": 1144138315234675, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55114, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53930, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:40:12.594070+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55114, "dest_port": 53}}'); INSERT INTO alerts VALUES(3382,1773078012.594069958,'{"timestamp": "2026-03-09T18:40:12.594070+0100", "flow_id": 1144140286761909, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55015, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51704, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:40:12.594070+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55015, "dest_port": 53}}'); INSERT INTO alerts VALUES(3383,1773078012.594070911,'{"timestamp": "2026-03-09T18:40:12.594071+0100", "flow_id": 1144143952315678, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54976, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45553, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:40:12.594071+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54976, "dest_port": 53}}'); INSERT INTO alerts VALUES(3384,1773078012.594070911,'{"timestamp": "2026-03-09T18:40:12.594071+0100", "flow_id": 1144140994028147, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51807, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27628, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:40:12.594071+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51807, "dest_port": 53}}'); INSERT INTO alerts VALUES(3385,1773078012.594070911,'{"timestamp": "2026-03-09T18:40:12.594071+0100", "flow_id": 1144143731995549, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62879, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29327, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:40:12.594071+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62879, "dest_port": 53}}'); INSERT INTO alerts VALUES(3386,1773078012.594070911,'{"timestamp": "2026-03-09T18:40:12.594071+0100", "flow_id": 1144141792861703, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53297, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40785, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:40:12.594071+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53297, "dest_port": 53}}'); INSERT INTO alerts VALUES(3387,1773078012.594593048,'{"timestamp": "2026-03-09T18:40:12.594593+0100", "flow_id": 1146384985609910, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55506, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48369, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:40:12.594593+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55506, "dest_port": 53}}'); INSERT INTO alerts VALUES(3388,1773078014.523941993,'{"timestamp": "2026-03-09T18:40:14.523942+0100", "flow_id": 1968841380902571, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60925, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:40:14.523942+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59747, "dest_port": 53}}'); INSERT INTO alerts VALUES(3389,1773078039.986433029,'{"timestamp": "2026-03-09T18:40:39.986433+0100", "flow_id": 1984897759607210, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 34420, "dest_ip": "134.19.55.199", "dest_port": 8064, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400037, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 38", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T18:40:39.986433+0100", "src_ip": "192.109.200.219", "dest_ip": "134.19.55.199", "src_port": 34420, "dest_port": 8064}}'); INSERT INTO alerts VALUES(3390,1773078039.986433029,'{"timestamp": "2026-03-09T18:40:39.986433+0100", "flow_id": 1984897759607210, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 34420, "dest_ip": "134.19.55.199", "dest_port": 8064, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500020, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 11", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T18:40:39.986433+0100", "src_ip": "192.109.200.219", "dest_ip": "134.19.55.199", "src_port": 34420, "dest_port": 8064}}'); INSERT INTO alerts VALUES(3391,1773078045.349947929,'{"timestamp": "2026-03-09T18:40:45.349948+0100", "flow_id": 1503017817913003, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60925, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:40:45.349948+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59747, "dest_port": 53}}'); INSERT INTO alerts VALUES(3392,1773078057.459815025,'{"timestamp": "2026-03-09T18:40:57.459815+0100", "flow_id": 473177093954070, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 33658, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:40:57.437850+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 33658, "dest_port": 853}}'); INSERT INTO alerts VALUES(3393,1773078057.462547063,'{"timestamp": "2026-03-09T18:40:57.462547+0100", "flow_id": 471440235239180, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 51670, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:40:57.437445+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 51670, "dest_port": 853}}'); INSERT INTO alerts VALUES(3394,1773078112.038150073,'{"timestamp": "2026-03-09T18:41:52.038150+0100", "flow_id": 163853333881916, "event_type": "alert", "src_ip": "88.210.63.190", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44438, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:41:52.038150+0100", "src_ip": "88.210.63.190", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44438}}'); INSERT INTO alerts VALUES(3395,1773078204.602226972,'{"timestamp": "2026-03-09T18:43:24.602227+0100", "flow_id": 1179171769218599, "event_type": "alert", "src_ip": "192.109.200.219", "src_port": 43839, "dest_ip": "134.19.55.199", "dest_port": 10045, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500020, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 11", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T18:43:24.602227+0100", "src_ip": "192.109.200.219", "dest_ip": "134.19.55.199", "src_port": 43839, "dest_port": 10045}}'); INSERT INTO alerts VALUES(3396,1773078219.699117898,'{"timestamp": "2026-03-09T18:43:39.699118+0100", "flow_id": 1032365593622474, "event_type": "alert", "src_ip": "193.163.125.191", "src_port": 37320, "dest_ip": "134.19.55.199", "dest_port": 1129, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:43:39.699118+0100", "src_ip": "193.163.125.191", "dest_ip": "134.19.55.199", "src_port": 37320, "dest_port": 1129}}'); INSERT INTO alerts VALUES(3397,1773078233.979306937,'{"timestamp": "2026-03-09T18:43:53.979307+0100", "flow_id": 546917407541662, "event_type": "alert", "src_ip": "195.184.76.221", "src_port": 28932, "dest_ip": "134.19.55.199", "dest_port": 5362, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:43:53.979307+0100", "src_ip": "195.184.76.221", "dest_ip": "134.19.55.199", "src_port": 28932, "dest_port": 5362}}'); INSERT INTO alerts VALUES(3398,1773078243.339857102,'{"timestamp": "2026-03-09T18:44:03.339857+0100", "flow_id": 896726838304100, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49853, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64733, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:44:03.339857+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49853, "dest_port": 53}}'); INSERT INTO alerts VALUES(3399,1773078243.339858056,'{"timestamp": "2026-03-09T18:44:03.339858+0100", "flow_id": 896733032566758, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61225, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5343, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:44:03.339858+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61225, "dest_port": 53}}'); INSERT INTO alerts VALUES(3400,1773078246.66485691,'{"timestamp": "2026-03-09T18:44:06.664857+0100", "flow_id": 1729639525753459, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51807, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27628, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:44:06.664857+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51807, "dest_port": 53}}'); INSERT INTO alerts VALUES(3401,1773078246.66485691,'{"timestamp": "2026-03-09T18:44:06.664857+0100", "flow_id": 1729642263720861, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62879, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29327, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:44:06.664857+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62879, "dest_port": 53}}'); INSERT INTO alerts VALUES(3402,1773078246.66485691,'{"timestamp": "2026-03-09T18:44:06.664857+0100", "flow_id": 1729640324587015, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53297, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40785, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:44:06.664857+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53297, "dest_port": 53}}'); INSERT INTO alerts VALUES(3403,1773078246.66485691,'{"timestamp": "2026-03-09T18:44:06.664857+0100", "flow_id": 1729641544406710, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55506, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48369, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:44:06.664857+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55506, "dest_port": 53}}'); INSERT INTO alerts VALUES(3404,1773078246.664858103,'{"timestamp": "2026-03-09T18:44:06.664858+0100", "flow_id": 1729646012304026, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60013, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3339, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:44:06.664858+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60013, "dest_port": 53}}'); INSERT INTO alerts VALUES(3405,1773078246.664858103,'{"timestamp": "2026-03-09T18:44:06.664858+0100", "flow_id": 1729645722463374, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64877, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19660, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:44:06.664858+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64877, "dest_port": 53}}'); INSERT INTO alerts VALUES(3406,1773078246.664858103,'{"timestamp": "2026-03-09T18:44:06.664858+0100", "flow_id": 1729646752187171, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49711, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:44:06.664858+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3407,1773078246.664858103,'{"timestamp": "2026-03-09T18:44:06.664858+0100", "flow_id": 1729647564712299, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55612, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2203, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:44:06.664858+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55612, "dest_port": 53}}'); INSERT INTO alerts VALUES(3408,1773078281.050239086,'{"timestamp": "2026-03-09T18:44:41.050239+0100", "flow_id": 497252441306795, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60925, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:44:41.050239+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59747, "dest_port": 53}}'); INSERT INTO alerts VALUES(3409,1773078330.533945084,'{"timestamp": "2026-03-09T18:45:30.533945+0100", "flow_id": 604430739885097, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56620, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35559, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:45:30.533945+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56620, "dest_port": 53}}'); INSERT INTO alerts VALUES(3410,1773078330.535248994,'{"timestamp": "2026-03-09T18:45:30.535249+0100", "flow_id": 610028758509449, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58913, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1328, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:45:30.535249+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58913, "dest_port": 53}}'); INSERT INTO alerts VALUES(3411,1773078407.358824014,'{"timestamp": "2026-03-09T18:46:47.358824+0100", "flow_id": 2008258642976922, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 50310, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:46:47.336512+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 50310, "dest_port": 853}}'); INSERT INTO alerts VALUES(3412,1773078448.685343981,'{"timestamp": "2026-03-09T18:47:28.685344+0100", "flow_id": 128780863052409, "event_type": "alert", "src_ip": "167.94.138.109", "src_port": 49222, "dest_ip": "134.19.55.199", "dest_port": 32384, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:47:28.685344+0100", "src_ip": "167.94.138.109", "dest_ip": "134.19.55.199", "src_port": 49222, "dest_port": 32384}}'); INSERT INTO alerts VALUES(3413,1773078458.792479992,'{"timestamp": "2026-03-09T18:47:38.792480+0100", "flow_id": 588927584996131, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 51465, "dest_ip": "134.19.55.199", "dest_port": 22022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:47:38.792480+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.55.199", "src_port": 51465, "dest_port": 22022}}'); INSERT INTO alerts VALUES(3414,1773078458.792479992,'{"timestamp": "2026-03-09T18:47:38.792480+0100", "flow_id": 588927584996131, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 51465, "dest_ip": "134.19.55.199", "dest_port": 22022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:47:38.792480+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.55.199", "src_port": 51465, "dest_port": 22022}}'); INSERT INTO alerts VALUES(3415,1773078465.417211056,'{"timestamp": "2026-03-09T18:47:45.417211+0100", "flow_id": 384535249173933, "event_type": "alert", "src_ip": "176.65.149.182", "src_port": 56576, "dest_ip": "134.19.55.199", "dest_port": 8128, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T18:47:45.417211+0100", "src_ip": "176.65.149.182", "dest_ip": "134.19.55.199", "src_port": 56576, "dest_port": 8128}}'); INSERT INTO alerts VALUES(3416,1773078512.417779923,'{"timestamp": "2026-03-09T18:48:32.417780+0100", "flow_id": 105502874502143, "event_type": "alert", "src_ip": "45.174.75.43", "src_port": 10000, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:48:32.417780+0100", "src_ip": "45.174.75.43", "dest_ip": "134.19.55.199", "src_port": 10000, "dest_port": 1433}}'); INSERT INTO alerts VALUES(3417,1773078512.417781114,'{"timestamp": "2026-03-09T18:48:32.417781+0100", "flow_id": 105502874502143, "event_type": "alert", "src_ip": "45.174.75.43", "src_port": 10000, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 80, "bytes_toclient": 0, "start": "2026-03-09T18:48:32.417780+0100", "src_ip": "45.174.75.43", "dest_ip": "134.19.55.199", "src_port": 10000, "dest_port": 1433}}'); INSERT INTO alerts VALUES(3418,1773078525.24070692,'{"timestamp": "2026-03-09T18:48:45.240707+0100", "flow_id": 1596780279399867, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64241, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37744, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:48:45.240707+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64241, "dest_port": 53}}'); INSERT INTO alerts VALUES(3419,1773078525.244252921,'{"timestamp": "2026-03-09T18:48:45.244253+0100", "flow_id": 1612011732326504, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49808, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50576, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:48:45.244253+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49808, "dest_port": 53}}'); INSERT INTO alerts VALUES(3420,1773078527.362584114,'{"timestamp": "2026-03-09T18:48:47.362584+0100", "flow_id": 2023646622279879, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 35550, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:48:47.340094+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 35550, "dest_port": 853}}'); INSERT INTO alerts VALUES(3421,1773078533.07698989,'{"timestamp": "2026-03-09T18:48:53.076990+0100", "flow_id": 1456570164901197, "event_type": "alert", "src_ip": "192.109.200.181", "src_port": 58589, "dest_ip": "134.19.55.199", "dest_port": 666, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400037, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 38", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:48:53.076990+0100", "src_ip": "192.109.200.181", "dest_ip": "134.19.55.199", "src_port": 58589, "dest_port": 666}}'); INSERT INTO alerts VALUES(3422,1773078541.87607193,'{"timestamp": "2026-03-09T18:49:01.876072+0100", "flow_id": 1510902986245146, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52803, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18013, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:49:01.876072+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52803, "dest_port": 53}}'); INSERT INTO alerts VALUES(3423,1773078547.68354392,'{"timestamp": "2026-03-09T18:49:07.683544+0100", "flow_id": 965474836972763, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 56264, "dest_ip": "134.19.55.199", "dest_port": 21526, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:49:07.683544+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 56264, "dest_port": 21526}}'); INSERT INTO alerts VALUES(3424,1773078559.021683932,'{"timestamp": "2026-03-09T18:49:19.021684+0100", "flow_id": 2063460324801434, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51832, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54869, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T18:49:19.021684+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51832, "dest_port": 53}}'); INSERT INTO alerts VALUES(3425,1773078568.143594981,'{"timestamp": "2026-03-09T18:49:28.143595+0100", "flow_id": 53787859128016, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65279, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2026888, "rev": 4, "signature": "ET INFO DNS Query for Suspicious .icu Domain", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["Medium"], "created_at": ["2019_02_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_11_21"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48933, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "prreqcroab.icu", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:49:28.143595+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65279, "dest_port": 53}}'); INSERT INTO alerts VALUES(3426,1773078647.362612963,'{"timestamp": "2026-03-09T18:50:47.362613+0100", "flow_id": 2026590461945794, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 38802, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:50:47.340780+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 38802, "dest_port": 853}}'); INSERT INTO alerts VALUES(3427,1773078687.142355919,'{"timestamp": "2026-03-09T18:51:27.142356+0100", "flow_id": 2018792860913208, "event_type": "alert", "src_ip": "88.210.63.193", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44311, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:51:27.142356+0100", "src_ip": "88.210.63.193", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44311}}'); INSERT INTO alerts VALUES(3428,1773078703.671924115,'{"timestamp": "2026-03-09T18:51:43.671924+0100", "flow_id": 2041468834400230, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62959, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4112, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:51:43.671924+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62959, "dest_port": 53}}'); INSERT INTO alerts VALUES(3429,1773078703.673002959,'{"timestamp": "2026-03-09T18:51:43.673003+0100", "flow_id": 2046101533848703, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57250, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63736, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:51:43.673003+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57250, "dest_port": 53}}'); INSERT INTO alerts VALUES(3430,1773078711.666383029,'{"timestamp": "2026-03-09T18:51:51.666383+0100", "flow_id": 2199898725884615, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39702, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:51:51.643275+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 39702, "dest_port": 853}}'); INSERT INTO alerts VALUES(3431,1773078715.30921793,'{"timestamp": "2026-03-09T18:51:55.309218+0100", "flow_id": 1046607406300617, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61211, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16915, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T18:51:55.309218+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61211, "dest_port": 53}}'); INSERT INTO alerts VALUES(3432,1773078746.254121065,'{"timestamp": "2026-03-09T18:52:26.254121+0100", "flow_id": 809969779138701, "event_type": "alert", "src_ip": "71.6.232.27", "src_port": 58919, "dest_ip": "134.19.55.199", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:52:26.254121+0100", "src_ip": "71.6.232.27", "dest_ip": "134.19.55.199", "src_port": 58919, "dest_port": 161}}'); INSERT INTO alerts VALUES(3433,1773078757.26272893,'{"timestamp": "2026-03-09T18:52:37.262729+0100", "flow_id": 1409889702243470, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64877, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19660, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:52:37.262729+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64877, "dest_port": 53}}'); INSERT INTO alerts VALUES(3434,1773078757.26272893,'{"timestamp": "2026-03-09T18:52:37.262729+0100", "flow_id": 1409890731967267, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49711, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:52:37.262729+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3435,1773078757.26272893,'{"timestamp": "2026-03-09T18:52:37.262729+0100", "flow_id": 1409889992084122, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60013, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3339, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:52:37.262729+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60013, "dest_port": 53}}'); INSERT INTO alerts VALUES(3436,1773078757.262729884,'{"timestamp": "2026-03-09T18:52:37.262730+0100", "flow_id": 1409895839459691, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55612, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2203, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:52:37.262730+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55612, "dest_port": 53}}'); INSERT INTO alerts VALUES(3437,1773078757.264462947,'{"timestamp": "2026-03-09T18:52:37.264463+0100", "flow_id": 1417336671516918, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51590, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29943, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:52:37.264463+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51590, "dest_port": 53}}'); INSERT INTO alerts VALUES(3438,1773078757.264462947,'{"timestamp": "2026-03-09T18:52:37.264463+0100", "flow_id": 1417335088167295, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63679, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44984, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:52:37.264463+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63679, "dest_port": 53}}'); INSERT INTO alerts VALUES(3439,1773078757.264462947,'{"timestamp": "2026-03-09T18:52:37.264463+0100", "flow_id": 1417335622294557, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61485, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1457, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:52:37.264463+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61485, "dest_port": 53}}'); INSERT INTO alerts VALUES(3440,1773078757.264843941,'{"timestamp": "2026-03-09T18:52:37.264844+0100", "flow_id": 1418974675885601, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60809, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24593, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:52:37.264844+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60809, "dest_port": 53}}'); INSERT INTO alerts VALUES(3441,1773078760.044027091,'{"timestamp": "2026-03-09T18:52:40.044027+0100", "flow_id": 189096123314130, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55528, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55558, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:52:40.044027+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55528, "dest_port": 53}}'); INSERT INTO alerts VALUES(3442,1773078767.367712975,'{"timestamp": "2026-03-09T18:52:47.367713+0100", "flow_id": 2050817587202639, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 55712, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:52:47.346421+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 55712, "dest_port": 853}}'); INSERT INTO alerts VALUES(3443,1773078771.606586933,'{"timestamp": "2026-03-09T18:52:51.606587+0100", "flow_id": 916422116923598, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 28467, "dest_ip": "134.19.55.199", "dest_port": 16144, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:52:51.606587+0100", "src_ip": "167.94.146.45", "dest_ip": "134.19.55.199", "src_port": 28467, "dest_port": 16144}}'); INSERT INTO alerts VALUES(3444,1773078831.671715022,'{"timestamp": "2026-03-09T18:53:51.671715+0100", "flow_id": 2234648256445959, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 51592, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:53:51.651366+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 51592, "dest_port": 853}}'); INSERT INTO alerts VALUES(3445,1773078833.94163704,'{"timestamp": "2026-03-09T18:53:53.941637+0100", "flow_id": 385125772187886, "event_type": "alert", "src_ip": "91.196.152.219", "src_port": 20674, "dest_ip": "134.19.55.199", "dest_port": 20140, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:53:53.941637+0100", "src_ip": "91.196.152.219", "dest_ip": "134.19.55.199", "src_port": 20674, "dest_port": 20140}}'); INSERT INTO alerts VALUES(3446,1773078845.634154081,'{"timestamp": "2026-03-09T18:54:05.634154+0100", "flow_id": 1597773386397355, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60925, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:54:05.634154+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59747, "dest_port": 53}}'); INSERT INTO alerts VALUES(3447,1773078845.634154081,'{"timestamp": "2026-03-09T18:54:05.634154+0100", "flow_id": 1597772767465168, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65279, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2026888, "rev": 4, "signature": "ET INFO DNS Query for Suspicious .icu Domain", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["Medium"], "created_at": ["2019_02_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_11_21"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48933, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "prreqcroab.icu", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:54:05.634154+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65279, "dest_port": 53}}'); INSERT INTO alerts VALUES(3448,1773078863.970252991,'{"timestamp": "2026-03-09T18:54:23.970253+0100", "flow_id": 2196880242325887, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63679, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44984, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:54:23.970253+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63679, "dest_port": 53}}'); INSERT INTO alerts VALUES(3449,1773078863.970253944,'{"timestamp": "2026-03-09T18:54:23.970254+0100", "flow_id": 2196885071420445, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61485, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1457, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:54:23.970254+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61485, "dest_port": 53}}'); INSERT INTO alerts VALUES(3450,1773078863.970253944,'{"timestamp": "2026-03-09T18:54:23.970254+0100", "flow_id": 2196886120642806, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51590, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29943, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:54:23.970254+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51590, "dest_port": 53}}'); INSERT INTO alerts VALUES(3451,1773078863.970253944,'{"timestamp": "2026-03-09T18:54:23.970254+0100", "flow_id": 2196887742471713, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60809, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24593, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:54:23.970254+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60809, "dest_port": 53}}'); INSERT INTO alerts VALUES(3452,1773078863.970253944,'{"timestamp": "2026-03-09T18:54:23.970254+0100", "flow_id": 2196885666622823, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59121, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47384, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:54:23.970254+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59121, "dest_port": 53}}'); INSERT INTO alerts VALUES(3453,1773078863.970254898,'{"timestamp": "2026-03-09T18:54:23.970255+0100", "flow_id": 2196892535567326, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60815, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40211, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:54:23.970255+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60815, "dest_port": 53}}'); INSERT INTO alerts VALUES(3454,1773078863.970254898,'{"timestamp": "2026-03-09T18:54:23.970255+0100", "flow_id": 2196888781023360, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62946, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45880, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:54:23.970255+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62946, "dest_port": 53}}'); INSERT INTO alerts VALUES(3455,1773078863.970254898,'{"timestamp": "2026-03-09T18:54:23.970255+0100", "flow_id": 2196889074010774, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50280, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38817, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:54:23.970255+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50280, "dest_port": 53}}'); INSERT INTO alerts VALUES(3456,1773078865.601233959,'{"timestamp": "2026-03-09T18:54:25.601234+0100", "flow_id": 330482068058222, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63151, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9329, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T18:54:25.601234+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63151, "dest_port": 53}}'); INSERT INTO alerts VALUES(3457,1773078887.371495962,'{"timestamp": "2026-03-09T18:54:47.371496+0100", "flow_id": 2070888104636073, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 45438, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:54:47.351094+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 45438, "dest_port": 853}}'); INSERT INTO alerts VALUES(3458,1773078911.057307004,'{"timestamp": "2026-03-09T18:55:11.057307+0100", "flow_id": 2216458999469039, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45687, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:55:11.057307+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52261, "dest_port": 53}}'); INSERT INTO alerts VALUES(3459,1773078944.679548978,'{"timestamp": "2026-03-09T18:55:44.679549+0100", "flow_id": 13473149184362, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 33252, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:55:44.658496+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 33252, "dest_port": 853}}'); INSERT INTO alerts VALUES(3460,1773078950.65795207,'{"timestamp": "2026-03-09T18:55:50.657952+0100", "flow_id": 1699985003658927, "event_type": "alert", "src_ip": "195.184.76.211", "src_port": 27527, "dest_ip": "134.19.55.199", "dest_port": 6543, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:55:50.657952+0100", "src_ip": "195.184.76.211", "dest_ip": "134.19.55.199", "src_port": 27527, "dest_port": 6543}}'); INSERT INTO alerts VALUES(3461,1773078952.143645048,'{"timestamp": "2026-03-09T18:55:52.143645+0100", "flow_id": 54004257337180, "event_type": "alert", "src_ip": "167.94.138.97", "src_port": 3766, "dest_ip": "134.19.55.199", "dest_port": 2106, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:55:52.143645+0100", "src_ip": "167.94.138.97", "dest_ip": "134.19.55.199", "src_port": 3766, "dest_port": 2106}}'); INSERT INTO alerts VALUES(3462,1773078961.246617079,'{"timestamp": "2026-03-09T18:56:01.246617+0100", "flow_id": 496263301000551, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59121, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47384, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:56:01.246617+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59121, "dest_port": 53}}'); INSERT INTO alerts VALUES(3463,1773078961.246617079,'{"timestamp": "2026-03-09T18:56:01.246617+0100", "flow_id": 496262413421206, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50280, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38817, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:56:01.246617+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50280, "dest_port": 53}}'); INSERT INTO alerts VALUES(3464,1773078961.246618033,'{"timestamp": "2026-03-09T18:56:01.246618+0100", "flow_id": 496270169945054, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60815, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40211, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:56:01.246618+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60815, "dest_port": 53}}'); INSERT INTO alerts VALUES(3465,1773078961.246618033,'{"timestamp": "2026-03-09T18:56:01.246618+0100", "flow_id": 496266415401088, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62946, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45880, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:56:01.246618+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62946, "dest_port": 53}}'); INSERT INTO alerts VALUES(3466,1773078961.246618033,'{"timestamp": "2026-03-09T18:56:01.246618+0100", "flow_id": 496266502546884, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58177, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5306, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:56:01.246618+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58177, "dest_port": 53}}'); INSERT INTO alerts VALUES(3467,1773078961.246618033,'{"timestamp": "2026-03-09T18:56:01.246618+0100", "flow_id": 496266344088464, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64628, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15528, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:56:01.246618+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64628, "dest_port": 53}}'); INSERT INTO alerts VALUES(3468,1773078961.246618986,'{"timestamp": "2026-03-09T18:56:01.246619+0100", "flow_id": 496272203651077, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60370, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24259, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:56:01.246619+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60370, "dest_port": 53}}'); INSERT INTO alerts VALUES(3469,1773078961.246618986,'{"timestamp": "2026-03-09T18:56:01.246619+0100", "flow_id": 496273508599797, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50883, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32336, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:56:01.246619+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50883, "dest_port": 53}}'); INSERT INTO alerts VALUES(3470,1773078968.868221998,'{"timestamp": "2026-03-09T18:56:08.868222+0100", "flow_id": 69813984611381, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59028, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3264, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:56:08.868222+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59028, "dest_port": 53}}'); INSERT INTO alerts VALUES(3471,1773078971.690578938,'{"timestamp": "2026-03-09T18:56:11.690579+0100", "flow_id": 995693437597790, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51208, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34054, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T18:56:11.690579+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51208, "dest_port": 53}}'); INSERT INTO alerts VALUES(3472,1773078978.848970891,'{"timestamp": "2026-03-09T18:56:18.848971+0100", "flow_id": 831556487034615, "event_type": "alert", "src_ip": "91.196.152.123", "src_port": 4402, "dest_ip": "134.19.55.199", "dest_port": 20083, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:56:18.848971+0100", "src_ip": "91.196.152.123", "dest_ip": "134.19.55.199", "src_port": 4402, "dest_port": 20083}}'); INSERT INTO alerts VALUES(3473,1773078983.334738016,'{"timestamp": "2026-03-09T18:56:23.334738+0100", "flow_id": 2000641398779470, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62159, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32878, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:56:23.334738+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62159, "dest_port": 53}}'); INSERT INTO alerts VALUES(3474,1773078983.334738016,'{"timestamp": "2026-03-09T18:56:23.334738+0100", "flow_id": 2000640289233696, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59486, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41764, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:56:23.334738+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59486, "dest_port": 53}}'); INSERT INTO alerts VALUES(3475,1773078983.334738016,'{"timestamp": "2026-03-09T18:56:23.334738+0100", "flow_id": 2000640694634691, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51147, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55107, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:56:23.334738+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51147, "dest_port": 53}}'); INSERT INTO alerts VALUES(3476,1773078983.334738969,'{"timestamp": "2026-03-09T18:56:23.334739+0100", "flow_id": 2000643743864118, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62255, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61804, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:56:23.334739+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62255, "dest_port": 53}}'); INSERT INTO alerts VALUES(3477,1773078984.804754018,'{"timestamp": "2026-03-09T18:56:24.804754+0100", "flow_id": 78693636452945, "event_type": "alert", "src_ip": "195.184.76.67", "src_port": 14839, "dest_ip": "134.19.55.199", "dest_port": 623, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:56:24.804754+0100", "src_ip": "195.184.76.67", "dest_ip": "134.19.55.199", "src_port": 14839, "dest_port": 623}}'); INSERT INTO alerts VALUES(3478,1773078994.649754048,'{"timestamp": "2026-03-09T18:56:34.649754+0100", "flow_id": 820350799976563, "event_type": "alert", "src_ip": "91.196.152.211", "src_port": 8299, "dest_ip": "134.19.55.199", "dest_port": 21554, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:56:34.649754+0100", "src_ip": "91.196.152.211", "dest_ip": "134.19.55.199", "src_port": 8299, "dest_port": 21554}}'); INSERT INTO alerts VALUES(3479,1773078996.720242023,'{"timestamp": "2026-03-09T18:56:36.720242+0100", "flow_id": 1404566757561545, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51962, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39547, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:56:36.720242+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51962, "dest_port": 53}}'); INSERT INTO alerts VALUES(3480,1773078999.488583088,'{"timestamp": "2026-03-09T18:56:39.488583+0100", "flow_id": 2098451272881841, "event_type": "alert", "src_ip": "195.184.76.203", "src_port": 5080, "dest_ip": "134.19.55.199", "dest_port": 6087, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:56:39.488583+0100", "src_ip": "195.184.76.203", "dest_ip": "134.19.55.199", "src_port": 5080, "dest_port": 6087}}'); INSERT INTO alerts VALUES(3481,1773079003.669241905,'{"timestamp": "2026-03-09T18:56:43.669242+0100", "flow_id": 904048506210797, "event_type": "alert", "src_ip": "185.156.73.182", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44331, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T18:56:43.669242+0100", "src_ip": "185.156.73.182", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44331}}'); INSERT INTO alerts VALUES(3482,1773079009.927862882,'{"timestamp": "2026-03-09T18:56:49.927863+0100", "flow_id": 325968802266538, "event_type": "alert", "src_ip": "195.184.76.19", "src_port": 14177, "dest_ip": "134.19.55.199", "dest_port": 6002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:56:49.927863+0100", "src_ip": "195.184.76.19", "dest_ip": "134.19.55.199", "src_port": 14177, "dest_port": 6002}}'); INSERT INTO alerts VALUES(3483,1773079042.549595118,'{"timestamp": "2026-03-09T18:57:22.549595+0100", "flow_id": 671643601618389, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62123, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64085, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:57:22.549595+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62123, "dest_port": 53}}'); INSERT INTO alerts VALUES(3484,1773079057.938489913,'{"timestamp": "2026-03-09T18:57:37.938490+0100", "flow_id": 371610733468448, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59486, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41764, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:57:37.938490+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59486, "dest_port": 53}}'); INSERT INTO alerts VALUES(3485,1773079057.938489913,'{"timestamp": "2026-03-09T18:57:37.938490+0100", "flow_id": 371611138869443, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51147, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55107, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:57:37.938490+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51147, "dest_port": 53}}'); INSERT INTO alerts VALUES(3486,1773079057.938489913,'{"timestamp": "2026-03-09T18:57:37.938490+0100", "flow_id": 371611843014222, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62159, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32878, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:57:37.938490+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62159, "dest_port": 53}}'); INSERT INTO alerts VALUES(3487,1773079057.938491107,'{"timestamp": "2026-03-09T18:57:37.938491+0100", "flow_id": 371614188098870, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62255, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61804, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:57:37.938491+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62255, "dest_port": 53}}'); INSERT INTO alerts VALUES(3488,1773079057.938491107,'{"timestamp": "2026-03-09T18:57:37.938491+0100", "flow_id": 371614860757614, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52817, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53789, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:57:37.938491+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52817, "dest_port": 53}}'); INSERT INTO alerts VALUES(3489,1773079057.938491107,'{"timestamp": "2026-03-09T18:57:37.938491+0100", "flow_id": 371617614216253, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61019, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32832, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:57:37.938491+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61019, "dest_port": 53}}'); INSERT INTO alerts VALUES(3490,1773079057.938491107,'{"timestamp": "2026-03-09T18:57:37.938491+0100", "flow_id": 371616988949928, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21285, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:57:37.938491+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3491,1773079058.82217002,'{"timestamp": "2026-03-09T18:57:38.822170+0100", "flow_id": 716444761740122, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62758, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5779, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:57:38.822170+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62758, "dest_port": 53}}'); INSERT INTO alerts VALUES(3492,1773079064.685897112,'{"timestamp": "2026-03-09T18:57:44.685897+0100", "flow_id": 34209238820567, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 46276, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:57:44.663324+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 46276, "dest_port": 853}}'); INSERT INTO alerts VALUES(3493,1773079082.376566886,'{"timestamp": "2026-03-09T18:58:02.376567+0100", "flow_id": 772920658917850, "event_type": "alert", "src_ip": "195.184.76.243", "src_port": 11147, "dest_ip": "134.19.55.199", "dest_port": 7010, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:58:02.376567+0100", "src_ip": "195.184.76.243", "dest_ip": "134.19.55.199", "src_port": 11147, "dest_port": 7010}}'); INSERT INTO alerts VALUES(3494,1773079102.387465,'{"timestamp": "2026-03-09T18:58:22.387465+0100", "flow_id": 1945627574259805, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57054, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52422, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:58:22.387465+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57054, "dest_port": 53}}'); INSERT INTO alerts VALUES(3495,1773079102.387753964,'{"timestamp": "2026-03-09T18:58:22.387754+0100", "flow_id": 1946866100460033, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51110, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47581, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:58:22.387754+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51110, "dest_port": 53}}'); INSERT INTO alerts VALUES(3496,1773079102.533830882,'{"timestamp": "2026-03-09T18:58:22.533831+0100", "flow_id": 1729839231252036, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58617, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11536, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "edge-184.defra2.ce.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-09T18:58:22.533831+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58617, "dest_port": 53}}'); INSERT INTO alerts VALUES(3497,1773079102.688318014,'{"timestamp": "2026-03-09T18:58:22.688318+0100", "flow_id": 1830403605482440, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63858, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:58:22.688318+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63858, "dest_port": 53}}'); INSERT INTO alerts VALUES(3498,1773079102.689413071,'{"timestamp": "2026-03-09T18:58:22.689413+0100", "flow_id": 1835110429194757, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64400, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17731, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:58:22.689413+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64400, "dest_port": 53}}'); INSERT INTO alerts VALUES(3499,1773079102.700319051,'{"timestamp": "2026-03-09T18:58:22.700319+0100", "flow_id": 1881950955136498, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65281, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59076, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "edge-184.defra2.ce.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-09T18:58:22.700319+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65281, "dest_port": 53}}'); INSERT INTO alerts VALUES(3500,1773079103.06739211,'{"timestamp": "2026-03-09T18:58:23.067392+0100", "flow_id": 1978299470031866, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52907, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27154, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T18:58:23.067392+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52907, "dest_port": 53}}'); INSERT INTO alerts VALUES(3501,1773079103.06739211,'{"timestamp": "2026-03-09T18:58:23.067392+0100", "flow_id": 1978296662009809, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51092, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42568, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T18:58:23.067392+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51092, "dest_port": 53}}'); INSERT INTO alerts VALUES(3502,1773079103.081024885,'{"timestamp": "2026-03-09T18:58:23.081025+0100", "flow_id": 2036850064172579, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53438, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64460, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:58:23.081025+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53438, "dest_port": 53}}'); INSERT INTO alerts VALUES(3503,1773079103.081024885,'{"timestamp": "2026-03-09T18:58:23.081025+0100", "flow_id": 2036853447425381, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50891, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18383, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:58:23.081025+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50891, "dest_port": 53}}'); INSERT INTO alerts VALUES(3504,1773079103.114101886,'{"timestamp": "2026-03-09T18:58:23.114102+0100", "flow_id": 2178916808871288, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58982, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9307, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "edge-184.defra2.ce.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-09T18:58:23.114102+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58982, "dest_port": 53}}'); INSERT INTO alerts VALUES(3505,1773079103.287501096,'{"timestamp": "2026-03-09T18:58:23.287501+0100", "flow_id": 2079233480433541, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63144, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42117, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "edge-184.defra2.ce.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-09T18:58:23.287501+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63144, "dest_port": 53}}'); INSERT INTO alerts VALUES(3506,1773079103.832983017,'{"timestamp": "2026-03-09T18:58:23.832983+0100", "flow_id": 2170261478625961, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49758, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60787, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T18:58:23.832983+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49758, "dest_port": 53}}'); INSERT INTO alerts VALUES(3507,1773079106.502902985,'{"timestamp": "2026-03-09T18:58:26.502903+0100", "flow_id": 752578051618708, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61773, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15890, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "content.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:58:26.502903+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61773, "dest_port": 53}}'); INSERT INTO alerts VALUES(3508,1773079110.447228909,'{"timestamp": "2026-03-09T18:58:30.447229+0100", "flow_id": 1920836995222377, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58615, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17425, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "content.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:58:30.447229+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58615, "dest_port": 53}}'); INSERT INTO alerts VALUES(3509,1773079110.574836015,'{"timestamp": "2026-03-09T18:58:30.574836+0100", "flow_id": 1905954193458471, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51252, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33779, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:58:30.574836+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51252, "dest_port": 53}}'); INSERT INTO alerts VALUES(3510,1773079112.509149075,'{"timestamp": "2026-03-09T18:58:32.509149+0100", "flow_id": 216456861973704, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:58:32.509149+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3511,1773079112.509149075,'{"timestamp": "2026-03-09T18:58:32.509149+0100", "flow_id": 216456132629571, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38700, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:58:32.509149+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62747, "dest_port": 53}}'); INSERT INTO alerts VALUES(3512,1773079112.698097944,'{"timestamp": "2026-03-09T18:58:32.698098+0100", "flow_id": 183559138443574, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51636, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64375, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:58:32.698098+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51636, "dest_port": 53}}'); INSERT INTO alerts VALUES(3513,1773079112.698097944,'{"timestamp": "2026-03-09T18:58:32.698098+0100", "flow_id": 183561522058220, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64597, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:58:32.698098+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64597, "dest_port": 53}}'); INSERT INTO alerts VALUES(3514,1773079113.072493076,'{"timestamp": "2026-03-09T18:58:33.072493+0100", "flow_id": 311355071626297, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62258, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18877, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "content.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:58:33.072493+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62258, "dest_port": 53}}'); INSERT INTO alerts VALUES(3515,1773079114.2881639,'{"timestamp": "2026-03-09T18:58:34.288164+0100", "flow_id": 674706062525803, "event_type": "alert", "src_ip": "185.242.226.73", "src_port": 45376, "dest_ip": "134.19.55.199", "dest_port": 8425, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:58:34.288164+0100", "src_ip": "185.242.226.73", "dest_ip": "134.19.55.199", "src_port": 45376, "dest_port": 8425}}'); INSERT INTO alerts VALUES(3516,1773079115.450715066,'{"timestamp": "2026-03-09T18:58:35.450715+0100", "flow_id": 1091383340719571, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59935, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47433, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "content.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:58:35.450715+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59935, "dest_port": 53}}'); INSERT INTO alerts VALUES(3517,1773079130.883388043,'{"timestamp": "2026-03-09T18:58:50.883388+0100", "flow_id": 697899724006414, "event_type": "alert", "src_ip": "195.184.76.91", "src_port": 14370, "dest_ip": "134.19.55.199", "dest_port": 8013, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T18:58:50.883388+0100", "src_ip": "195.184.76.91", "dest_ip": "134.19.55.199", "src_port": 14370, "dest_port": 8013}}'); INSERT INTO alerts VALUES(3518,1773079131.916177988,'{"timestamp": "2026-03-09T18:58:51.916178+0100", "flow_id": 1120206643644530, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:58:51.916178+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3519,1773079131.916178942,'{"timestamp": "2026-03-09T18:58:51.916179+0100", "flow_id": 1120210330113440, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:58:51.916179+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3520,1773079146.889503956,'{"timestamp": "2026-03-09T18:59:06.889504+0100", "flow_id": 724167557418159, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56840, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48411, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "content.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:59:06.889504+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56840, "dest_port": 53}}'); INSERT INTO alerts VALUES(3521,1773079146.890295983,'{"timestamp": "2026-03-09T18:59:06.890296+0100", "flow_id": 727569886618407, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63461, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9411, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "edge-184.defra2.ce.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-09T18:59:06.890296+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63461, "dest_port": 53}}'); INSERT INTO alerts VALUES(3522,1773079152.181308984,'{"timestamp": "2026-03-09T18:59:12.181309+0100", "flow_id": 215767055580229, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61317, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36791, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:59:12.181309+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61317, "dest_port": 53}}'); INSERT INTO alerts VALUES(3523,1773079152.181309939,'{"timestamp": "2026-03-09T18:59:12.181310+0100", "flow_id": 215770690493234, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60521, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34082, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:59:12.181310+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60521, "dest_port": 53}}'); INSERT INTO alerts VALUES(3524,1773079162.314321994,'{"timestamp": "2026-03-09T18:59:22.314322+0100", "flow_id": 787056915856445, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61019, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32832, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:59:22.314322+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61019, "dest_port": 53}}'); INSERT INTO alerts VALUES(3525,1773079162.314321994,'{"timestamp": "2026-03-09T18:59:22.314322+0100", "flow_id": 787056290590120, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21285, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T18:59:22.314322+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3526,1773079168.883989095,'{"timestamp": "2026-03-09T18:59:28.883989+0100", "flow_id": 137530595552248, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 57769, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T18:59:28.883989+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 57769, "dest_port": 3389}}'); INSERT INTO alerts VALUES(3527,1773079184.192713022,'{"timestamp": "2026-03-09T18:59:44.192713+0100", "flow_id": 264747484498542, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52817, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53789, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:59:44.192713+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52817, "dest_port": 53}}'); INSERT INTO alerts VALUES(3528,1773079184.192713022,'{"timestamp": "2026-03-09T18:59:44.192713+0100", "flow_id": 264748880747105, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62020, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44129, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:59:44.192713+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62020, "dest_port": 53}}'); INSERT INTO alerts VALUES(3529,1773079184.688858985,'{"timestamp": "2026-03-09T18:59:44.688859+0100", "flow_id": 48438836679498, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 33922, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T18:59:44.666638+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 33922, "dest_port": 853}}'); INSERT INTO alerts VALUES(3530,1773079188.972058058,'{"timestamp": "2026-03-09T18:59:48.972058+0100", "flow_id": 1360210947865800, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:59:48.972058+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3531,1773079188.972434997,'{"timestamp": "2026-03-09T18:59:48.972435+0100", "flow_id": 1361829421192259, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38700, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T18:59:48.972435+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62747, "dest_port": 53}}'); INSERT INTO alerts VALUES(3532,1773079194.420680999,'{"timestamp": "2026-03-09T18:59:54.420681+0100", "flow_id": 680913093642354, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:59:54.420681+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3533,1773079194.420680999,'{"timestamp": "2026-03-09T18:59:54.420681+0100", "flow_id": 680912485143968, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T18:59:54.420681+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3534,1773079201.774847985,'{"timestamp": "2026-03-09T19:00:01.774848+0100", "flow_id": 513200226020346, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52907, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27154, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:00:01.774848+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52907, "dest_port": 53}}'); INSERT INTO alerts VALUES(3535,1773079201.777051925,'{"timestamp": "2026-03-09T19:00:01.777052+0100", "flow_id": 522663525918673, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51092, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42568, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:00:01.777052+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51092, "dest_port": 53}}'); INSERT INTO alerts VALUES(3536,1773079201.783561945,'{"timestamp": "2026-03-09T19:00:01.783562+0100", "flow_id": 550626290146787, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56953, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27242, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:00:01.783562+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56953, "dest_port": 53}}'); INSERT INTO alerts VALUES(3537,1773079201.784018993,'{"timestamp": "2026-03-09T19:00:01.784019+0100", "flow_id": 552588638554182, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62455, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39659, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:00:01.784019+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62455, "dest_port": 53}}'); INSERT INTO alerts VALUES(3538,1773079208.695640087,'{"timestamp": "2026-03-09T19:00:08.695640+0100", "flow_id": 173002066213957, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61317, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36791, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:00:08.695640+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61317, "dest_port": 53}}'); INSERT INTO alerts VALUES(3539,1773079208.695640087,'{"timestamp": "2026-03-09T19:00:08.695640+0100", "flow_id": 173001406159666, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60521, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34082, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:00:08.695640+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60521, "dest_port": 53}}'); INSERT INTO alerts VALUES(3540,1773079208.695641041,'{"timestamp": "2026-03-09T19:00:08.695641+0100", "flow_id": 173008242112770, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54330, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46456, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:00:08.695641+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54330, "dest_port": 53}}'); INSERT INTO alerts VALUES(3541,1773079208.695645094,'{"timestamp": "2026-03-09T19:00:08.695645+0100", "flow_id": 173026615318048, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51960, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32100, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:00:08.695645+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51960, "dest_port": 53}}'); INSERT INTO alerts VALUES(3542,1773079220.429503918,'{"timestamp": "2026-03-09T19:00:20.429504+0100", "flow_id": 1281759075237064, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:00:20.429504+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3543,1773079220.429503918,'{"timestamp": "2026-03-09T19:00:20.429504+0100", "flow_id": 1281758345892931, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38700, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:00:20.429504+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62747, "dest_port": 53}}'); INSERT INTO alerts VALUES(3544,1773079224.62597394,'{"timestamp": "2026-03-09T19:00:24.625974+0100", "flow_id": 155264931186802, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:00:24.625974+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3545,1773079224.625974893,'{"timestamp": "2026-03-09T19:00:24.625975+0100", "flow_id": 155268617655712, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:00:24.625975+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3546,1773079251.534751893,'{"timestamp": "2026-03-09T19:00:51.534752+0100", "flow_id": 889370863074504, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:00:51.534752+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3547,1773079251.534751893,'{"timestamp": "2026-03-09T19:00:51.534752+0100", "flow_id": 889370133730371, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38700, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:00:51.534752+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62747, "dest_port": 53}}'); INSERT INTO alerts VALUES(3548,1773079254.692337037,'{"timestamp": "2026-03-09T19:00:54.692337+0100", "flow_id": 1847666729404530, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:00:54.692337+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3549,1773079254.692337989,'{"timestamp": "2026-03-09T19:00:54.692338+0100", "flow_id": 1847670415873440, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:00:54.692338+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3550,1773079264.820295096,'{"timestamp": "2026-03-09T19:01:04.820295+0100", "flow_id": 145441882950254, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52817, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53789, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:01:04.820295+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52817, "dest_port": 53}}'); INSERT INTO alerts VALUES(3551,1773079264.820295096,'{"timestamp": "2026-03-09T19:01:04.820295+0100", "flow_id": 145443279198817, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62020, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44129, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:01:04.820295+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62020, "dest_port": 53}}'); INSERT INTO alerts VALUES(3552,1773079264.820296049,'{"timestamp": "2026-03-09T19:01:04.820296+0100", "flow_id": 145448931376189, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61019, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32832, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:01:04.820296+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61019, "dest_port": 53}}'); INSERT INTO alerts VALUES(3553,1773079264.820297002,'{"timestamp": "2026-03-09T19:01:04.820297+0100", "flow_id": 145452601077160, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21285, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:01:04.820297+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3554,1773079264.821007966,'{"timestamp": "2026-03-09T19:01:04.821008+0100", "flow_id": 148505864070598, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56139, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7192, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:01:04.821008+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56139, "dest_port": 53}}'); INSERT INTO alerts VALUES(3555,1773079264.82100892,'{"timestamp": "2026-03-09T19:01:04.821009+0100", "flow_id": 148507923735314, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57457, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31801, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:01:04.821009+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57457, "dest_port": 53}}'); INSERT INTO alerts VALUES(3556,1773079265.30239606,'{"timestamp": "2026-03-09T19:01:05.302396+0100", "flow_id": 454358893174243, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56953, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27242, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:01:05.302396+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56953, "dest_port": 53}}'); INSERT INTO alerts VALUES(3557,1773079265.302397012,'{"timestamp": "2026-03-09T19:01:05.302397+0100", "flow_id": 454362736494662, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62455, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39659, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:01:05.302397+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62455, "dest_port": 53}}'); INSERT INTO alerts VALUES(3558,1773079268.150826931,'{"timestamp": "2026-03-09T19:01:08.150827+0100", "flow_id": 1210749991602841, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49764, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48399, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:01:08.150827+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49764, "dest_port": 53}}'); INSERT INTO alerts VALUES(3559,1773079268.150827884,'{"timestamp": "2026-03-09T19:01:08.150828+0100", "flow_id": 1210755382555671, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61899, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17539, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:01:08.150828+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61899, "dest_port": 53}}'); INSERT INTO alerts VALUES(3560,1773079273.960340977,'{"timestamp": "2026-03-09T19:01:13.960341+0100", "flow_id": 465461723962553, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61550, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20781, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:01:13.960341+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61550, "dest_port": 53}}'); INSERT INTO alerts VALUES(3561,1773079273.960624933,'{"timestamp": "2026-03-09T19:01:13.960625+0100", "flow_id": 466680075433238, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61470, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:01:13.960625+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62124, "dest_port": 53}}'); INSERT INTO alerts VALUES(3562,1773079276.681998968,'{"timestamp": "2026-03-09T19:01:16.681999+0100", "flow_id": 1240316205103362, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54330, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46456, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:01:16.681999+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54330, "dest_port": 53}}'); INSERT INTO alerts VALUES(3563,1773079276.681999921,'{"timestamp": "2026-03-09T19:01:16.682000+0100", "flow_id": 1240321693406752, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51960, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32100, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:01:16.682000+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51960, "dest_port": 53}}'); INSERT INTO alerts VALUES(3564,1773079276.681999921,'{"timestamp": "2026-03-09T19:01:16.682000+0100", "flow_id": 1240320908407806, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53387, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39722, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:01:16.682000+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53387, "dest_port": 53}}'); INSERT INTO alerts VALUES(3565,1773079276.681999921,'{"timestamp": "2026-03-09T19:01:16.682000+0100", "flow_id": 1240318462482094, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65205, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33353, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:01:16.682000+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65205, "dest_port": 53}}'); INSERT INTO alerts VALUES(3566,1773079276.794934034,'{"timestamp": "2026-03-09T19:01:16.794934+0100", "flow_id": 1162418787369039, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57532, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31603, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:01:16.794934+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57532, "dest_port": 53}}'); INSERT INTO alerts VALUES(3567,1773079276.794934034,'{"timestamp": "2026-03-09T19:01:16.794934+0100", "flow_id": 1162418563697453, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51787, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5054, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:01:16.794934+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51787, "dest_port": 53}}'); INSERT INTO alerts VALUES(3568,1773079276.794934034,'{"timestamp": "2026-03-09T19:01:16.794934+0100", "flow_id": 1162418230526071, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62409, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49564, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:01:16.794934+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62409, "dest_port": 53}}'); INSERT INTO alerts VALUES(3569,1773079276.794934989,'{"timestamp": "2026-03-09T19:01:16.794935+0100", "flow_id": 1162423796543697, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55889, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3215, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:01:16.794935+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55889, "dest_port": 53}}'); INSERT INTO alerts VALUES(3570,1773079284.25099802,'{"timestamp": "2026-03-09T19:01:24.250998+0100", "flow_id": 1359506064765004, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62981, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33599, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:01:24.250998+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62981, "dest_port": 53}}'); INSERT INTO alerts VALUES(3571,1773079284.250998974,'{"timestamp": "2026-03-09T19:01:24.250999+0100", "flow_id": 1359509432401766, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52756, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27779, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:01:24.250999+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52756, "dest_port": 53}}'); INSERT INTO alerts VALUES(3572,1773079328.479953051,'{"timestamp": "2026-03-09T19:02:08.479953+0100", "flow_id": 91060267455555, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38700, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:02:08.479953+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62747, "dest_port": 53}}'); INSERT INTO alerts VALUES(3573,1773079328.479953051,'{"timestamp": "2026-03-09T19:02:08.479953+0100", "flow_id": 91059465078898, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:02:08.479953+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3574,1773079328.479954004,'{"timestamp": "2026-03-09T19:02:08.479954+0100", "flow_id": 91063151547808, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:02:08.479954+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3575,1773079336.288544893,'{"timestamp": "2026-03-09T19:02:16.288545+0100", "flow_id": 113394504381438, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53387, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39722, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:02:16.288545+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53387, "dest_port": 53}}'); INSERT INTO alerts VALUES(3576,1773079336.288544893,'{"timestamp": "2026-03-09T19:02:16.288545+0100", "flow_id": 113392058455726, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65205, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33353, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:02:16.288545+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65205, "dest_port": 53}}'); INSERT INTO alerts VALUES(3577,1773079336.288544893,'{"timestamp": "2026-03-09T19:02:16.288545+0100", "flow_id": 113392618329579, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23946, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:02:16.288545+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58468, "dest_port": 53}}'); INSERT INTO alerts VALUES(3578,1773079336.288546085,'{"timestamp": "2026-03-09T19:02:16.288546+0100", "flow_id": 113395760434994, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63043, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33788, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:02:16.288546+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63043, "dest_port": 53}}'); INSERT INTO alerts VALUES(3579,1773079336.288546085,'{"timestamp": "2026-03-09T19:02:16.288546+0100", "flow_id": 113398364228720, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50160, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6890, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:02:16.288546+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50160, "dest_port": 53}}'); INSERT INTO alerts VALUES(3580,1773079336.288546085,'{"timestamp": "2026-03-09T19:02:16.288546+0100", "flow_id": 113399617075850, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63623, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49418, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:02:16.288546+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63623, "dest_port": 53}}'); INSERT INTO alerts VALUES(3581,1773079359.131793975,'{"timestamp": "2026-03-09T19:02:39.131794+0100", "flow_id": 1973429198519496, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:02:39.131794+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3582,1773079359.131793975,'{"timestamp": "2026-03-09T19:02:39.131794+0100", "flow_id": 1973428469175363, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38700, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:02:39.131794+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62747, "dest_port": 53}}'); INSERT INTO alerts VALUES(3583,1773079359.13179493,'{"timestamp": "2026-03-09T19:02:39.131795+0100", "flow_id": 1973431961766002, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:02:39.131795+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3584,1773079359.13179493,'{"timestamp": "2026-03-09T19:02:39.131795+0100", "flow_id": 1973431353267616, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:02:39.131795+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3585,1773079383.66602993,'{"timestamp": "2026-03-09T19:03:03.666030+0100", "flow_id": 2016155206598735, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57532, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31603, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:03.666030+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57532, "dest_port": 53}}'); INSERT INTO alerts VALUES(3586,1773079383.666030883,'{"timestamp": "2026-03-09T19:03:03.666031+0100", "flow_id": 2016159277894445, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51787, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5054, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:03:03.666031+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51787, "dest_port": 53}}'); INSERT INTO alerts VALUES(3587,1773079383.666030883,'{"timestamp": "2026-03-09T19:03:03.666031+0100", "flow_id": 2016158944723063, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62409, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49564, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:03:03.666031+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62409, "dest_port": 53}}'); INSERT INTO alerts VALUES(3588,1773079383.666030883,'{"timestamp": "2026-03-09T19:03:03.666031+0100", "flow_id": 2016160215773393, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55889, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3215, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:03.666031+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55889, "dest_port": 53}}'); INSERT INTO alerts VALUES(3589,1773079383.666030883,'{"timestamp": "2026-03-09T19:03:03.666031+0100", "flow_id": 2016159853972614, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56975, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3478, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:03.666031+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56975, "dest_port": 53}}'); INSERT INTO alerts VALUES(3590,1773079383.666032076,'{"timestamp": "2026-03-09T19:03:03.666032+0100", "flow_id": 2016161205985059, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61538, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28630, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:03:03.666032+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61538, "dest_port": 53}}'); INSERT INTO alerts VALUES(3591,1773079383.666032076,'{"timestamp": "2026-03-09T19:03:03.666032+0100", "flow_id": 2016162362005367, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56893, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54381, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:03:03.666032+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56893, "dest_port": 53}}'); INSERT INTO alerts VALUES(3592,1773079383.666032076,'{"timestamp": "2026-03-09T19:03:03.666032+0100", "flow_id": 2016161183862561, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49339, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54993, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:03.666032+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49339, "dest_port": 53}}'); INSERT INTO alerts VALUES(3593,1773079385.999840021,'{"timestamp": "2026-03-09T19:03:05.999840+0100", "flow_id": 353634600425965, "event_type": "alert", "src_ip": "81.29.142.50", "src_port": 46742, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:03:05.999840+0100", "src_ip": "81.29.142.50", "dest_ip": "134.19.55.199", "src_port": 46742, "dest_port": 1433}}'); INSERT INTO alerts VALUES(3594,1773079387.289825916,'{"timestamp": "2026-03-09T19:03:07.289826+0100", "flow_id": 963319401567723, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23946, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:07.289826+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58468, "dest_port": 53}}'); INSERT INTO alerts VALUES(3595,1773079387.289825916,'{"timestamp": "2026-03-09T19:03:07.289826+0100", "flow_id": 963318248705842, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63043, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33788, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:07.289826+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63043, "dest_port": 53}}'); INSERT INTO alerts VALUES(3596,1773079387.289827108,'{"timestamp": "2026-03-09T19:03:07.289827+0100", "flow_id": 963324901811393, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65069, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15786, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:07.289827+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65069, "dest_port": 53}}'); INSERT INTO alerts VALUES(3597,1773079387.289827108,'{"timestamp": "2026-03-09T19:03:07.289827+0100", "flow_id": 963323066372450, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56891, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38984, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:07.289827+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56891, "dest_port": 53}}'); INSERT INTO alerts VALUES(3598,1773079387.289827108,'{"timestamp": "2026-03-09T19:03:07.289827+0100", "flow_id": 963324641029363, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54912, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:03:07.289827+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62886, "dest_port": 53}}'); INSERT INTO alerts VALUES(3599,1773079387.289827108,'{"timestamp": "2026-03-09T19:03:07.289827+0100", "flow_id": 963326372777699, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60288, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14477, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:03:07.289827+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60288, "dest_port": 53}}'); INSERT INTO alerts VALUES(3600,1773079388.895020962,'{"timestamp": "2026-03-09T19:03:08.895021+0100", "flow_id": 1310812173624740, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58042, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50352, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:03:08.895021+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58042, "dest_port": 53}}'); INSERT INTO alerts VALUES(3601,1773079388.895021915,'{"timestamp": "2026-03-09T19:03:08.895022+0100", "flow_id": 1310818209215645, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57942, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36815, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:03:08.895022+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57942, "dest_port": 53}}'); INSERT INTO alerts VALUES(3602,1773079389.494940043,'{"timestamp": "2026-03-09T19:03:09.494940+0100", "flow_id": 1562804555218120, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:09.494940+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3603,1773079389.494940996,'{"timestamp": "2026-03-09T19:03:09.494941+0100", "flow_id": 1562808120841283, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38700, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:09.494941+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62747, "dest_port": 53}}'); INSERT INTO alerts VALUES(3604,1773079389.494940996,'{"timestamp": "2026-03-09T19:03:09.494941+0100", "flow_id": 1562807318464626, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:03:09.494941+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3605,1773079389.494940996,'{"timestamp": "2026-03-09T19:03:09.494941+0100", "flow_id": 1562806709966240, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:03:09.494941+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3606,1773079417.276429891,'{"timestamp": "2026-03-09T19:03:37.276430+0100", "flow_id": 342836729557055, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49597, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55675, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:37.276430+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49597, "dest_port": 53}}'); INSERT INTO alerts VALUES(3607,1773079417.276429891,'{"timestamp": "2026-03-09T19:03:37.276430+0100", "flow_id": 342836677499985, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49693, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24200, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:03:37.276430+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49693, "dest_port": 53}}'); INSERT INTO alerts VALUES(3608,1773079417.276431084,'{"timestamp": "2026-03-09T19:03:37.276431+0100", "flow_id": 342839751684940, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63416, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51617, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:03:37.276431+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63416, "dest_port": 53}}'); INSERT INTO alerts VALUES(3609,1773079417.276431084,'{"timestamp": "2026-03-09T19:03:37.276431+0100", "flow_id": 342839281624024, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63308, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29563, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:37.276431+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63308, "dest_port": 53}}'); INSERT INTO alerts VALUES(3610,1773079417.596663952,'{"timestamp": "2026-03-09T19:03:37.596664+0100", "flow_id": 310854760925042, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53089, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40712, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:37.596664+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53089, "dest_port": 53}}'); INSERT INTO alerts VALUES(3611,1773079417.596663952,'{"timestamp": "2026-03-09T19:03:37.596664+0100", "flow_id": 310852570234070, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57986, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28161, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:37.596664+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57986, "dest_port": 53}}'); INSERT INTO alerts VALUES(3612,1773079417.596663952,'{"timestamp": "2026-03-09T19:03:37.596664+0100", "flow_id": 310853566618067, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56052, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44968, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:03:37.596664+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56052, "dest_port": 53}}'); INSERT INTO alerts VALUES(3613,1773079417.596663952,'{"timestamp": "2026-03-09T19:03:37.596664+0100", "flow_id": 310855606681202, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53881, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65349, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:03:37.596664+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53881, "dest_port": 53}}'); INSERT INTO alerts VALUES(3614,1773079420.665209055,'{"timestamp": "2026-03-09T19:03:40.665209+0100", "flow_id": 1168204434898120, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:03:40.665209+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3615,1773079420.665719986,'{"timestamp": "2026-03-09T19:03:40.665720+0100", "flow_id": 1170397631465586, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:03:40.665720+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3616,1773079420.665719986,'{"timestamp": "2026-03-09T19:03:40.665720+0100", "flow_id": 1170397022967200, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:03:40.665720+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3617,1773079424.693043948,'{"timestamp": "2026-03-09T19:03:44.693044+0100", "flow_id": 71906603725347, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 48258, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:03:44.672102+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 48258, "dest_port": 853}}'); INSERT INTO alerts VALUES(3618,1773079451.744204044,'{"timestamp": "2026-03-09T19:04:11.744204+0100", "flow_id": 944535423024328, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:04:11.744204+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3619,1773079451.744204044,'{"timestamp": "2026-03-09T19:04:11.744204+0100", "flow_id": 944533891303538, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:04:11.744204+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3620,1773079451.744204999,'{"timestamp": "2026-03-09T19:04:11.744205+0100", "flow_id": 944537577772448, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:04:11.744205+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3621,1773079482.708631039,'{"timestamp": "2026-03-09T19:04:42.708631+0100", "flow_id": 791750551403720, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:04:42.708631+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3622,1773079482.708631039,'{"timestamp": "2026-03-09T19:04:42.708631+0100", "flow_id": 791749019682930, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:04:42.708631+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3623,1773079482.708631993,'{"timestamp": "2026-03-09T19:04:42.708632+0100", "flow_id": 791752706151840, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:04:42.708632+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3624,1773079512.945487023,'{"timestamp": "2026-03-09T19:05:12.945487+0100", "flow_id": 120189465001160, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:05:12.945487+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3625,1773079512.945487023,'{"timestamp": "2026-03-09T19:05:12.945487+0100", "flow_id": 120187933280370, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:05:12.945487+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3626,1773079512.945487023,'{"timestamp": "2026-03-09T19:05:12.945487+0100", "flow_id": 120187324781984, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:05:12.945487+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3627,1773079523.679569005,'{"timestamp": "2026-03-09T19:05:23.679569+0100", "flow_id": 948405643456575, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49597, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55675, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:05:23.679569+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49597, "dest_port": 53}}'); INSERT INTO alerts VALUES(3628,1773079523.679569005,'{"timestamp": "2026-03-09T19:05:23.679569+0100", "flow_id": 948405591399505, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49693, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24200, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:05:23.679569+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49693, "dest_port": 53}}'); INSERT INTO alerts VALUES(3629,1773079523.679569005,'{"timestamp": "2026-03-09T19:05:23.679569+0100", "flow_id": 948404370617164, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63416, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51617, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:05:23.679569+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63416, "dest_port": 53}}'); INSERT INTO alerts VALUES(3630,1773079523.679569959,'{"timestamp": "2026-03-09T19:05:23.679570+0100", "flow_id": 948408195523544, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63308, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29563, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:05:23.679570+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63308, "dest_port": 53}}'); INSERT INTO alerts VALUES(3631,1773079523.679569959,'{"timestamp": "2026-03-09T19:05:23.679570+0100", "flow_id": 948409360938173, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53925, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63980, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:05:23.679570+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53925, "dest_port": 53}}'); INSERT INTO alerts VALUES(3632,1773079523.679569959,'{"timestamp": "2026-03-09T19:05:23.679570+0100", "flow_id": 948407261032259, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54776, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6549, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:05:23.679570+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54776, "dest_port": 53}}'); INSERT INTO alerts VALUES(3633,1773079523.679569959,'{"timestamp": "2026-03-09T19:05:23.679570+0100", "flow_id": 948409316392866, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60388, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37734, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:05:23.679570+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60388, "dest_port": 53}}'); INSERT INTO alerts VALUES(3634,1773079523.679570914,'{"timestamp": "2026-03-09T19:05:23.679571+0100", "flow_id": 948414517588983, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65532, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48098, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:05:23.679571+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65532, "dest_port": 53}}'); INSERT INTO alerts VALUES(3635,1773079540.07293892,'{"timestamp": "2026-03-09T19:05:40.072939+0100", "flow_id": 1157697246617273, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65043, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43930, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:05:40.072939+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65043, "dest_port": 53}}'); INSERT INTO alerts VALUES(3636,1773079540.072940111,'{"timestamp": "2026-03-09T19:05:40.072940+0100", "flow_id": 1157701705518887, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57678, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43744, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:05:40.072940+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57678, "dest_port": 53}}'); INSERT INTO alerts VALUES(3637,1773079544.705842971,'{"timestamp": "2026-03-09T19:05:44.705843+0100", "flow_id": 123386051458136, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 40122, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:05:44.684088+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 40122, "dest_port": 853}}'); INSERT INTO alerts VALUES(3638,1773079562.53698492,'{"timestamp": "2026-03-09T19:06:02.536985+0100", "flow_id": 617486721759365, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55170, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45691, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:06:02.536985+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55170, "dest_port": 53}}'); INSERT INTO alerts VALUES(3639,1773079562.536986112,'{"timestamp": "2026-03-09T19:06:02.536986+0100", "flow_id": 617491012108009, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50418, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49841, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:06:02.536986+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50418, "dest_port": 53}}'); INSERT INTO alerts VALUES(3640,1773079562.536986112,'{"timestamp": "2026-03-09T19:06:02.536986+0100", "flow_id": 617488474011194, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59170, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21597, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:06:02.536986+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59170, "dest_port": 53}}'); INSERT INTO alerts VALUES(3641,1773079562.536986112,'{"timestamp": "2026-03-09T19:06:02.536986+0100", "flow_id": 617489921768094, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55831, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25016, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:06:02.536986+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55831, "dest_port": 53}}'); INSERT INTO alerts VALUES(3642,1773079567.935909033,'{"timestamp": "2026-03-09T19:06:07.935909+0100", "flow_id": 2232960736266781, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 56366, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:06:07.913117+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 56366, "dest_port": 853}}'); INSERT INTO alerts VALUES(3643,1773079572.017127037,'{"timestamp": "2026-03-09T19:06:12.017127+0100", "flow_id": 1199462019630962, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53089, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40712, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:06:12.017127+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53089, "dest_port": 53}}'); INSERT INTO alerts VALUES(3644,1773079572.017127037,'{"timestamp": "2026-03-09T19:06:12.017127+0100", "flow_id": 1199459828939990, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57986, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28161, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:06:12.017127+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57986, "dest_port": 53}}'); INSERT INTO alerts VALUES(3645,1773079572.01712799,'{"timestamp": "2026-03-09T19:06:12.017128+0100", "flow_id": 1199468329438020, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62588, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33820, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:06:12.017128+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62588, "dest_port": 53}}'); INSERT INTO alerts VALUES(3646,1773079572.01712799,'{"timestamp": "2026-03-09T19:06:12.017128+0100", "flow_id": 1199468112456376, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63621, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45871, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:06:12.017128+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63621, "dest_port": 53}}'); INSERT INTO alerts VALUES(3647,1773079572.017128945,'{"timestamp": "2026-03-09T19:06:12.017129+0100", "flow_id": 1199470678293505, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60493, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28638, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:06:12.017129+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60493, "dest_port": 53}}'); INSERT INTO alerts VALUES(3648,1773079572.017581939,'{"timestamp": "2026-03-09T19:06:12.017582+0100", "flow_id": 1201417951534797, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57128, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35735, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:06:12.017582+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57128, "dest_port": 53}}'); INSERT INTO alerts VALUES(3649,1773079576.741372109,'{"timestamp": "2026-03-09T19:06:16.741372+0100", "flow_id": 87947145510088, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:06:16.741372+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3650,1773079576.741632939,'{"timestamp": "2026-03-09T19:06:16.741633+0100", "flow_id": 89066600253554, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:06:16.741633+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3651,1773079576.743479968,'{"timestamp": "2026-03-09T19:06:16.743480+0100", "flow_id": 96998796350880, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:06:16.743480+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3652,1773079584.744230985,'{"timestamp": "2026-03-09T19:06:24.744231+0100", "flow_id": 100226653314044, "event_type": "alert", "src_ip": "193.163.125.211", "src_port": 59214, "dest_ip": "134.19.55.199", "dest_port": 9282, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:06:24.744231+0100", "src_ip": "193.163.125.211", "dest_ip": "134.19.55.199", "src_port": 59214, "dest_port": 9282}}'); INSERT INTO alerts VALUES(3653,1773079600.240134,'{"timestamp": "2026-03-09T19:06:40.240134+0100", "flow_id": 186946946062276, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 46275, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T19:06:40.240134+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 46275, "dest_port": 8545}}'); INSERT INTO alerts VALUES(3654,1773079600.240134,'{"timestamp": "2026-03-09T19:06:40.240134+0100", "flow_id": 186946946062276, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 46275, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T19:06:40.240134+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 46275, "dest_port": 8545}}'); INSERT INTO alerts VALUES(3655,1773079603.769229888,'{"timestamp": "2026-03-09T19:06:43.769230+0100", "flow_id": 1052020056452666, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53610, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11612, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:06:43.769230+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53610, "dest_port": 53}}'); INSERT INTO alerts VALUES(3656,1773079603.769229888,'{"timestamp": "2026-03-09T19:06:43.769230+0100", "flow_id": 1052020211716690, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49323, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 328, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:06:43.769230+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49323, "dest_port": 53}}'); INSERT INTO alerts VALUES(3657,1773079619.694816112,'{"timestamp": "2026-03-09T19:06:59.694816+0100", "flow_id": 1013890528306453, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 37736, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:06:59.694816+0100", "src_ip": "193.142.146.230", "dest_ip": "134.19.55.199", "src_port": 37736, "dest_port": 8080}}'); INSERT INTO alerts VALUES(3658,1773079623.373914004,'{"timestamp": "2026-03-09T19:07:03.373914+0100", "flow_id": 2168902289505839, "event_type": "alert", "src_ip": "147.185.132.249", "src_port": 52498, "dest_ip": "134.19.55.199", "dest_port": 37777, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:07:03.373914+0100", "src_ip": "147.185.132.249", "dest_ip": "134.19.55.199", "src_port": 52498, "dest_port": 37777}}'); INSERT INTO alerts VALUES(3659,1773079643.692353964,'{"timestamp": "2026-03-09T19:07:23.692354+0100", "flow_id": 1003316518860933, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55170, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45691, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:07:23.692354+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55170, "dest_port": 53}}'); INSERT INTO alerts VALUES(3660,1773079643.692353964,'{"timestamp": "2026-03-09T19:07:23.692354+0100", "flow_id": 1003316514242281, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50418, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49841, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:07:23.692354+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50418, "dest_port": 53}}'); INSERT INTO alerts VALUES(3661,1773079643.692354917,'{"timestamp": "2026-03-09T19:07:23.692355+0100", "flow_id": 1003318271112762, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59170, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21597, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:07:23.692355+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59170, "dest_port": 53}}'); INSERT INTO alerts VALUES(3662,1773079643.692354917,'{"timestamp": "2026-03-09T19:07:23.692355+0100", "flow_id": 1003319718869662, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55831, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25016, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:07:23.692355+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55831, "dest_port": 53}}'); INSERT INTO alerts VALUES(3663,1773079643.692354917,'{"timestamp": "2026-03-09T19:07:23.692355+0100", "flow_id": 1003318147573203, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50411, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4627, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:07:23.692355+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50411, "dest_port": 53}}'); INSERT INTO alerts VALUES(3664,1773079643.692354917,'{"timestamp": "2026-03-09T19:07:23.692355+0100", "flow_id": 1003320831657496, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57677, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1164, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:07:23.692355+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57677, "dest_port": 53}}'); INSERT INTO alerts VALUES(3665,1773079643.692356109,'{"timestamp": "2026-03-09T19:07:23.692356+0100", "flow_id": 1003325609294861, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49940, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38422, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:07:23.692356+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49940, "dest_port": 53}}'); INSERT INTO alerts VALUES(3666,1773079643.692356109,'{"timestamp": "2026-03-09T19:07:23.692356+0100", "flow_id": 1003325783019509, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49369, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11273, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:07:23.692356+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49369, "dest_port": 53}}'); INSERT INTO alerts VALUES(3667,1773079664.711781025,'{"timestamp": "2026-03-09T19:07:44.711781+0100", "flow_id": 148188799433781, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 43482, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:07:44.689862+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 43482, "dest_port": 853}}'); INSERT INTO alerts VALUES(3668,1773079673.927608967,'{"timestamp": "2026-03-09T19:07:53.927609+0100", "flow_id": 324879016393928, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:07:53.927609+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3669,1773079673.92760992,'{"timestamp": "2026-03-09T19:07:53.927610+0100", "flow_id": 324881779640434, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:07:53.927610+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3670,1773079673.92760992,'{"timestamp": "2026-03-09T19:07:53.927610+0100", "flow_id": 324881171142048, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:07:53.927610+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3671,1773079685.901297093,'{"timestamp": "2026-03-09T19:08:05.901297+0100", "flow_id": 1619245543379371, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49936, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32955, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T19:08:05.901297+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49936, "dest_port": 53}}'); INSERT INTO alerts VALUES(3672,1773079687.935594081,'{"timestamp": "2026-03-09T19:08:07.935594+0100", "flow_id": 2235116479019386, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 42662, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:08:07.913619+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 42662, "dest_port": 853}}'); INSERT INTO alerts VALUES(3673,1773079692.276422024,'{"timestamp": "2026-03-09T19:08:12.276422+0100", "flow_id": 1187224167054752, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54637, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22243, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:08:12.276422+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54637, "dest_port": 53}}'); INSERT INTO alerts VALUES(3674,1773079692.276422024,'{"timestamp": "2026-03-09T19:08:12.276422+0100", "flow_id": 1187223560673798, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63410, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52656, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:08:12.276422+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63410, "dest_port": 53}}'); INSERT INTO alerts VALUES(3675,1773079692.276422977,'{"timestamp": "2026-03-09T19:08:12.276423+0100", "flow_id": 1187230380171635, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49864, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63342, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:08:12.276423+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49864, "dest_port": 53}}'); INSERT INTO alerts VALUES(3676,1773079692.276422977,'{"timestamp": "2026-03-09T19:08:12.276423+0100", "flow_id": 1187230205660846, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62666, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38346, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:08:12.276423+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62666, "dest_port": 53}}'); INSERT INTO alerts VALUES(3677,1773079704.128022909,'{"timestamp": "2026-03-09T19:08:24.128023+0100", "flow_id": 268383016582344, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:08:24.128023+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3678,1773079704.128022909,'{"timestamp": "2026-03-09T19:08:24.128023+0100", "flow_id": 268381484861554, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:08:24.128023+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3679,1773079704.128024101,'{"timestamp": "2026-03-09T19:08:24.128024+0100", "flow_id": 268385171330464, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:08:24.128024+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3680,1773079743.33009696,'{"timestamp": "2026-03-09T19:09:03.330097+0100", "flow_id": 1980706490088864, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54637, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22243, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:09:03.330097+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54637, "dest_port": 53}}'); INSERT INTO alerts VALUES(3681,1773079743.33009696,'{"timestamp": "2026-03-09T19:09:03.330097+0100", "flow_id": 1980705883707910, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63410, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52656, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:09:03.330097+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63410, "dest_port": 53}}'); INSERT INTO alerts VALUES(3682,1773079743.330097914,'{"timestamp": "2026-03-09T19:09:03.330098+0100", "flow_id": 1980712703205747, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49864, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63342, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:09:03.330098+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49864, "dest_port": 53}}'); INSERT INTO alerts VALUES(3683,1773079743.330097914,'{"timestamp": "2026-03-09T19:09:03.330098+0100", "flow_id": 1980712528694958, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62666, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38346, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:09:03.330098+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62666, "dest_port": 53}}'); INSERT INTO alerts VALUES(3684,1773079743.330097914,'{"timestamp": "2026-03-09T19:09:03.330098+0100", "flow_id": 1980713986353787, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56293, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1692, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:09:03.330098+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56293, "dest_port": 53}}'); INSERT INTO alerts VALUES(3685,1773079743.330557108,'{"timestamp": "2026-03-09T19:09:03.330557+0100", "flow_id": 1982684376613249, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54788, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21908, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:09:03.330557+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54788, "dest_port": 53}}'); INSERT INTO alerts VALUES(3686,1773079743.330558061,'{"timestamp": "2026-03-09T19:09:03.330558+0100", "flow_id": 1982688220931380, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58152, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60837, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:09:03.330558+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58152, "dest_port": 53}}'); INSERT INTO alerts VALUES(3687,1773079743.433579922,'{"timestamp": "2026-03-09T19:09:03.433580+0100", "flow_id": 2143689073946170, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53610, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11612, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:09:03.433580+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53610, "dest_port": 53}}'); INSERT INTO alerts VALUES(3688,1773079743.433579922,'{"timestamp": "2026-03-09T19:09:03.433580+0100", "flow_id": 2143689229210194, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49323, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 328, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:09:03.433580+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49323, "dest_port": 53}}'); INSERT INTO alerts VALUES(3689,1773079743.433581113,'{"timestamp": "2026-03-09T19:09:03.433581+0100", "flow_id": 2143692462197230, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54858, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47081, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:09:03.433581+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54858, "dest_port": 53}}'); INSERT INTO alerts VALUES(3690,1773079743.433581113,'{"timestamp": "2026-03-09T19:09:03.433581+0100", "flow_id": 2143692187264626, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36411, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:09:03.433581+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56509, "dest_port": 53}}'); INSERT INTO alerts VALUES(3691,1773079754.218211889,'{"timestamp": "2026-03-09T19:09:14.218212+0100", "flow_id": 655741210706119, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 47855, "dest_ip": "134.19.55.199", "dest_port": 3475, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:09:14.218212+0100", "src_ip": "45.142.193.7", "dest_ip": "134.19.55.199", "src_port": 47855, "dest_port": 3475}}'); INSERT INTO alerts VALUES(3692,1773079764.146914959,'{"timestamp": "2026-03-09T19:09:24.146915+0100", "flow_id": 1193948468870344, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:09:24.146915+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3693,1773079764.146915912,'{"timestamp": "2026-03-09T19:09:24.146916+0100", "flow_id": 1193951232116850, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:09:24.146916+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3694,1773079764.146915912,'{"timestamp": "2026-03-09T19:09:24.146916+0100", "flow_id": 1193950623618464, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:09:24.146916+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3695,1773079768.321789979,'{"timestamp": "2026-03-09T19:09:28.321790+0100", "flow_id": 256178090475214, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61439, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54559, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:09:28.321790+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61439, "dest_port": 53}}'); INSERT INTO alerts VALUES(3696,1773079768.323879003,'{"timestamp": "2026-03-09T19:09:28.323879+0100", "flow_id": 265153950506812, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62013, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30491, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:09:28.323879+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62013, "dest_port": 53}}'); INSERT INTO alerts VALUES(3697,1773079768.323879957,'{"timestamp": "2026-03-09T19:09:28.323880+0100", "flow_id": 265154287821942, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63486, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60716, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:09:28.323880+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63486, "dest_port": 53}}'); INSERT INTO alerts VALUES(3698,1773079768.323879957,'{"timestamp": "2026-03-09T19:09:28.323880+0100", "flow_id": 265154176014161, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62464, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61115, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:09:28.323880+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62464, "dest_port": 53}}'); INSERT INTO alerts VALUES(3699,1773079782.53618908,'{"timestamp": "2026-03-09T19:09:42.536189+0100", "flow_id": 1739965349333817, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58617, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63611, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T19:09:42.536189+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58617, "dest_port": 53}}'); INSERT INTO alerts VALUES(3700,1773079784.714601993,'{"timestamp": "2026-03-09T19:09:44.714602+0100", "flow_id": 167194518156482, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 33246, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:09:44.694288+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 33246, "dest_port": 853}}'); INSERT INTO alerts VALUES(3701,1773079784.868817091,'{"timestamp": "2026-03-09T19:09:44.868817+0100", "flow_id": 72368169498648, "event_type": "alert", "src_ip": "185.242.226.60", "src_port": 57593, "dest_ip": "134.19.55.199", "dest_port": 18264, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:09:44.868817+0100", "src_ip": "185.242.226.60", "dest_ip": "134.19.55.199", "src_port": 57593, "dest_port": 18264}}'); INSERT INTO alerts VALUES(3702,1773079794.643763065,'{"timestamp": "2026-03-09T19:09:54.643763+0100", "flow_id": 794619589557448, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:09:54.643763+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3703,1773079794.645272971,'{"timestamp": "2026-03-09T19:09:54.645273+0100", "flow_id": 801103458453618, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:09:54.645273+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3704,1773079794.645272971,'{"timestamp": "2026-03-09T19:09:54.645273+0100", "flow_id": 801102849955232, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:09:54.645273+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3705,1773079807.936966897,'{"timestamp": "2026-03-09T19:10:07.936967+0100", "flow_id": 2244487845192550, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 41418, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:10:07.915801+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 41418, "dest_port": 853}}'); INSERT INTO alerts VALUES(3706,1773079822.583229065,'{"timestamp": "2026-03-09T19:10:22.583229+0100", "flow_id": 1942003210574169, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 56878, "dest_ip": "134.19.55.199", "dest_port": 13397, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:10:22.583229+0100", "src_ip": "79.124.40.82", "dest_ip": "134.19.55.199", "src_port": 56878, "dest_port": 13397}}'); INSERT INTO alerts VALUES(3707,1773079826.140533925,'{"timestamp": "2026-03-09T19:10:26.140534+0100", "flow_id": 603592329133256, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:10:26.140534+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3708,1773079826.140535116,'{"timestamp": "2026-03-09T19:10:26.140535+0100", "flow_id": 603595092379762, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:10:26.140535+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3709,1773079826.140535116,'{"timestamp": "2026-03-09T19:10:26.140535+0100", "flow_id": 603594483881376, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:10:26.140535+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3710,1773079838.477078915,'{"timestamp": "2026-03-09T19:10:38.477079+0100", "flow_id": 1767567870385980, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62013, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30491, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:10:38.477079+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62013, "dest_port": 53}}'); INSERT INTO alerts VALUES(3711,1773079838.477078915,'{"timestamp": "2026-03-09T19:10:38.477079+0100", "flow_id": 1767563912733814, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63486, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60716, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:10:38.477079+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63486, "dest_port": 53}}'); INSERT INTO alerts VALUES(3712,1773079838.477078915,'{"timestamp": "2026-03-09T19:10:38.477079+0100", "flow_id": 1767564197035726, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61439, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54559, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:10:38.477079+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61439, "dest_port": 53}}'); INSERT INTO alerts VALUES(3713,1773079838.477080106,'{"timestamp": "2026-03-09T19:10:38.477080+0100", "flow_id": 1767568095893329, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62464, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61115, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:10:38.477080+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62464, "dest_port": 53}}'); INSERT INTO alerts VALUES(3714,1773079838.477080106,'{"timestamp": "2026-03-09T19:10:38.477080+0100", "flow_id": 1767568659055083, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60365, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41082, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:10:38.477080+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60365, "dest_port": 53}}'); INSERT INTO alerts VALUES(3715,1773079838.477080106,'{"timestamp": "2026-03-09T19:10:38.477080+0100", "flow_id": 1767568493312036, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52681, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7045, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:10:38.477080+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52681, "dest_port": 53}}'); INSERT INTO alerts VALUES(3716,1773079838.477080106,'{"timestamp": "2026-03-09T19:10:38.477080+0100", "flow_id": 1767569185643441, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50780, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45891, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:10:38.477080+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50780, "dest_port": 53}}'); INSERT INTO alerts VALUES(3717,1773079838.477081061,'{"timestamp": "2026-03-09T19:10:38.477081+0100", "flow_id": 1767574692024906, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50565, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5284, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:10:38.477081+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50565, "dest_port": 53}}'); INSERT INTO alerts VALUES(3718,1773079853.909485101,'{"timestamp": "2026-03-09T19:10:53.909485+0100", "flow_id": 1654412569245288, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50877, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61894, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:10:53.909485+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50877, "dest_port": 53}}'); INSERT INTO alerts VALUES(3719,1773079876.929176092,'{"timestamp": "2026-03-09T19:11:16.929176+0100", "flow_id": 1176032128283938, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51082, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65076, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:11:16.929176+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51082, "dest_port": 53}}'); INSERT INTO alerts VALUES(3720,1773079876.929176092,'{"timestamp": "2026-03-09T19:11:16.929176+0100", "flow_id": 1176031438567307, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59829, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57782, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:11:16.929176+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59829, "dest_port": 53}}'); INSERT INTO alerts VALUES(3721,1773079876.929176092,'{"timestamp": "2026-03-09T19:11:16.929176+0100", "flow_id": 1176031183906049, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56727, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1120, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:11:16.929176+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56727, "dest_port": 53}}'); INSERT INTO alerts VALUES(3722,1773079876.929176092,'{"timestamp": "2026-03-09T19:11:16.929176+0100", "flow_id": 1176031299783666, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60085, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39581, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:11:16.929176+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60085, "dest_port": 53}}'); INSERT INTO alerts VALUES(3723,1773079890.369244099,'{"timestamp": "2026-03-09T19:11:30.369244+0100", "flow_id": 741469369269448, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:11:30.369244+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3724,1773079890.369245052,'{"timestamp": "2026-03-09T19:11:30.369245+0100", "flow_id": 741472132515954, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:11:30.369245+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3725,1773079890.369246006,'{"timestamp": "2026-03-09T19:11:30.369246+0100", "flow_id": 741475818984864, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:11:30.369246+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3726,1773079896.918302059,'{"timestamp": "2026-03-09T19:11:36.918302+0100", "flow_id": 3428725197832, "event_type": "alert", "src_ip": "198.235.24.97", "src_port": 50607, "dest_ip": "134.19.55.199", "dest_port": 2001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:11:36.918302+0100", "src_ip": "198.235.24.97", "dest_ip": "134.19.55.199", "src_port": 50607, "dest_port": 2001}}'); INSERT INTO alerts VALUES(3727,1773079904.719311952,'{"timestamp": "2026-03-09T19:11:44.719312+0100", "flow_id": 178118761158701, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 36332, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:11:44.696831+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 36332, "dest_port": 853}}'); INSERT INTO alerts VALUES(3728,1773079908.042032957,'{"timestamp": "2026-03-09T19:11:48.042033+0100", "flow_id": 1306430534614759, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50156, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 736, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T19:11:48.042033+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50156, "dest_port": 53}}'); INSERT INTO alerts VALUES(3729,1773079920.443583966,'{"timestamp": "2026-03-09T19:12:00.443584+0100", "flow_id": 216332307922120, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:12:00.443584+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3730,1773079920.443583966,'{"timestamp": "2026-03-09T19:12:00.443584+0100", "flow_id": 216330776201330, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:12:00.443584+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3731,1773079920.443583966,'{"timestamp": "2026-03-09T19:12:00.443584+0100", "flow_id": 216330167702944, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:12:00.443584+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3732,1773079926.373693944,'{"timestamp": "2026-03-09T19:12:06.373694+0100", "flow_id": 1886479848584482, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51082, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65076, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:12:06.373694+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51082, "dest_port": 53}}'); INSERT INTO alerts VALUES(3733,1773079926.373694897,'{"timestamp": "2026-03-09T19:12:06.373695+0100", "flow_id": 1886483453835147, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59829, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57782, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:12:06.373695+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59829, "dest_port": 53}}'); INSERT INTO alerts VALUES(3734,1773079926.373694897,'{"timestamp": "2026-03-09T19:12:06.373695+0100", "flow_id": 1886483199173889, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56727, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1120, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:12:06.373695+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56727, "dest_port": 53}}'); INSERT INTO alerts VALUES(3735,1773079926.373694897,'{"timestamp": "2026-03-09T19:12:06.373695+0100", "flow_id": 1886483315051506, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60085, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39581, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:12:06.373695+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60085, "dest_port": 53}}'); INSERT INTO alerts VALUES(3736,1773079926.373694897,'{"timestamp": "2026-03-09T19:12:06.373695+0100", "flow_id": 1886485557783692, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49893, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23346, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:12:06.373695+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49893, "dest_port": 53}}'); INSERT INTO alerts VALUES(3737,1773079926.373696088,'{"timestamp": "2026-03-09T19:12:06.373696+0100", "flow_id": 1886490295908530, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50403, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34924, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:12:06.373696+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50403, "dest_port": 53}}'); INSERT INTO alerts VALUES(3738,1773079926.373696088,'{"timestamp": "2026-03-09T19:12:06.373696+0100", "flow_id": 1886489607652830, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50040, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59304, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:12:06.373696+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50040, "dest_port": 53}}'); INSERT INTO alerts VALUES(3739,1773079926.373696088,'{"timestamp": "2026-03-09T19:12:06.373696+0100", "flow_id": 1886490396264322, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58567, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3166, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:12:06.373696+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58567, "dest_port": 53}}'); INSERT INTO alerts VALUES(3740,1773079927.941632987,'{"timestamp": "2026-03-09T19:12:07.941633+0100", "flow_id": 1980678440382705, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39680, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:12:07.919914+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 39680, "dest_port": 853}}'); INSERT INTO alerts VALUES(3741,1773079950.76175809,'{"timestamp": "2026-03-09T19:12:30.761758+0100", "flow_id": 1864354209070280, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:12:30.761758+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3742,1773079950.761759042,'{"timestamp": "2026-03-09T19:12:30.761759+0100", "flow_id": 1864356972316786, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:12:30.761759+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3743,1773079950.761759042,'{"timestamp": "2026-03-09T19:12:30.761759+0100", "flow_id": 1864356363818400, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:12:30.761759+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3744,1773079981.331413985,'{"timestamp": "2026-03-09T19:13:01.331414+0100", "flow_id": 1423415686593736, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:13:01.331414+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3745,1773079981.331414938,'{"timestamp": "2026-03-09T19:13:01.331415+0100", "flow_id": 1423418449840242, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:13:01.331415+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3746,1773079981.331414938,'{"timestamp": "2026-03-09T19:13:01.331415+0100", "flow_id": 1423417841341856, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:13:01.331415+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3747,1773079984.316734075,'{"timestamp": "2026-03-09T19:13:04.316734+0100", "flow_id": 234465042082956, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49893, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23346, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:13:04.316734+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49893, "dest_port": 53}}'); INSERT INTO alerts VALUES(3748,1773079984.316734075,'{"timestamp": "2026-03-09T19:13:04.316734+0100", "flow_id": 234465485240498, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50403, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34924, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:13:04.316734+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50403, "dest_port": 53}}'); INSERT INTO alerts VALUES(3749,1773079984.317037105,'{"timestamp": "2026-03-09T19:13:04.317037+0100", "flow_id": 235766172075486, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50040, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59304, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:13:04.317037+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50040, "dest_port": 53}}'); INSERT INTO alerts VALUES(3750,1773079984.317037105,'{"timestamp": "2026-03-09T19:13:04.317037+0100", "flow_id": 235766960686978, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58567, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3166, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:13:04.317037+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58567, "dest_port": 53}}'); INSERT INTO alerts VALUES(3751,1773079984.317037105,'{"timestamp": "2026-03-09T19:13:04.317037+0100", "flow_id": 235766016486581, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:13:04.317037+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65449, "dest_port": 53}}'); INSERT INTO alerts VALUES(3752,1773079984.317037105,'{"timestamp": "2026-03-09T19:13:04.317037+0100", "flow_id": 235767907464505, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49738, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21883, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:13:04.317037+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49738, "dest_port": 53}}'); INSERT INTO alerts VALUES(3753,1773079984.31703806,'{"timestamp": "2026-03-09T19:13:04.317038+0100", "flow_id": 235769814730992, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63901, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44943, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:13:04.317038+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63901, "dest_port": 53}}'); INSERT INTO alerts VALUES(3754,1773079984.31703806,'{"timestamp": "2026-03-09T19:13:04.317038+0100", "flow_id": 235770208716813, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56178, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:13:04.317038+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56178, "dest_port": 53}}'); INSERT INTO alerts VALUES(3755,1773080011.7810781,'{"timestamp": "2026-03-09T19:13:31.781078+0100", "flow_id": 1102908047097032, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:13:31.781078+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3756,1773080011.7810781,'{"timestamp": "2026-03-09T19:13:31.781078+0100", "flow_id": 1102906515376242, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:13:31.781078+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3757,1773080011.781079053,'{"timestamp": "2026-03-09T19:13:31.781079+0100", "flow_id": 1102910201845152, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:13:31.781079+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3758,1773080013.083383083,'{"timestamp": "2026-03-09T19:13:33.083383+0100", "flow_id": 1484028700777410, "event_type": "alert", "src_ip": "198.235.24.197", "src_port": 18927, "dest_ip": "134.19.55.199", "dest_port": 12746, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T19:13:33.083383+0100", "src_ip": "198.235.24.197", "dest_ip": "134.19.55.199", "src_port": 18927, "dest_port": 12746}}'); INSERT INTO alerts VALUES(3759,1773080019.020374059,'{"timestamp": "2026-03-09T19:13:39.020374+0100", "flow_id": 931934666019007, "event_type": "alert", "src_ip": "147.185.132.76", "src_port": 49575, "dest_ip": "134.19.55.199", "dest_port": 2525, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:13:39.020374+0100", "src_ip": "147.185.132.76", "dest_ip": "134.19.55.199", "src_port": 49575, "dest_port": 2525}}'); INSERT INTO alerts VALUES(3760,1773080041.897969007,'{"timestamp": "2026-03-09T19:14:01.897969+0100", "flow_id": 479051162451144, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:14:01.897969+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3761,1773080041.897969961,'{"timestamp": "2026-03-09T19:14:01.897970+0100", "flow_id": 479053925697650, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:14:01.897970+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3762,1773080041.897969961,'{"timestamp": "2026-03-09T19:14:01.897970+0100", "flow_id": 479053317199264, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:14:01.897970+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3763,1773080047.943825006,'{"timestamp": "2026-03-09T19:14:07.943825+0100", "flow_id": 1993744809925497, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 55028, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:14:07.922956+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 55028, "dest_port": 853}}'); INSERT INTO alerts VALUES(3764,1773080060.133335113,'{"timestamp": "2026-03-09T19:14:20.133335+0100", "flow_id": 1135621794540725, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:14:20.133335+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65449, "dest_port": 53}}'); INSERT INTO alerts VALUES(3765,1773080060.133336067,'{"timestamp": "2026-03-09T19:14:20.133336+0100", "flow_id": 1135627980485945, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49738, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21883, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:14:20.133336+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49738, "dest_port": 53}}'); INSERT INTO alerts VALUES(3766,1773080060.133336067,'{"timestamp": "2026-03-09T19:14:20.133336+0100", "flow_id": 1135625592785136, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63901, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44943, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:14:20.133336+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63901, "dest_port": 53}}'); INSERT INTO alerts VALUES(3767,1773080060.133336067,'{"timestamp": "2026-03-09T19:14:20.133336+0100", "flow_id": 1135627020570231, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64455, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57346, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:14:20.133336+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64455, "dest_port": 53}}'); INSERT INTO alerts VALUES(3768,1773080060.133336067,'{"timestamp": "2026-03-09T19:14:20.133336+0100", "flow_id": 1135627599725529, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52437, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60057, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:14:20.133336+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52437, "dest_port": 53}}'); INSERT INTO alerts VALUES(3769,1773080060.133337021,'{"timestamp": "2026-03-09T19:14:20.133337+0100", "flow_id": 1135629749841342, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61329, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1845, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:14:20.133337+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61329, "dest_port": 53}}'); INSERT INTO alerts VALUES(3770,1773080062.343319892,'{"timestamp": "2026-03-09T19:14:22.343320+0100", "flow_id": 1756026069387035, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51604, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52192, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:14:22.343320+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51604, "dest_port": 53}}'); INSERT INTO alerts VALUES(3771,1773080070.009146928,'{"timestamp": "2026-03-09T19:14:30.009147+0100", "flow_id": 1728137898322193, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60125, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60580, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:14:30.009147+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60125, "dest_port": 53}}'); INSERT INTO alerts VALUES(3772,1773080070.009147883,'{"timestamp": "2026-03-09T19:14:30.009148+0100", "flow_id": 1728140661409554, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53175, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35634, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:14:30.009148+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53175, "dest_port": 53}}'); INSERT INTO alerts VALUES(3773,1773080072.241379977,'{"timestamp": "2026-03-09T19:14:32.241380+0100", "flow_id": 192297670933704, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:14:32.241380+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3774,1773080072.241379977,'{"timestamp": "2026-03-09T19:14:32.241380+0100", "flow_id": 192296139212914, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:14:32.241380+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3775,1773080072.241379977,'{"timestamp": "2026-03-09T19:14:32.241380+0100", "flow_id": 192295530714528, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:14:32.241380+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3776,1773080090.680720091,'{"timestamp": "2026-03-09T19:14:50.680720+0100", "flow_id": 671871664089016, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56709, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56632, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:14:50.680720+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56709, "dest_port": 53}}'); INSERT INTO alerts VALUES(3777,1773080090.680720091,'{"timestamp": "2026-03-09T19:14:50.680720+0100", "flow_id": 671872784507507, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62965, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48526, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:14:50.680720+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62965, "dest_port": 53}}'); INSERT INTO alerts VALUES(3778,1773080090.680720091,'{"timestamp": "2026-03-09T19:14:50.680720+0100", "flow_id": 671871205238646, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62518, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31921, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:14:50.680720+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62518, "dest_port": 53}}'); INSERT INTO alerts VALUES(3779,1773080090.681195975,'{"timestamp": "2026-03-09T19:14:50.681196+0100", "flow_id": 673918699242046, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63346, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6203, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:14:50.681196+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63346, "dest_port": 53}}'); INSERT INTO alerts VALUES(3780,1773080094.518269063,'{"timestamp": "2026-03-09T19:14:54.518269+0100", "flow_id": 1944473723868663, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54222, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1045, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:14:54.518269+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54222, "dest_port": 53}}'); INSERT INTO alerts VALUES(3781,1773080094.518269063,'{"timestamp": "2026-03-09T19:14:54.518269+0100", "flow_id": 1944475090964193, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64059, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48116, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:14:54.518269+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64059, "dest_port": 53}}'); INSERT INTO alerts VALUES(3782,1773080098.810197114,'{"timestamp": "2026-03-09T19:14:58.810197+0100", "flow_id": 665023197006713, "event_type": "alert", "src_ip": "176.65.149.45", "src_port": 42647, "dest_ip": "134.19.55.199", "dest_port": 8081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:14:58.810197+0100", "src_ip": "176.65.149.45", "dest_ip": "134.19.55.199", "src_port": 42647, "dest_port": 8081}}'); INSERT INTO alerts VALUES(3783,1773080103.180777072,'{"timestamp": "2026-03-09T19:15:03.180777+0100", "flow_id": 2183809581579464, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:15:03.180777+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3784,1773080103.180778026,'{"timestamp": "2026-03-09T19:15:03.180778+0100", "flow_id": 2183812344825970, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:15:03.180778+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3785,1773080103.180778026,'{"timestamp": "2026-03-09T19:15:03.180778+0100", "flow_id": 2183811736327584, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:15:03.180778+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3786,1773080136.528063058,'{"timestamp": "2026-03-09T19:15:36.528063+0100", "flow_id": 16217279849190, "event_type": "alert", "src_ip": "147.185.132.119", "src_port": 52273, "dest_ip": "134.19.55.199", "dest_port": 24118, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:15:36.528063+0100", "src_ip": "147.185.132.119", "dest_ip": "134.19.55.199", "src_port": 52273, "dest_port": 24118}}'); INSERT INTO alerts VALUES(3787,1773080149.597914934,'{"timestamp": "2026-03-09T19:15:49.597915+0100", "flow_id": 1442126603578777, "event_type": "alert", "src_ip": "206.189.202.0", "src_port": 47264, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:15:49.597915+0100", "src_ip": "206.189.202.0", "dest_ip": "134.19.55.199", "src_port": 47264, "dest_port": 1433}}'); INSERT INTO alerts VALUES(3788,1773080152.882462024,'{"timestamp": "2026-03-09T19:15:52.882462+0100", "flow_id": 130974825240670, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53601, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:15:52.882462+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53601, "dest_port": 53}}'); INSERT INTO alerts VALUES(3789,1773080152.882462978,'{"timestamp": "2026-03-09T19:15:52.882463+0100", "flow_id": 130977589699914, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52199, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49773, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:15:52.882463+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52199, "dest_port": 53}}'); INSERT INTO alerts VALUES(3790,1773080163.756150008,'{"timestamp": "2026-03-09T19:16:03.756150+0100", "flow_id": 995843102342344, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31279, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:16:03.756150+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50673, "dest_port": 53}}'); INSERT INTO alerts VALUES(3791,1773080163.756150961,'{"timestamp": "2026-03-09T19:16:03.756151+0100", "flow_id": 995845865588850, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61985, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:16:03.756151+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61985, "dest_port": 53}}'); INSERT INTO alerts VALUES(3792,1773080163.756150961,'{"timestamp": "2026-03-09T19:16:03.756151+0100", "flow_id": 995845257090464, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:16:03.756151+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3793,1773080163.756151914,'{"timestamp": "2026-03-09T19:16:03.756152+0100", "flow_id": 995850170121533, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:16:03.756152+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3794,1773080164.946115971,'{"timestamp": "2026-03-09T19:16:04.946116+0100", "flow_id": 1248788463100934, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:16:04.946116+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3795,1773080164.946115971,'{"timestamp": "2026-03-09T19:16:04.946116+0100", "flow_id": 1248790339410323, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:16:04.946116+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3796,1773080167.947623968,'{"timestamp": "2026-03-09T19:16:07.947624+0100", "flow_id": 2002821283646903, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 49766, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:16:07.925070+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 49766, "dest_port": 853}}'); INSERT INTO alerts VALUES(3797,1773080175.19214201,'{"timestamp": "2026-03-09T19:16:15.192142+0100", "flow_id": 2232622293192390, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58298, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49288, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:16:15.192142+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58298, "dest_port": 53}}'); INSERT INTO alerts VALUES(3798,1773080179.975919009,'{"timestamp": "2026-03-09T19:16:19.975919+0100", "flow_id": 1095315634511721, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65089, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41135, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:16:19.975919+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65089, "dest_port": 53}}'); INSERT INTO alerts VALUES(3799,1773080179.975919009,'{"timestamp": "2026-03-09T19:16:19.975919+0100", "flow_id": 1095317787633096, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54505, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11895, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:16:19.975919+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54505, "dest_port": 53}}'); INSERT INTO alerts VALUES(3800,1773080206.665688038,'{"timestamp": "2026-03-09T19:16:46.665688+0100", "flow_id": 1733209125045733, "event_type": "alert", "src_ip": "45.156.87.24", "src_port": 38351, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:16:46.665688+0100", "src_ip": "45.156.87.24", "dest_ip": "134.19.55.199", "src_port": 38351, "dest_port": 5555}}'); INSERT INTO alerts VALUES(3801,1773080210.603929043,'{"timestamp": "2026-03-09T19:16:50.603929+0100", "flow_id": 623531807172536, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56709, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56632, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:16:50.603929+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56709, "dest_port": 53}}'); INSERT INTO alerts VALUES(3802,1773080210.603929043,'{"timestamp": "2026-03-09T19:16:50.603929+0100", "flow_id": 623532927591027, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62965, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48526, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:16:50.603929+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62965, "dest_port": 53}}'); INSERT INTO alerts VALUES(3803,1773080210.603929997,'{"timestamp": "2026-03-09T19:16:50.603930+0100", "flow_id": 623535643289462, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62518, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31921, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:16:50.603930+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62518, "dest_port": 53}}'); INSERT INTO alerts VALUES(3804,1773080210.603929997,'{"timestamp": "2026-03-09T19:16:50.603930+0100", "flow_id": 623538732859966, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63346, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6203, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:16:50.603930+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63346, "dest_port": 53}}'); INSERT INTO alerts VALUES(3805,1773080210.603929997,'{"timestamp": "2026-03-09T19:16:50.603930+0100", "flow_id": 623538502915721, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59295, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 246, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:16:50.603930+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59295, "dest_port": 53}}'); INSERT INTO alerts VALUES(3806,1773080210.603929997,'{"timestamp": "2026-03-09T19:16:50.603930+0100", "flow_id": 623537912496725, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59631, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23041, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:16:50.603930+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59631, "dest_port": 53}}'); INSERT INTO alerts VALUES(3807,1773080210.60393095,'{"timestamp": "2026-03-09T19:16:50.603931+0100", "flow_id": 623541948120079, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62635, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54059, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:16:50.603931+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62635, "dest_port": 53}}'); INSERT INTO alerts VALUES(3808,1773080223.79894209,'{"timestamp": "2026-03-09T19:17:03.798942+0100", "flow_id": 2024055190445031, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:17:03.798942+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3809,1773080223.799412966,'{"timestamp": "2026-03-09T19:17:03.799413+0100", "flow_id": 2026080988603985, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:17:03.799413+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3810,1773080226.73626089,'{"timestamp": "2026-03-09T19:17:06.736261+0100", "flow_id": 628943998926141, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:17:06.736261+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3811,1773080226.73626089,'{"timestamp": "2026-03-09T19:17:06.736261+0100", "flow_id": 628943077909510, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:17:06.736261+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3812,1773080226.736696005,'{"timestamp": "2026-03-09T19:17:06.736696+0100", "flow_id": 630813264992659, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:17:06.736696+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3813,1773080235.577965022,'{"timestamp": "2026-03-09T19:17:15.577965+0100", "flow_id": 1074970085975979, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63583, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29812, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:17:15.577965+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63583, "dest_port": 53}}'); INSERT INTO alerts VALUES(3814,1773080235.599412919,'{"timestamp": "2026-03-09T19:17:15.599413+0100", "flow_id": 885610245873574, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64196, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50597, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:17:15.599413+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64196, "dest_port": 53}}'); INSERT INTO alerts VALUES(3815,1773080237.599981069,'{"timestamp": "2026-03-09T19:17:17.599981+0100", "flow_id": 1451002669829830, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58298, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49288, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:17:17.599981+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58298, "dest_port": 53}}'); INSERT INTO alerts VALUES(3816,1773080246.45555091,'{"timestamp": "2026-03-09T19:17:26.455551+0100", "flow_id": 1956579937947648, "event_type": "alert", "src_ip": "198.235.24.174", "src_port": 52467, "dest_ip": "134.19.55.199", "dest_port": 7170, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:17:26.455551+0100", "src_ip": "198.235.24.174", "dest_ip": "134.19.55.199", "src_port": 52467, "dest_port": 7170}}'); INSERT INTO alerts VALUES(3817,1773080257.864850997,'{"timestamp": "2026-03-09T19:17:37.864851+0100", "flow_id": 336808913386813, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:17:37.864851+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3818,1773080257.864851952,'{"timestamp": "2026-03-09T19:17:37.864852+0100", "flow_id": 336812287337478, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:17:37.864852+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3819,1773080257.864851952,'{"timestamp": "2026-03-09T19:17:37.864852+0100", "flow_id": 336814163646867, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:17:37.864852+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3820,1773080270.894959926,'{"timestamp": "2026-03-09T19:17:50.894960+0100", "flow_id": 1873501271695138, "event_type": "alert", "src_ip": "195.184.76.183", "src_port": 19677, "dest_ip": "134.19.55.199", "dest_port": 5363, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:17:50.894960+0100", "src_ip": "195.184.76.183", "dest_ip": "134.19.55.199", "src_port": 19677, "dest_port": 5363}}'); INSERT INTO alerts VALUES(3821,1773080273.08207202,'{"timestamp": "2026-03-09T19:17:53.082072+0100", "flow_id": 352500664941812, "event_type": "alert", "src_ip": "66.132.153.156", "src_port": 65013, "dest_ip": "134.19.55.199", "dest_port": 1962, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:17:53.082072+0100", "src_ip": "66.132.153.156", "dest_ip": "134.19.55.199", "src_port": 65013, "dest_port": 1962}}'); INSERT INTO alerts VALUES(3822,1773080287.940476895,'{"timestamp": "2026-03-09T19:18:07.940477+0100", "flow_id": 2068994993667389, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:18:07.940477+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3823,1773080287.940478087,'{"timestamp": "2026-03-09T19:18:07.940478+0100", "flow_id": 2068998367618054, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:18:07.940478+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3824,1773080287.940478087,'{"timestamp": "2026-03-09T19:18:07.940478+0100", "flow_id": 2069000243927443, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:18:07.940478+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3825,1773080287.954662085,'{"timestamp": "2026-03-09T19:18:07.954662+0100", "flow_id": 2033043579080905, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 37864, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:18:07.932106+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 37864, "dest_port": 853}}'); INSERT INTO alerts VALUES(3826,1773080307.578289985,'{"timestamp": "2026-03-09T19:18:27.578290+0100", "flow_id": 1076365478580012, "event_type": "alert", "src_ip": "198.235.24.214", "src_port": 52277, "dest_ip": "134.19.55.199", "dest_port": 993, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:18:27.578290+0100", "src_ip": "198.235.24.214", "dest_ip": "134.19.55.199", "src_port": 52277, "dest_port": 993}}'); INSERT INTO alerts VALUES(3827,1773080311.018838882,'{"timestamp": "2026-03-09T19:18:31.018839+0100", "flow_id": 2051240112895549, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65271, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 394, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:18:31.018839+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65271, "dest_port": 53}}'); INSERT INTO alerts VALUES(3828,1773080311.021241903,'{"timestamp": "2026-03-09T19:18:31.021242+0100", "flow_id": 2061562603365516, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51204, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22067, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:18:31.021242+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51204, "dest_port": 53}}'); INSERT INTO alerts VALUES(3829,1773080318.840732098,'{"timestamp": "2026-03-09T19:18:38.840732+0100", "flow_id": 1922068117317589, "event_type": "alert", "src_ip": "130.12.180.65", "src_port": 41291, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:18:38.840732+0100", "src_ip": "130.12.180.65", "dest_ip": "134.19.55.199", "src_port": 41291, "dest_port": 5555}}'); INSERT INTO alerts VALUES(3830,1773080318.840732098,'{"timestamp": "2026-03-09T19:18:38.840732+0100", "flow_id": 1922068117317589, "event_type": "alert", "src_ip": "130.12.180.65", "src_port": 41291, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:18:38.840732+0100", "src_ip": "130.12.180.65", "dest_ip": "134.19.55.199", "src_port": 41291, "dest_port": 5555}}'); INSERT INTO alerts VALUES(3831,1773080318.979753972,'{"timestamp": "2026-03-09T19:18:38.979754+0100", "flow_id": 1956213447441725, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:18:38.979754+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3832,1773080318.979754925,'{"timestamp": "2026-03-09T19:18:38.979755+0100", "flow_id": 1956216821392390, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:18:38.979755+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3833,1773080318.979754925,'{"timestamp": "2026-03-09T19:18:38.979755+0100", "flow_id": 1956218697701779, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:18:38.979755+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3834,1773080341.681224108,'{"timestamp": "2026-03-09T19:19:01.681224+0100", "flow_id": 1518463658514057, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59295, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 246, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:19:01.681224+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59295, "dest_port": 53}}'); INSERT INTO alerts VALUES(3835,1773080341.681225061,'{"timestamp": "2026-03-09T19:19:01.681225+0100", "flow_id": 1518467103718415, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62635, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54059, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:19:01.681225+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62635, "dest_port": 53}}'); INSERT INTO alerts VALUES(3836,1773080341.681225061,'{"timestamp": "2026-03-09T19:19:01.681225+0100", "flow_id": 1518467363062357, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59631, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23041, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:19:01.681225+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59631, "dest_port": 53}}'); INSERT INTO alerts VALUES(3837,1773080341.681225061,'{"timestamp": "2026-03-09T19:19:01.681225+0100", "flow_id": 1518467515577775, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56510, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48600, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:19:01.681225+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56510, "dest_port": 53}}'); INSERT INTO alerts VALUES(3838,1773080341.681225061,'{"timestamp": "2026-03-09T19:19:01.681225+0100", "flow_id": 1518465379816011, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59661, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17710, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:19:01.681225+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59661, "dest_port": 53}}'); INSERT INTO alerts VALUES(3839,1773080341.681226015,'{"timestamp": "2026-03-09T19:19:01.681226+0100", "flow_id": 1518471985039387, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:19:01.681226+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63468, "dest_port": 53}}'); INSERT INTO alerts VALUES(3840,1773080341.681226015,'{"timestamp": "2026-03-09T19:19:01.681226+0100", "flow_id": 1518469821605478, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:19:01.681226+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62064, "dest_port": 53}}'); INSERT INTO alerts VALUES(3841,1773080341.681226015,'{"timestamp": "2026-03-09T19:19:01.681226+0100", "flow_id": 1518471763161457, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53801, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13414, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:19:01.681226+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53801, "dest_port": 53}}'); INSERT INTO alerts VALUES(3842,1773080350.257841111,'{"timestamp": "2026-03-09T19:19:10.257841+0100", "flow_id": 1951845465701693, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:19:10.257841+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3843,1773080350.257841111,'{"timestamp": "2026-03-09T19:19:10.257841+0100", "flow_id": 1951844544685062, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:19:10.257841+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3844,1773080350.257841111,'{"timestamp": "2026-03-09T19:19:10.257841+0100", "flow_id": 1951846420994451, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:19:10.257841+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3845,1773080354.204756976,'{"timestamp": "2026-03-09T19:19:14.204757+0100", "flow_id": 597952548565011, "event_type": "alert", "src_ip": "185.242.226.95", "src_port": 53756, "dest_ip": "134.19.55.199", "dest_port": 8501, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:19:14.204757+0100", "src_ip": "185.242.226.95", "dest_ip": "134.19.55.199", "src_port": 53756, "dest_port": 8501}}'); INSERT INTO alerts VALUES(3846,1773080372.045969009,'{"timestamp": "2026-03-09T19:19:32.045969+0100", "flow_id": 1323337190385075, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65337, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57220, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:19:32.045969+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65337, "dest_port": 53}}'); INSERT INTO alerts VALUES(3847,1773080372.045969963,'{"timestamp": "2026-03-09T19:19:32.045970+0100", "flow_id": 1323343218314353, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51330, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29027, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:19:32.045970+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51330, "dest_port": 53}}'); INSERT INTO alerts VALUES(3848,1773080381.153645993,'{"timestamp": "2026-03-09T19:19:41.153646+0100", "flow_id": 1504331348294973, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:19:41.153646+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3849,1773080381.153650999,'{"timestamp": "2026-03-09T19:19:41.153651+0100", "flow_id": 1504351902114822, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:19:41.153651+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3850,1773080381.153650999,'{"timestamp": "2026-03-09T19:19:41.153651+0100", "flow_id": 1504353778424211, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:19:41.153651+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3851,1773080401.453485966,'{"timestamp": "2026-03-09T19:20:01.453486+0100", "flow_id": 540336772654487, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56118, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4918, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:20:01.453486+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56118, "dest_port": 53}}'); INSERT INTO alerts VALUES(3852,1773080401.45380497,'{"timestamp": "2026-03-09T19:20:01.453805+0100", "flow_id": 541703603448875, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52949, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48979, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:20:01.453805+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52949, "dest_port": 53}}'); INSERT INTO alerts VALUES(3853,1773080407.956163883,'{"timestamp": "2026-03-09T19:20:07.956164+0100", "flow_id": 2044567191550748, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 52018, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:20:07.934789+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 52018, "dest_port": 853}}'); INSERT INTO alerts VALUES(3854,1773080411.169861079,'{"timestamp": "2026-03-09T19:20:11.169861+0100", "flow_id": 1011024289578301, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:20:11.169861+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3855,1773080411.169861079,'{"timestamp": "2026-03-09T19:20:11.169861+0100", "flow_id": 1011023368561670, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:20:11.169861+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3856,1773080411.169862032,'{"timestamp": "2026-03-09T19:20:11.169862+0100", "flow_id": 1011029539838355, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:20:11.169862+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3857,1773080426.266305924,'{"timestamp": "2026-03-09T19:20:26.266306+0100", "flow_id": 580829084715035, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:20:26.266306+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63468, "dest_port": 53}}'); INSERT INTO alerts VALUES(3858,1773080426.266305924,'{"timestamp": "2026-03-09T19:20:26.266306+0100", "flow_id": 580826921281126, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:20:26.266306+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62064, "dest_port": 53}}'); INSERT INTO alerts VALUES(3859,1773080428.582957984,'{"timestamp": "2026-03-09T19:20:28.582958+0100", "flow_id": 1377887962774332, "event_type": "alert", "src_ip": "167.94.138.132", "src_port": 35767, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:20:28.582958+0100", "src_ip": "167.94.138.132", "dest_ip": "134.19.55.199", "src_port": 35767, "dest_port": 27017}}'); INSERT INTO alerts VALUES(3860,1773080440.082478047,'{"timestamp": "2026-03-09T19:20:40.082478+0100", "flow_id": 72765834737399, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63430, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29353, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:20:40.082478+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63430, "dest_port": 53}}'); INSERT INTO alerts VALUES(3861,1773080440.082796096,'{"timestamp": "2026-03-09T19:20:40.082796+0100", "flow_id": 74134923539660, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50349, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25508, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:20:40.082796+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50349, "dest_port": 53}}'); INSERT INTO alerts VALUES(3862,1773080441.22535491,'{"timestamp": "2026-03-09T19:20:41.225355+0100", "flow_id": 404942669127456, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54657, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:20:41.225355+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3863,1773080450.463699103,'{"timestamp": "2026-03-09T19:20:50.463699+0100", "flow_id": 584197430935046, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58497, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51870, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:20:50.463699+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58497, "dest_port": 53}}'); INSERT INTO alerts VALUES(3864,1773080450.463700056,'{"timestamp": "2026-03-09T19:20:50.463700+0100", "flow_id": 584204586470471, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65490, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33304, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:20:50.463700+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65490, "dest_port": 53}}'); INSERT INTO alerts VALUES(3865,1773080456.306353093,'{"timestamp": "2026-03-09T19:20:56.306353+0100", "flow_id": 189876521786343, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:20:56.306353+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3866,1773080456.306353093,'{"timestamp": "2026-03-09T19:20:56.306353+0100", "flow_id": 189879390348881, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:20:56.306353+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3867,1773080481.78717208,'{"timestamp": "2026-03-09T19:21:21.787172+0100", "flow_id": 284655125511485, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:21:21.787172+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3868,1773080481.787173033,'{"timestamp": "2026-03-09T19:21:21.787173+0100", "flow_id": 284658499462150, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:21:21.787173+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3869,1773080481.787525892,'{"timestamp": "2026-03-09T19:21:21.787526+0100", "flow_id": 286176499227027, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:21:21.787526+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3870,1773080484.140244961,'{"timestamp": "2026-03-09T19:21:24.140245+0100", "flow_id": 1165298161693749, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55139, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11286, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:21:24.140245+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55139, "dest_port": 53}}'); INSERT INTO alerts VALUES(3871,1773080484.140245915,'{"timestamp": "2026-03-09T19:21:24.140246+0100", "flow_id": 1165306132721117, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60925, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29491, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:21:24.140246+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60925, "dest_port": 53}}'); INSERT INTO alerts VALUES(3872,1773080486.790563106,'{"timestamp": "2026-03-09T19:21:26.790563+0100", "flow_id": 1706592682761191, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:21:26.790563+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3873,1773080486.790563106,'{"timestamp": "2026-03-09T19:21:26.790563+0100", "flow_id": 1706595551323729, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:21:26.790563+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3874,1773080493.77604103,'{"timestamp": "2026-03-09T19:21:33.776041+0100", "flow_id": 1644222007433359, "event_type": "alert", "src_ip": "178.20.210.152", "src_port": 54473, "dest_ip": "134.19.55.199", "dest_port": 2022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:21:33.776041+0100", "src_ip": "178.20.210.152", "dest_ip": "134.19.55.199", "src_port": 54473, "dest_port": 2022}}'); INSERT INTO alerts VALUES(3875,1773080510.894769907,'{"timestamp": "2026-03-09T19:21:50.894770+0100", "flow_id": 1872684317650896, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55762, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34692, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:21:50.894770+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55762, "dest_port": 53}}'); INSERT INTO alerts VALUES(3876,1773080510.8947711,'{"timestamp": "2026-03-09T19:21:50.894771+0100", "flow_id": 1872688735898565, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46633, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:21:50.894771+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58367, "dest_port": 53}}'); INSERT INTO alerts VALUES(3877,1773080512.604398965,'{"timestamp": "2026-03-09T19:21:52.604399+0100", "flow_id": 62601021340989, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:21:52.604399+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3878,1773080512.604398965,'{"timestamp": "2026-03-09T19:21:52.604399+0100", "flow_id": 62600100324358, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:21:52.604399+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3879,1773080512.604398965,'{"timestamp": "2026-03-09T19:21:52.604399+0100", "flow_id": 62601976633747, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:21:52.604399+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3880,1773080516.219923973,'{"timestamp": "2026-03-09T19:21:56.219924+0100", "flow_id": 1226044841723931, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:21:56.219924+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63468, "dest_port": 53}}'); INSERT INTO alerts VALUES(3881,1773080516.219923973,'{"timestamp": "2026-03-09T19:21:56.219924+0100", "flow_id": 1226042678290022, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:21:56.219924+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62064, "dest_port": 53}}'); INSERT INTO alerts VALUES(3882,1773080517.851502895,'{"timestamp": "2026-03-09T19:21:57.851503+0100", "flow_id": 1686853013068775, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:21:57.851503+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3883,1773080517.851504088,'{"timestamp": "2026-03-09T19:21:57.851504+0100", "flow_id": 1686860176598609, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:21:57.851504+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3884,1773080518.687549115,'{"timestamp": "2026-03-09T19:21:58.687549+0100", "flow_id": 1827101888957688, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 12902, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:21:58.687549+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 12902}}'); INSERT INTO alerts VALUES(3885,1773080522.70173812,'{"timestamp": "2026-03-09T19:22:02.701738+0100", "flow_id": 762142719882156, "event_type": "alert", "src_ip": "198.235.24.50", "src_port": 56032, "dest_ip": "134.19.55.199", "dest_port": 10001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:22:02.701738+0100", "src_ip": "198.235.24.50", "dest_ip": "134.19.55.199", "src_port": 56032, "dest_port": 10001}}'); INSERT INTO alerts VALUES(3886,1773080527.959486962,'{"timestamp": "2026-03-09T19:22:07.959487+0100", "flow_id": 2057349763197406, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 42602, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:22:07.937766+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 42602, "dest_port": 853}}'); INSERT INTO alerts VALUES(3887,1773080532.185655117,'{"timestamp": "2026-03-09T19:22:12.185655+0100", "flow_id": 1360333273911883, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59661, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17710, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:22:12.185655+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59661, "dest_port": 53}}'); INSERT INTO alerts VALUES(3888,1773080538.12502098,'{"timestamp": "2026-03-09T19:22:18.125021+0100", "flow_id": 818439877238364, "event_type": "alert", "src_ip": "91.196.152.84", "src_port": 31427, "dest_ip": "134.19.55.199", "dest_port": 3260, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:22:18.125021+0100", "src_ip": "91.196.152.84", "dest_ip": "134.19.55.199", "src_port": 31427, "dest_port": 3260}}'); INSERT INTO alerts VALUES(3889,1773080544.07949996,'{"timestamp": "2026-03-09T19:22:24.079500+0100", "flow_id": 59976796323133, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:22:24.079500+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3890,1773080544.07949996,'{"timestamp": "2026-03-09T19:22:24.079500+0100", "flow_id": 59975875306502, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:22:24.079500+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3891,1773080544.07949996,'{"timestamp": "2026-03-09T19:22:24.079500+0100", "flow_id": 59977751615891, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:22:24.079500+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3892,1773080546.558128119,'{"timestamp": "2026-03-09T19:22:26.558128+0100", "flow_id": 708295124125723, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:22:26.558128+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63468, "dest_port": 53}}'); INSERT INTO alerts VALUES(3893,1773080546.558128119,'{"timestamp": "2026-03-09T19:22:26.558128+0100", "flow_id": 708292960691814, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:22:26.558128+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62064, "dest_port": 53}}'); INSERT INTO alerts VALUES(3894,1773080548.288096905,'{"timestamp": "2026-03-09T19:22:28.288097+0100", "flow_id": 1237367505673191, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:22:28.288097+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3895,1773080548.288096905,'{"timestamp": "2026-03-09T19:22:28.288097+0100", "flow_id": 1237370374235729, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:22:28.288097+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3896,1773080574.148272038,'{"timestamp": "2026-03-09T19:22:54.148272+0100", "flow_id": 1762725170756925, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:22:54.148272+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3897,1773080574.148272038,'{"timestamp": "2026-03-09T19:22:54.148272+0100", "flow_id": 1762724249740294, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:22:54.148272+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3898,1773080574.148272038,'{"timestamp": "2026-03-09T19:22:54.148272+0100", "flow_id": 1762726126049683, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:22:54.148272+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3899,1773080578.882489919,'{"timestamp": "2026-03-09T19:22:58.882490+0100", "flow_id": 694041257827303, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:22:58.882490+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3900,1773080578.882491112,'{"timestamp": "2026-03-09T19:22:58.882491+0100", "flow_id": 694048421357137, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:22:58.882491+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3901,1773080582.100594997,'{"timestamp": "2026-03-09T19:23:02.100595+0100", "flow_id": 1839430545989312, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54870, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4166, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:23:02.100595+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54870, "dest_port": 53}}'); INSERT INTO alerts VALUES(3902,1773080582.100595952,'{"timestamp": "2026-03-09T19:23:02.100596+0100", "flow_id": 1839432254332475, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50624, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43818, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:23:02.100596+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50624, "dest_port": 53}}'); INSERT INTO alerts VALUES(3903,1773080606.586654902,'{"timestamp": "2026-03-09T19:23:26.586655+0100", "flow_id": 1956715958615357, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:23:26.586655+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56562, "dest_port": 53}}'); INSERT INTO alerts VALUES(3904,1773080606.586654902,'{"timestamp": "2026-03-09T19:23:26.586655+0100", "flow_id": 1956715037598726, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51231, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:23:26.586655+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51231, "dest_port": 53}}'); INSERT INTO alerts VALUES(3905,1773080606.586654902,'{"timestamp": "2026-03-09T19:23:26.586655+0100", "flow_id": 1956716913908115, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64272, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9014, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:23:26.586655+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64272, "dest_port": 53}}'); INSERT INTO alerts VALUES(3906,1773080606.586656093,'{"timestamp": "2026-03-09T19:23:26.586656+0100", "flow_id": 1956719880281569, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:23:26.586656+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3907,1773080606.586657047,'{"timestamp": "2026-03-09T19:23:26.586657+0100", "flow_id": 1956724353730814, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56197, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18680, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:23:26.586657+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56197, "dest_port": 53}}'); INSERT INTO alerts VALUES(3908,1773080608.651268006,'{"timestamp": "2026-03-09T19:23:28.651268+0100", "flow_id": 263903218123089, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:23:28.651268+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(3909,1773080608.651268959,'{"timestamp": "2026-03-09T19:23:28.651269+0100", "flow_id": 263905368951165, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:23:28.651269+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(3910,1773080610.046775102,'{"timestamp": "2026-03-09T19:23:30.046775+0100", "flow_id": 763847361289191, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:23:30.046775+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3911,1773080610.046775102,'{"timestamp": "2026-03-09T19:23:30.046775+0100", "flow_id": 763850229851729, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:23:30.046775+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3912,1773080612.17562008,'{"timestamp": "2026-03-09T19:23:32.175620+0100", "flow_id": 1317233277096523, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59661, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17710, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:23:32.175620+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59661, "dest_port": 53}}'); INSERT INTO alerts VALUES(3913,1773080619.074193954,'{"timestamp": "2026-03-09T19:23:39.074194+0100", "flow_id": 881612149555547, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51035, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62946, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:23:39.074194+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51035, "dest_port": 53}}'); INSERT INTO alerts VALUES(3914,1773080635.284094096,'{"timestamp": "2026-03-09T19:23:55.284094+0100", "flow_id": 938702939686939, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:23:55.284094+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63468, "dest_port": 53}}'); INSERT INTO alerts VALUES(3915,1773080635.284094096,'{"timestamp": "2026-03-09T19:23:55.284094+0100", "flow_id": 938700776253030, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:23:55.284094+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62064, "dest_port": 53}}'); INSERT INTO alerts VALUES(3916,1773080641.298329114,'{"timestamp": "2026-03-09T19:24:01.298329+0100", "flow_id": 436888680913895, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:24:01.298329+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3917,1773080641.298329114,'{"timestamp": "2026-03-09T19:24:01.298329+0100", "flow_id": 436891549476433, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:24:01.298329+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3918,1773080642.82457304,'{"timestamp": "2026-03-09T19:24:02.824573+0100", "flow_id": 726765468209739, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59661, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17710, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:24:02.824573+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59661, "dest_port": 53}}'); INSERT INTO alerts VALUES(3919,1773080647.959736108,'{"timestamp": "2026-03-09T19:24:07.959736+0100", "flow_id": 2064300326835680, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 57912, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:24:07.939384+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 57912, "dest_port": 853}}'); INSERT INTO alerts VALUES(3920,1773080651.983206987,'{"timestamp": "2026-03-09T19:24:11.983207+0100", "flow_id": 845143055961728, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62400, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 793, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:24:11.983207+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62400, "dest_port": 53}}'); INSERT INTO alerts VALUES(3921,1773080651.983769893,'{"timestamp": "2026-03-09T19:24:11.983770+0100", "flow_id": 847563012458601, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62496, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43440, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:24:11.983770+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62496, "dest_port": 53}}'); INSERT INTO alerts VALUES(3922,1773080668.958009005,'{"timestamp": "2026-03-09T19:24:28.958009+0100", "flow_id": 1299869056867809, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:24:28.958009+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3923,1773080670.894670963,'{"timestamp": "2026-03-09T19:24:30.894671+0100", "flow_id": 1872260018058476, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57430, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5756, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:24:30.894671+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57430, "dest_port": 53}}'); INSERT INTO alerts VALUES(3924,1773080670.894670963,'{"timestamp": "2026-03-09T19:24:30.894671+0100", "flow_id": 1872258986978924, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59496, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21919, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:24:30.894671+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59496, "dest_port": 53}}'); INSERT INTO alerts VALUES(3925,1773080671.787972927,'{"timestamp": "2026-03-09T19:24:31.787973+0100", "flow_id": 1976946629165393, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:24:31.787973+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(3926,1773080671.787972927,'{"timestamp": "2026-03-09T19:24:31.787973+0100", "flow_id": 1976944485026173, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:24:31.787973+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(3927,1773080679.255752087,'{"timestamp": "2026-03-09T19:24:39.255752+0100", "flow_id": 2224346926449261, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60429, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5548, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:24:39.255752+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60429, "dest_port": 53}}'); INSERT INTO alerts VALUES(3928,1773080699.345844985,'{"timestamp": "2026-03-09T19:24:59.345845+0100", "flow_id": 922444510764513, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:24:59.345845+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3929,1773080702.448570014,'{"timestamp": "2026-03-09T19:25:02.448570+0100", "flow_id": 1926596727554385, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:25:02.448570+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(3930,1773080702.448570014,'{"timestamp": "2026-03-09T19:25:02.448570+0100", "flow_id": 1926594583415165, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:25:02.448570+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(3931,1773080717.086297036,'{"timestamp": "2026-03-09T19:25:17.086297+0100", "flow_id": 1496546176993307, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:25:17.086297+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63468, "dest_port": 53}}'); INSERT INTO alerts VALUES(3932,1773080717.086297036,'{"timestamp": "2026-03-09T19:25:17.086297+0100", "flow_id": 1496544013559398, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:25:17.086297+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62064, "dest_port": 53}}'); INSERT INTO alerts VALUES(3933,1773080717.3566401,'{"timestamp": "2026-03-09T19:25:17.356640+0100", "flow_id": 1531759964506918, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46116, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:25:17.356640+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3934,1773080717.3566401,'{"timestamp": "2026-03-09T19:25:17.356640+0100", "flow_id": 1531761262272292, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56432, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59500, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:25:17.356640+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56432, "dest_port": 53}}'); INSERT INTO alerts VALUES(3935,1773080720.20126295,'{"timestamp": "2026-03-09T19:25:20.201263+0100", "flow_id": 19993385360359, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:25:20.201263+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3936,1773080720.201263904,'{"timestamp": "2026-03-09T19:25:20.201264+0100", "flow_id": 20000548890193, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:25:20.201264+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3937,1773080720.201263904,'{"timestamp": "2026-03-09T19:25:20.201264+0100", "flow_id": 19998234021504, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62400, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 793, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:25:20.201264+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62400, "dest_port": 53}}'); INSERT INTO alerts VALUES(3938,1773080720.201263904,'{"timestamp": "2026-03-09T19:25:20.201264+0100", "flow_id": 20000123930729, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62496, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43440, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:25:20.201264+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62496, "dest_port": 53}}'); INSERT INTO alerts VALUES(3939,1773080729.5508039,'{"timestamp": "2026-03-09T19:25:29.550804+0100", "flow_id": 395361829232097, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:25:29.550804+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3940,1773080733.916743041,'{"timestamp": "2026-03-09T19:25:33.916743+0100", "flow_id": 1685584637739345, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:25:33.916743+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(3941,1773080733.916743993,'{"timestamp": "2026-03-09T19:25:33.916744+0100", "flow_id": 1685586788567421, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:25:33.916744+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(3942,1773080747.864249944,'{"timestamp": "2026-03-09T19:25:47.864250+0100", "flow_id": 897179195869211, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:25:47.864250+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63468, "dest_port": 53}}'); INSERT INTO alerts VALUES(3943,1773080747.864249944,'{"timestamp": "2026-03-09T19:25:47.864250+0100", "flow_id": 897177032435302, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:25:47.864250+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62064, "dest_port": 53}}'); INSERT INTO alerts VALUES(3944,1773080748.938597917,'{"timestamp": "2026-03-09T19:25:48.938598+0100", "flow_id": 1216501285842313, "event_type": "alert", "src_ip": "51.38.211.50", "src_port": 5137, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 438, "bytes_toclient": 0, "start": "2026-03-09T19:25:48.938598+0100", "src_ip": "51.38.211.50", "dest_ip": "134.19.55.199", "src_port": 5137, "dest_port": 5060}}'); INSERT INTO alerts VALUES(3945,1773080748.938597917,'{"timestamp": "2026-03-09T19:25:48.938598+0100", "flow_id": 1216501285842313, "event_type": "alert", "src_ip": "51.38.211.50", "src_port": 5137, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "sip", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 438, "bytes_toclient": 0, "start": "2026-03-09T19:25:48.938598+0100", "src_ip": "51.38.211.50", "dest_ip": "134.19.55.199", "src_port": 5137, "dest_port": 5060}}'); INSERT INTO alerts VALUES(3946,1773080751.400516034,'{"timestamp": "2026-03-09T19:25:51.400516+0100", "flow_id": 2001678410832871, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:25:51.400516+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3947,1773080751.400516034,'{"timestamp": "2026-03-09T19:25:51.400516+0100", "flow_id": 2001681279395409, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:25:51.400516+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3948,1773080751.400516986,'{"timestamp": "2026-03-09T19:25:51.400517+0100", "flow_id": 2001683259494016, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62400, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 793, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:25:51.400517+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62400, "dest_port": 53}}'); INSERT INTO alerts VALUES(3949,1773080751.400516986,'{"timestamp": "2026-03-09T19:25:51.400517+0100", "flow_id": 2001685149403241, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62496, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43440, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T19:25:51.400517+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62496, "dest_port": 53}}'); INSERT INTO alerts VALUES(3950,1773080753.475790978,'{"timestamp": "2026-03-09T19:25:53.475791+0100", "flow_id": 354658288812869, "event_type": "alert", "src_ip": "193.163.125.208", "src_port": 39701, "dest_ip": "134.19.55.199", "dest_port": 6881, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:25:53.475791+0100", "src_ip": "193.163.125.208", "dest_ip": "134.19.55.199", "src_port": 39701, "dest_port": 6881}}'); INSERT INTO alerts VALUES(3951,1773080756.205193042,'{"timestamp": "2026-03-09T19:25:56.205193+0100", "flow_id": 1162774334458865, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53783, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53756, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:25:56.205193+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53783, "dest_port": 53}}'); INSERT INTO alerts VALUES(3952,1773080756.205193042,'{"timestamp": "2026-03-09T19:25:56.205193+0100", "flow_id": 1162775968270135, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65145, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10719, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:25:56.205193+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65145, "dest_port": 53}}'); INSERT INTO alerts VALUES(3953,1773080760.894606113,'{"timestamp": "2026-03-09T19:26:00.894606+0100", "flow_id": 183130315267553, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:26:00.894606+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3954,1773080765.375550031,'{"timestamp": "2026-03-09T19:26:05.375550+0100", "flow_id": 1612978215600465, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:26:05.375550+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(3955,1773080765.375550985,'{"timestamp": "2026-03-09T19:26:05.375551+0100", "flow_id": 1612980366428541, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:26:05.375551+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(3956,1773080767.725554944,'{"timestamp": "2026-03-09T19:26:07.725555+0100", "flow_id": 1990336079196419, "event_type": "alert", "src_ip": "91.196.152.76", "src_port": 62140, "dest_ip": "134.19.55.199", "dest_port": 2022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:26:07.725555+0100", "src_ip": "91.196.152.76", "dest_ip": "134.19.55.199", "src_port": 62140, "dest_port": 2022}}'); INSERT INTO alerts VALUES(3957,1773080774.197581053,'{"timestamp": "2026-03-09T19:26:14.197581+0100", "flow_id": 1693028925972171, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54573, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15715, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:26:14.197581+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54573, "dest_port": 53}}'); INSERT INTO alerts VALUES(3958,1773080777.95311594,'{"timestamp": "2026-03-09T19:26:17.953116+0100", "flow_id": 434427638027110, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50803, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3188, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:26:17.953116+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50803, "dest_port": 53}}'); INSERT INTO alerts VALUES(3959,1773080777.953116894,'{"timestamp": "2026-03-09T19:26:17.953117+0100", "flow_id": 434433178719923, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49200, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57071, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:26:17.953117+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49200, "dest_port": 53}}'); INSERT INTO alerts VALUES(3960,1773080778.0130589,'{"timestamp": "2026-03-09T19:26:18.013059+0100", "flow_id": 619041408747547, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:26:18.013059+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63468, "dest_port": 53}}'); INSERT INTO alerts VALUES(3961,1773080778.013659,'{"timestamp": "2026-03-09T19:26:18.013659+0100", "flow_id": 621616225691238, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:26:18.013659+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62064, "dest_port": 53}}'); INSERT INTO alerts VALUES(3962,1773080782.814590931,'{"timestamp": "2026-03-09T19:26:22.814591+0100", "flow_id": 1809792156949479, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:26:22.814591+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3963,1773080782.814590931,'{"timestamp": "2026-03-09T19:26:22.814591+0100", "flow_id": 1809795025512017, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:26:22.814591+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3964,1773080787.090039015,'{"timestamp": "2026-03-09T19:26:27.090039+0100", "flow_id": 949664745085592, "event_type": "alert", "src_ip": "167.94.138.136", "src_port": 63970, "dest_ip": "134.19.55.199", "dest_port": 5986, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:26:27.090039+0100", "src_ip": "167.94.138.136", "dest_ip": "134.19.55.199", "src_port": 63970, "dest_port": 5986}}'); INSERT INTO alerts VALUES(3965,1773080792.194843054,'{"timestamp": "2026-03-09T19:26:32.194843+0100", "flow_id": 273895859133921, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:26:32.194843+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3966,1773080795.725042105,'{"timestamp": "2026-03-09T19:26:35.725042+0100", "flow_id": 862235112128849, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:26:35.725042+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(3967,1773080795.725042105,'{"timestamp": "2026-03-09T19:26:35.725042+0100", "flow_id": 862232967989629, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:26:35.725042+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(3968,1773080802.568914891,'{"timestamp": "2026-03-09T19:26:42.568915+0100", "flow_id": 754625462046280, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56250, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10751, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:26:42.568915+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56250, "dest_port": 53}}'); INSERT INTO alerts VALUES(3969,1773080809.504775048,'{"timestamp": "2026-03-09T19:26:49.504775+0100", "flow_id": 479145733982235, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:26:49.504775+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63468, "dest_port": 53}}'); INSERT INTO alerts VALUES(3970,1773080809.504775048,'{"timestamp": "2026-03-09T19:26:49.504775+0100", "flow_id": 479143570548326, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:26:49.504775+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62064, "dest_port": 53}}'); INSERT INTO alerts VALUES(3971,1773080814.246582985,'{"timestamp": "2026-03-09T19:26:54.246583+0100", "flow_id": 1903491163479015, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:26:54.246583+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3972,1773080814.246582985,'{"timestamp": "2026-03-09T19:26:54.246583+0100", "flow_id": 1903494032041553, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:26:54.246583+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3973,1773080815.169727087,'{"timestamp": "2026-03-09T19:26:55.169727+0100", "flow_id": 2136347893077307, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61194, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5431, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:26:55.169727+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61194, "dest_port": 53}}'); INSERT INTO alerts VALUES(3974,1773080815.169727087,'{"timestamp": "2026-03-09T19:26:55.169727+0100", "flow_id": 2136349847414245, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56637, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:26:55.169727+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53006, "dest_port": 53}}'); INSERT INTO alerts VALUES(3975,1773080823.281053067,'{"timestamp": "2026-03-09T19:27:03.281053+0100", "flow_id": 2051541500501822, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64748, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4983, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:27:03.281053+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64748, "dest_port": 53}}'); INSERT INTO alerts VALUES(3976,1773080823.28166008,'{"timestamp": "2026-03-09T19:27:03.281660+0100", "flow_id": 2054147631102946, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60899, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18895, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:27:03.281660+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60899, "dest_port": 53}}'); INSERT INTO alerts VALUES(3977,1773080823.396039009,'{"timestamp": "2026-03-09T19:27:03.396039+0100", "flow_id": 1982451029351905, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:27:03.396039+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3978,1773080825.172445059,'{"timestamp": "2026-03-09T19:27:05.172445+0100", "flow_id": 459171879518810, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62439, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:27:05.172445+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62439, "dest_port": 53}}'); INSERT INTO alerts VALUES(3979,1773080826.111982107,'{"timestamp": "2026-03-09T19:27:06.111982+0100", "flow_id": 762437252038993, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:27:06.111982+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(3980,1773080826.111983061,'{"timestamp": "2026-03-09T19:27:06.111983+0100", "flow_id": 762439402867069, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:27:06.111983+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(3981,1773080839.095961093,'{"timestamp": "2026-03-09T19:27:19.095961+0100", "flow_id": 2101003069307796, "event_type": "alert", "src_ip": "176.65.149.180", "src_port": 51866, "dest_ip": "134.19.55.199", "dest_port": 8265, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:27:19.095961+0100", "src_ip": "176.65.149.180", "dest_ip": "134.19.55.199", "src_port": 51866, "dest_port": 8265}}'); INSERT INTO alerts VALUES(3982,1773080845.099422932,'{"timestamp": "2026-03-09T19:27:25.099423+0100", "flow_id": 1552918752910311, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:27:25.099423+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3983,1773080845.100078105,'{"timestamp": "2026-03-09T19:27:25.100078+0100", "flow_id": 1555734825051729, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:27:25.100078+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3984,1773080846.012979984,'{"timestamp": "2026-03-09T19:27:26.012980+0100", "flow_id": 1744600321081028, "event_type": "alert", "src_ip": "167.94.146.35", "src_port": 65224, "dest_ip": "134.19.55.199", "dest_port": 31107, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:27:26.012980+0100", "src_ip": "167.94.146.35", "dest_ip": "134.19.55.199", "src_port": 65224, "dest_port": 31107}}'); INSERT INTO alerts VALUES(3985,1773080848.614753008,'{"timestamp": "2026-03-09T19:27:28.614753+0100", "flow_id": 107072926438933, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26964, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:27:28.614753+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63137, "dest_port": 53}}'); INSERT INTO alerts VALUES(3986,1773080853.721313954,'{"timestamp": "2026-03-09T19:27:33.721314+0100", "flow_id": 1409171679583713, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:27:33.721314+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3987,1773080857.453119039,'{"timestamp": "2026-03-09T19:27:37.453119+0100", "flow_id": 538759650230609, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:27:37.453119+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(3988,1773080857.454855919,'{"timestamp": "2026-03-09T19:27:37.454856+0100", "flow_id": 546217864284541, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:27:37.454856+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(3989,1773080876.463517905,'{"timestamp": "2026-03-09T19:27:56.463518+0100", "flow_id": 1146373198383131, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:27:56.463518+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63468, "dest_port": 53}}'); INSERT INTO alerts VALUES(3990,1773080876.463517905,'{"timestamp": "2026-03-09T19:27:56.463518+0100", "flow_id": 1146371034949222, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:27:56.463518+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62064, "dest_port": 53}}'); INSERT INTO alerts VALUES(3991,1773080876.516186952,'{"timestamp": "2026-03-09T19:27:56.516187+0100", "flow_id": 1372581666085863, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:27:56.516187+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3992,1773080876.516187906,'{"timestamp": "2026-03-09T19:27:56.516188+0100", "flow_id": 1372588829615697, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:27:56.516188+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(3993,1773080884.504582882,'{"timestamp": "2026-03-09T19:28:04.504583+0100", "flow_id": 1322744052686305, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:28:04.504583+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(3994,1773080888.818408012,'{"timestamp": "2026-03-09T19:28:08.818408+0100", "flow_id": 137339121844561, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:28:08.818408+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(3995,1773080888.818408012,'{"timestamp": "2026-03-09T19:28:08.818408+0100", "flow_id": 137336977705341, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:28:08.818408+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(3996,1773080893.137978077,'{"timestamp": "2026-03-09T19:28:13.137978+0100", "flow_id": 1437040178960601, "event_type": "alert", "src_ip": "205.210.31.75", "src_port": 55970, "dest_ip": "134.19.55.199", "dest_port": 8159, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:28:13.137978+0100", "src_ip": "205.210.31.75", "dest_ip": "134.19.55.199", "src_port": 55970, "dest_port": 8159}}'); INSERT INTO alerts VALUES(3997,1773080903.28623104,'{"timestamp": "2026-03-09T19:28:23.286231+0100", "flow_id": 2073778950008383, "event_type": "alert", "src_ip": "45.153.34.179", "src_port": 53722, "dest_ip": "134.19.55.199", "dest_port": 52869, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:28:23.286231+0100", "src_ip": "45.153.34.179", "dest_ip": "134.19.55.199", "src_port": 53722, "dest_port": 52869}}'); INSERT INTO alerts VALUES(3998,1773080907.070933103,'{"timestamp": "2026-03-09T19:28:27.070933+0100", "flow_id": 867605181225959, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:28:27.070933+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(3999,1773080907.070933103,'{"timestamp": "2026-03-09T19:28:27.070933+0100", "flow_id": 867608049788497, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:28:27.070933+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4000,1773080908.117595911,'{"timestamp": "2026-03-09T19:28:28.117596+0100", "flow_id": 1349496732445355, "event_type": "alert", "src_ip": "205.210.31.83", "src_port": 49961, "dest_ip": "134.19.55.199", "dest_port": 8000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:28:28.117596+0100", "src_ip": "205.210.31.83", "dest_ip": "134.19.55.199", "src_port": 49961, "dest_port": 8000}}'); INSERT INTO alerts VALUES(4001,1773080914.451575995,'{"timestamp": "2026-03-09T19:28:34.451576+0100", "flow_id": 813606616197425, "event_type": "alert", "src_ip": "195.174.41.66", "src_port": 42072, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:28:34.451576+0100", "src_ip": "195.174.41.66", "dest_ip": "134.19.55.199", "src_port": 42072, "dest_port": 1433}}'); INSERT INTO alerts VALUES(4002,1773080915.853014946,'{"timestamp": "2026-03-09T19:28:35.853015+0100", "flow_id": 848923260591585, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:28:35.853015+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4003,1773080920.19007802,'{"timestamp": "2026-03-09T19:28:40.190078+0100", "flow_id": 253432087855441, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:28:40.190078+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4004,1773080920.19007802,'{"timestamp": "2026-03-09T19:28:40.190078+0100", "flow_id": 253429943716221, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:28:40.190078+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4005,1773080937.526559115,'{"timestamp": "2026-03-09T19:28:57.526559+0100", "flow_id": 291229160037351, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:28:57.526559+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4006,1773080937.526851892,'{"timestamp": "2026-03-09T19:28:57.526852+0100", "flow_id": 292490454017617, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:28:57.526852+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4007,1773080941.320081949,'{"timestamp": "2026-03-09T19:29:01.320082+0100", "flow_id": 1656217865900619, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59661, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17710, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:29:01.320082+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59661, "dest_port": 53}}'); INSERT INTO alerts VALUES(4008,1773080941.320081949,'{"timestamp": "2026-03-09T19:29:01.320082+0100", "flow_id": 1656220176156699, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63468, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:29:01.320082+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63468, "dest_port": 53}}'); INSERT INTO alerts VALUES(4009,1773080941.320081949,'{"timestamp": "2026-03-09T19:29:01.320082+0100", "flow_id": 1656218012722790, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:29:01.320082+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62064, "dest_port": 53}}'); INSERT INTO alerts VALUES(4010,1773080941.320081949,'{"timestamp": "2026-03-09T19:29:01.320082+0100", "flow_id": 1656220814900811, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55525, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9520, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:29:01.320082+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55525, "dest_port": 53}}'); INSERT INTO alerts VALUES(4011,1773080941.320082903,'{"timestamp": "2026-03-09T19:29:01.320083+0100", "flow_id": 1656224817863367, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59109, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64384, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:29:01.320083+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59109, "dest_port": 53}}'); INSERT INTO alerts VALUES(4012,1773080941.320082903,'{"timestamp": "2026-03-09T19:29:01.320083+0100", "flow_id": 1656222581934824, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61288, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33154, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:29:01.320083+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61288, "dest_port": 53}}'); INSERT INTO alerts VALUES(4013,1773080941.320533037,'{"timestamp": "2026-03-09T19:29:01.320533+0100", "flow_id": 1658156578730628, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60153, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7583, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:29:01.320533+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60153, "dest_port": 53}}'); INSERT INTO alerts VALUES(4014,1773080947.040188075,'{"timestamp": "2026-03-09T19:29:07.040188+0100", "flow_id": 1017032575524321, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:29:07.040188+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4015,1773080950.282192945,'{"timestamp": "2026-03-09T19:29:10.282193+0100", "flow_id": 1774962907169105, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:29:10.282193+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4016,1773080950.282192945,'{"timestamp": "2026-03-09T19:29:10.282193+0100", "flow_id": 1774960763029885, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:29:10.282193+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4017,1773080968.425951004,'{"timestamp": "2026-03-09T19:29:28.425951+0100", "flow_id": 140596067032039, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:29:28.425951+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4018,1773080968.425951004,'{"timestamp": "2026-03-09T19:29:28.425951+0100", "flow_id": 140598935594577, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:29:28.425951+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4019,1773080977.009851932,'{"timestamp": "2026-03-09T19:29:37.009852+0100", "flow_id": 323792966744936, "event_type": "alert", "src_ip": "158.94.209.116", "src_port": 65414, "dest_ip": "134.19.55.199", "dest_port": 25, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400027, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 28", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T19:29:37.009852+0100", "src_ip": "158.94.209.116", "dest_ip": "134.19.55.199", "src_port": 65414, "dest_port": 25}}'); INSERT INTO alerts VALUES(4020,1773080977.671926021,'{"timestamp": "2026-03-09T19:29:37.671926+0100", "flow_id": 352626904636897, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:29:37.671926+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4021,1773080980.301276923,'{"timestamp": "2026-03-09T19:29:40.301277+0100", "flow_id": 1293978109624657, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:29:40.301277+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4022,1773080980.301278115,'{"timestamp": "2026-03-09T19:29:40.301278+0100", "flow_id": 1293980260452733, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:29:40.301278+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4023,1773080998.654938936,'{"timestamp": "2026-03-09T19:29:58.654939+0100", "flow_id": 1968516968340455, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:29:58.654939+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4024,1773080998.65493989,'{"timestamp": "2026-03-09T19:29:58.654940+0100", "flow_id": 1968524131870289, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:29:58.654940+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4025,1773081000.901547909,'{"timestamp": "2026-03-09T19:30:00.901548+0100", "flow_id": 212945794342291, "event_type": "alert", "src_ip": "198.235.24.244", "src_port": 51593, "dest_ip": "134.19.55.199", "dest_port": 2085, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:30:00.901548+0100", "src_ip": "198.235.24.244", "dest_ip": "134.19.55.199", "src_port": 51593, "dest_port": 2085}}'); INSERT INTO alerts VALUES(4026,1773081006.945800066,'{"timestamp": "2026-03-09T19:30:06.945800+0100", "flow_id": 1810384371023435, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55525, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9520, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:30:06.945800+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55525, "dest_port": 53}}'); INSERT INTO alerts VALUES(4027,1773081006.945800066,'{"timestamp": "2026-03-09T19:30:06.945800+0100", "flow_id": 1810384079018695, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59109, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64384, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:30:06.945800+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59109, "dest_port": 53}}'); INSERT INTO alerts VALUES(4028,1773081006.945800066,'{"timestamp": "2026-03-09T19:30:06.945800+0100", "flow_id": 1810381843090152, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61288, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33154, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:30:06.945800+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61288, "dest_port": 53}}'); INSERT INTO alerts VALUES(4029,1773081006.945801019,'{"timestamp": "2026-03-09T19:30:06.945801+0100", "flow_id": 1810387399570052, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60153, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7583, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:30:06.945801+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60153, "dest_port": 53}}'); INSERT INTO alerts VALUES(4030,1773081006.945801019,'{"timestamp": "2026-03-09T19:30:06.945801+0100", "flow_id": 1810386633048343, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53915, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33389, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:30:06.945801+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53915, "dest_port": 53}}'); INSERT INTO alerts VALUES(4031,1773081006.945801019,'{"timestamp": "2026-03-09T19:30:06.945801+0100", "flow_id": 1810386909951779, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:30:06.945801+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4032,1773081006.945801019,'{"timestamp": "2026-03-09T19:30:06.945801+0100", "flow_id": 1810388509118757, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:30:06.945801+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4033,1773081009.058950902,'{"timestamp": "2026-03-09T19:30:09.058951+0100", "flow_id": 534669093477857, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:30:09.058951+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4034,1773081011.447911977,'{"timestamp": "2026-03-09T19:30:11.447912+0100", "flow_id": 1079345708941649, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:30:11.447912+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4035,1773081011.447911977,'{"timestamp": "2026-03-09T19:30:11.447912+0100", "flow_id": 1079343564802429, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:30:11.447912+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4036,1773081017.07662201,'{"timestamp": "2026-03-09T19:30:17.076622+0100", "flow_id": 329092267864733, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 8008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:30:17.076622+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 8008}}'); INSERT INTO alerts VALUES(4037,1773081017.07662201,'{"timestamp": "2026-03-09T19:30:17.076622+0100", "flow_id": 329092267864733, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 8008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:30:17.076622+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 8008}}'); INSERT INTO alerts VALUES(4038,1773081028.95093298,'{"timestamp": "2026-03-09T19:30:28.950933+0100", "flow_id": 1269476681178087, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:30:28.950933+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4039,1773081028.95093298,'{"timestamp": "2026-03-09T19:30:28.950933+0100", "flow_id": 1269479549740625, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:30:28.950933+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4040,1773081032.753514051,'{"timestamp": "2026-03-09T19:30:32.753514+0100", "flow_id": 140096977767988, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:30:32.753514+0100", "src_ip": "185.156.73.86", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44000}}'); INSERT INTO alerts VALUES(4041,1773081041.652106046,'{"timestamp": "2026-03-09T19:30:41.652106+0100", "flow_id": 548975227128735, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 11456, "dest_ip": "134.19.55.199", "dest_port": 51942, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:30:41.652106+0100", "src_ip": "167.94.146.37", "dest_ip": "134.19.55.199", "src_port": 11456, "dest_port": 51942}}'); INSERT INTO alerts VALUES(4042,1773081052.794332027,'{"timestamp": "2026-03-09T19:30:52.794332+0100", "flow_id": 1159830939052158, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51352, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26529, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:30:52.794332+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51352, "dest_port": 53}}'); INSERT INTO alerts VALUES(4043,1773081059.690736056,'{"timestamp": "2026-03-09T19:30:59.690736+0100", "flow_id": 996364005792743, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:30:59.690736+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4044,1773081059.690736056,'{"timestamp": "2026-03-09T19:30:59.690736+0100", "flow_id": 996366874355281, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:30:59.690736+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4045,1773081068.45876789,'{"timestamp": "2026-03-09T19:31:08.458768+0100", "flow_id": 1125969187670235, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52139, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14076, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:31:08.458768+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52139, "dest_port": 53}}'); INSERT INTO alerts VALUES(4046,1773081074.183039904,'{"timestamp": "2026-03-09T19:31:14.183040+0100", "flow_id": 786153173972771, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:31:14.183040+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4047,1773081074.183039904,'{"timestamp": "2026-03-09T19:31:14.183040+0100", "flow_id": 786154773139749, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:31:14.183040+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4048,1773081089.852253914,'{"timestamp": "2026-03-09T19:31:29.852254+0100", "flow_id": 282705776235450, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61415, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 741, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:31:29.852254+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61415, "dest_port": 53}}'); INSERT INTO alerts VALUES(4049,1773081090.850416898,'{"timestamp": "2026-03-09T19:31:30.850417+0100", "flow_id": 837763748453351, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:31:30.850417+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4050,1773081090.851135015,'{"timestamp": "2026-03-09T19:31:30.851135+0100", "flow_id": 840850403534417, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:31:30.851135+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4051,1773081104.29180789,'{"timestamp": "2026-03-09T19:31:44.291808+0100", "flow_id": 127408524957528, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51019, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51664, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:31:44.291808+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51019, "dest_port": 53}}'); INSERT INTO alerts VALUES(4052,1773081104.291809082,'{"timestamp": "2026-03-09T19:31:44.291809+0100", "flow_id": 127413569155451, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62606, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17276, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:31:44.291809+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62606, "dest_port": 53}}'); INSERT INTO alerts VALUES(4053,1773081104.516618013,'{"timestamp": "2026-03-09T19:31:44.516618+0100", "flow_id": 248534937663267, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:31:44.516618+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4054,1773081104.520404101,'{"timestamp": "2026-03-09T19:31:44.520404+0100", "flow_id": 264797283012901, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:31:44.520404+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4055,1773081115.326432944,'{"timestamp": "2026-03-09T19:31:55.326433+0100", "flow_id": 1120546564114990, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55162, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52180, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:31:55.326433+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55162, "dest_port": 53}}'); INSERT INTO alerts VALUES(4056,1773081121.573086977,'{"timestamp": "2026-03-09T19:32:01.573087+0100", "flow_id": 491065398385639, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:32:01.573087+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4057,1773081121.573087931,'{"timestamp": "2026-03-09T19:32:01.573088+0100", "flow_id": 491072561915473, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:32:01.573088+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4058,1773081134.89840889,'{"timestamp": "2026-03-09T19:32:14.898409+0100", "flow_id": 1888313936158177, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:32:14.898409+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4059,1773081134.89840889,'{"timestamp": "2026-03-09T19:32:14.898409+0100", "flow_id": 1888315684045137, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:32:14.898409+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4060,1773081134.898410081,'{"timestamp": "2026-03-09T19:32:14.898410+0100", "flow_id": 1888317834873213, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:32:14.898410+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4061,1773081152.464982987,'{"timestamp": "2026-03-09T19:32:32.464983+0100", "flow_id": 26762253818855, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:32:32.464983+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4062,1773081152.464983941,'{"timestamp": "2026-03-09T19:32:32.464984+0100", "flow_id": 26769417348689, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:32:32.464984+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4063,1773081155.543587923,'{"timestamp": "2026-03-09T19:32:35.543588+0100", "flow_id": 927320598591276, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55143, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63432, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:32:35.543588+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55143, "dest_port": 53}}'); INSERT INTO alerts VALUES(4064,1773081155.543589116,'{"timestamp": "2026-03-09T19:32:35.543589+0100", "flow_id": 927323621988076, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62527, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17198, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:32:35.543589+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62527, "dest_port": 53}}'); INSERT INTO alerts VALUES(4065,1773081166.106004954,'{"timestamp": "2026-03-09T19:32:46.106005+0100", "flow_id": 1862664391466465, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:32:46.106005+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4066,1773081166.106400967,'{"timestamp": "2026-03-09T19:32:46.106401+0100", "flow_id": 1864366946402641, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:32:46.106401+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4067,1773081166.106400967,'{"timestamp": "2026-03-09T19:32:46.106401+0100", "flow_id": 1864364802263421, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:32:46.106401+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4068,1773081179.701061011,'{"timestamp": "2026-03-09T19:32:59.701061+0100", "flow_id": 1040712123072506, "event_type": "alert", "src_ip": "195.82.148.30", "src_port": 10400, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:32:59.701061+0100", "src_ip": "195.82.148.30", "dest_ip": "134.19.55.199", "src_port": 10400, "dest_port": 1433}}'); INSERT INTO alerts VALUES(4069,1773081180.094244004,'{"timestamp": "2026-03-09T19:33:00.094244+0100", "flow_id": 1249202188089123, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:33:00.094244+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4070,1773081180.094244956,'{"timestamp": "2026-03-09T19:33:00.094245+0100", "flow_id": 1249208082223397, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:33:00.094245+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4071,1773081183.796009063,'{"timestamp": "2026-03-09T19:33:03.796009+0100", "flow_id": 2011458051365863, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:33:03.796009+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4072,1773081183.796009063,'{"timestamp": "2026-03-09T19:33:03.796009+0100", "flow_id": 2011460919928401, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:33:03.796009+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4073,1773081186.675446033,'{"timestamp": "2026-03-09T19:33:06.675446+0100", "flow_id": 649219182188702, "event_type": "alert", "src_ip": "198.235.24.71", "src_port": 54278, "dest_ip": "134.19.55.199", "dest_port": 771, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:33:06.675446+0100", "src_ip": "198.235.24.71", "dest_ip": "134.19.55.199", "src_port": 54278, "dest_port": 771}}'); INSERT INTO alerts VALUES(4074,1773081190.411952019,'{"timestamp": "2026-03-09T19:33:10.411952+0100", "flow_id": 1769324088575907, "event_type": "alert", "src_ip": "147.185.132.246", "src_port": 51207, "dest_ip": "134.19.55.199", "dest_port": 1701, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 86, "bytes_toclient": 0, "start": "2026-03-09T19:33:10.411952+0100", "src_ip": "147.185.132.246", "dest_ip": "134.19.55.199", "src_port": 51207, "dest_port": 1701}}'); INSERT INTO alerts VALUES(4075,1773081196.590706111,'{"timestamp": "2026-03-09T19:33:16.590706+0100", "flow_id": 1129689567698401, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:33:16.590706+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4076,1773081196.590706111,'{"timestamp": "2026-03-09T19:33:16.590706+0100", "flow_id": 1129691315585361, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:33:16.590706+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4077,1773081196.590706111,'{"timestamp": "2026-03-09T19:33:16.590706+0100", "flow_id": 1129689171446141, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:33:16.590706+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4078,1773081211.122855902,'{"timestamp": "2026-03-09T19:33:31.122856+0100", "flow_id": 1090614815651619, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:33:31.122856+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4079,1773081211.122855902,'{"timestamp": "2026-03-09T19:33:31.122856+0100", "flow_id": 1090616414818597, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:33:31.122856+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4080,1773081240.422640086,'{"timestamp": "2026-03-09T19:34:00.422640+0100", "flow_id": 126378065394824, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61479, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40530, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:34:00.422640+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61479, "dest_port": 53}}'); INSERT INTO alerts VALUES(4081,1773081240.422640086,'{"timestamp": "2026-03-09T19:34:00.422640+0100", "flow_id": 126375654743586, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64953, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6349, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:34:00.422640+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64953, "dest_port": 53}}'); INSERT INTO alerts VALUES(4082,1773081256.50157404,'{"timestamp": "2026-03-09T19:34:16.501574+0100", "flow_id": 183919402146791, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:34:16.501574+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4083,1773081256.50157404,'{"timestamp": "2026-03-09T19:34:16.501574+0100", "flow_id": 183922270709329, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:34:16.501574+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4084,1773081279.343978882,'{"timestamp": "2026-03-09T19:34:39.343979+0100", "flow_id": 2040330008632801, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:34:39.343979+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4085,1773081279.343980073,'{"timestamp": "2026-03-09T19:34:39.343980+0100", "flow_id": 2040336051487057, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:34:39.343980+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4086,1773081279.343980073,'{"timestamp": "2026-03-09T19:34:39.343980+0100", "flow_id": 2040333907347837, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:34:39.343980+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4087,1773081290.413646936,'{"timestamp": "2026-03-09T19:34:50.413647+0100", "flow_id": 650703542068195, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 59655, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:34:50.413647+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 59655, "dest_port": 3389}}'); INSERT INTO alerts VALUES(4088,1773081300.186527013,'{"timestamp": "2026-03-09T19:35:00.186527+0100", "flow_id": 1364079678355235, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:35:00.186527+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4089,1773081300.186527968,'{"timestamp": "2026-03-09T19:35:00.186528+0100", "flow_id": 1364085572489509, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:35:00.186528+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4090,1773081310.494010925,'{"timestamp": "2026-03-09T19:35:10.494011+0100", "flow_id": 1840287611854305, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:35:10.494011+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4091,1773081310.494010925,'{"timestamp": "2026-03-09T19:35:10.494011+0100", "flow_id": 1840289359741265, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:35:10.494011+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4092,1773081310.494012118,'{"timestamp": "2026-03-09T19:35:10.494012+0100", "flow_id": 1840291510569341, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:35:10.494012+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4093,1773081326.295819998,'{"timestamp": "2026-03-09T19:35:26.295820+0100", "flow_id": 1833487799890786, "event_type": "alert", "src_ip": "185.242.226.120", "src_port": 59468, "dest_ip": "134.19.55.199", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T19:35:26.295820+0100", "src_ip": "185.242.226.120", "dest_ip": "134.19.55.199", "src_port": 59468, "dest_port": 443}}'); INSERT INTO alerts VALUES(4094,1773081330.900337934,'{"timestamp": "2026-03-09T19:35:30.900338+0100", "flow_id": 770699881641763, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:35:30.900338+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4095,1773081330.900338889,'{"timestamp": "2026-03-09T19:35:30.900339+0100", "flow_id": 770705775776037, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:35:30.900339+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4096,1773081331.681448937,'{"timestamp": "2026-03-09T19:35:31.681449+0100", "flow_id": 956476644514791, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:35:31.681449+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4097,1773081331.681449891,'{"timestamp": "2026-03-09T19:35:31.681450+0100", "flow_id": 956483808044625, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:35:31.681450+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4098,1773081343.954988003,'{"timestamp": "2026-03-09T19:35:43.954988+0100", "flow_id": 2131319610561905, "event_type": "alert", "src_ip": "167.94.146.36", "src_port": 28956, "dest_ip": "134.19.55.199", "dest_port": 43109, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:35:43.954988+0100", "src_ip": "167.94.146.36", "dest_ip": "134.19.55.199", "src_port": 28956, "dest_port": 43109}}'); INSERT INTO alerts VALUES(4099,1773081362.081727982,'{"timestamp": "2026-03-09T19:36:02.081728+0100", "flow_id": 632494376475623, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:36:02.081728+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4100,1773081362.082645894,'{"timestamp": "2026-03-09T19:36:02.082646+0100", "flow_id": 636440025015889, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:36:02.082646+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4101,1773081373.630975962,'{"timestamp": "2026-03-09T19:36:13.630976+0100", "flow_id": 1584122877418977, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:36:13.630976+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4102,1773081373.630976916,'{"timestamp": "2026-03-09T19:36:13.630977+0100", "flow_id": 1584128920273233, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:36:13.630977+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4103,1773081373.630976916,'{"timestamp": "2026-03-09T19:36:13.630977+0100", "flow_id": 1584126776134013, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:36:13.630977+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4104,1773081393.186398983,'{"timestamp": "2026-03-09T19:36:33.186399+0100", "flow_id": 519102944893927, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:36:33.186399+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4105,1773081393.186398983,'{"timestamp": "2026-03-09T19:36:33.186399+0100", "flow_id": 519105813456465, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:36:33.186399+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4106,1773081395.27563095,'{"timestamp": "2026-03-09T19:36:35.275631+0100", "flow_id": 902353514166051, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:36:35.275631+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4107,1773081395.275631904,'{"timestamp": "2026-03-09T19:36:35.275632+0100", "flow_id": 902359408300325, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:36:35.275632+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4108,1773081404.6694839,'{"timestamp": "2026-03-09T19:36:44.669484+0100", "flow_id": 1186563524632033, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:36:44.669484+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4109,1773081404.6694839,'{"timestamp": "2026-03-09T19:36:44.669484+0100", "flow_id": 1186565272518993, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:36:44.669484+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4110,1773081404.6694839,'{"timestamp": "2026-03-09T19:36:44.669484+0100", "flow_id": 1186563128379773, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:36:44.669484+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4111,1773081414.66596508,'{"timestamp": "2026-03-09T19:36:54.665965+0100", "flow_id": 1734400121050017, "event_type": "alert", "src_ip": "125.72.100.110", "src_port": 46840, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:36:54.665965+0100", "src_ip": "125.72.100.110", "dest_ip": "134.19.55.199", "src_port": 46840, "dest_port": 1433}}'); INSERT INTO alerts VALUES(4112,1773081417.592956067,'{"timestamp": "2026-03-09T19:36:57.592956+0100", "flow_id": 294929098274066, "event_type": "alert", "src_ip": "15.204.54.13", "src_port": 56118, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 441, "bytes_toclient": 0, "start": "2026-03-09T19:36:57.592956+0100", "src_ip": "15.204.54.13", "dest_ip": "134.19.55.199", "src_port": 56118, "dest_port": 5060}}'); INSERT INTO alerts VALUES(4113,1773081417.592956067,'{"timestamp": "2026-03-09T19:36:57.592956+0100", "flow_id": 294929098274066, "event_type": "alert", "src_ip": "15.204.54.13", "src_port": 56118, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 441, "bytes_toclient": 0, "start": "2026-03-09T19:36:57.592956+0100", "src_ip": "15.204.54.13", "dest_ip": "134.19.55.199", "src_port": 56118, "dest_port": 5060}}'); INSERT INTO alerts VALUES(4114,1773081424.558034897,'{"timestamp": "2026-03-09T19:37:04.558035+0100", "flow_id": 144942573935591, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:37:04.558035+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4115,1773081424.558036088,'{"timestamp": "2026-03-09T19:37:04.558036+0100", "flow_id": 144949737465425, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:37:04.558036+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4116,1773081425.31111312,'{"timestamp": "2026-03-09T19:37:05.311113+0100", "flow_id": 491797590341411, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:37:05.311113+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4117,1773081425.31111312,'{"timestamp": "2026-03-09T19:37:05.311113+0100", "flow_id": 491799189508389, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:37:05.311113+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4118,1773081425.882759095,'{"timestamp": "2026-03-09T19:37:05.882759+0100", "flow_id": 413725067679870, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55091, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46494, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:37:05.882759+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55091, "dest_port": 53}}'); INSERT INTO alerts VALUES(4119,1773081425.882759095,'{"timestamp": "2026-03-09T19:37:05.882759+0100", "flow_id": 413722796603451, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61017, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51446, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:37:05.882759+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61017, "dest_port": 53}}'); INSERT INTO alerts VALUES(4120,1773081436.044146061,'{"timestamp": "2026-03-09T19:37:16.044146+0100", "flow_id": 1315507032792545, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:37:16.044146+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4121,1773081436.044147014,'{"timestamp": "2026-03-09T19:37:16.044147+0100", "flow_id": 1315513075646801, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:37:16.044147+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4122,1773081436.044147014,'{"timestamp": "2026-03-09T19:37:16.044147+0100", "flow_id": 1315510931507581, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:37:16.044147+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4123,1773081455.358069897,'{"timestamp": "2026-03-09T19:37:35.358070+0100", "flow_id": 2100851253212963, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:37:35.358070+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4124,1773081455.359141112,'{"timestamp": "2026-03-09T19:37:35.359141+0100", "flow_id": 2105452762353957, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:37:35.359141+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4125,1773081466.371376038,'{"timestamp": "2026-03-09T19:37:46.371376+0100", "flow_id": 750624344088033, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:37:46.371376+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4126,1773081466.371376991,'{"timestamp": "2026-03-09T19:37:46.371377+0100", "flow_id": 750630386942289, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:37:46.371377+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4127,1773081466.371376991,'{"timestamp": "2026-03-09T19:37:46.371377+0100", "flow_id": 750628242803069, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:37:46.371377+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4128,1773081467.809887887,'{"timestamp": "2026-03-09T19:37:47.809888+0100", "flow_id": 945169782910666, "event_type": "alert", "src_ip": "45.142.154.99", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 50805, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:37:47.809888+0100", "src_ip": "45.142.154.99", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 50805}}'); INSERT INTO alerts VALUES(4129,1773081490.590631008,'{"timestamp": "2026-03-09T19:38:10.590631+0100", "flow_id": 566416304626663, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:38:10.590631+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4130,1773081490.590631008,'{"timestamp": "2026-03-09T19:38:10.590631+0100", "flow_id": 566419173189201, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:38:10.590631+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4131,1773081496.748822928,'{"timestamp": "2026-03-09T19:38:16.748823+0100", "flow_id": 119947051376097, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:38:16.748823+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4132,1773081496.748823881,'{"timestamp": "2026-03-09T19:38:16.748824+0100", "flow_id": 119953094230353, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:38:16.748824+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4133,1773081496.748823881,'{"timestamp": "2026-03-09T19:38:16.748824+0100", "flow_id": 119950950091133, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:38:16.748824+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4134,1773081520.09861207,'{"timestamp": "2026-03-09T19:38:40.098612+0100", "flow_id": 142061054789111, "event_type": "alert", "src_ip": "185.241.208.163", "src_port": 50251, "dest_ip": "134.19.55.199", "dest_port": 3379, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:38:40.098612+0100", "src_ip": "185.241.208.163", "dest_ip": "134.19.55.199", "src_port": 50251, "dest_port": 3379}}'); INSERT INTO alerts VALUES(4135,1773081520.622436047,'{"timestamp": "2026-03-09T19:38:40.622436+0100", "flow_id": 140067786054631, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:38:40.622436+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4136,1773081520.622437001,'{"timestamp": "2026-03-09T19:38:40.622437+0100", "flow_id": 140074949584465, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:38:40.622437+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4137,1773081527.945925951,'{"timestamp": "2026-03-09T19:38:47.945926+0100", "flow_id": 2092397897162209, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:38:47.945926+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53148, "dest_port": 53}}'); INSERT INTO alerts VALUES(4138,1773081527.945925951,'{"timestamp": "2026-03-09T19:38:47.945926+0100", "flow_id": 2092399645049169, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57739, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:38:47.945926+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57739, "dest_port": 53}}'); INSERT INTO alerts VALUES(4139,1773081527.945925951,'{"timestamp": "2026-03-09T19:38:47.945926+0100", "flow_id": 2092397500909949, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:38:47.945926+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(4140,1773081529.184911966,'{"timestamp": "2026-03-09T19:38:49.184912+0100", "flow_id": 512719208763518, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49939, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55930, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:38:49.184912+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49939, "dest_port": 53}}'); INSERT INTO alerts VALUES(4141,1773081541.479211091,'{"timestamp": "2026-03-09T19:39:01.479211+0100", "flow_id": 1495247979575075, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:39:01.479211+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4142,1773081541.479211091,'{"timestamp": "2026-03-09T19:39:01.479211+0100", "flow_id": 1495249578742053, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:39:01.479211+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4143,1773081571.701664925,'{"timestamp": "2026-03-09T19:39:31.701665+0100", "flow_id": 1043305750886179, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:39:31.701665+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4144,1773081571.70331192,'{"timestamp": "2026-03-09T19:39:31.703312+0100", "flow_id": 1050381161189669, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:39:31.703312+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4145,1773081602.859452962,'{"timestamp": "2026-03-09T19:40:02.859453+0100", "flow_id": 595100143744803, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:40:02.859453+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4146,1773081602.859452962,'{"timestamp": "2026-03-09T19:40:02.859453+0100", "flow_id": 595101742911781, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:40:02.859453+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4147,1773081607.098309041,'{"timestamp": "2026-03-09T19:40:07.098309+0100", "flow_id": 2111084112763879, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:40:07.098309+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4148,1773081607.09850502,'{"timestamp": "2026-03-09T19:40:07.098505+0100", "flow_id": 2111928794916433, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:40:07.098505+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4149,1773081633.205559016,'{"timestamp": "2026-03-09T19:40:33.205559+0100", "flow_id": 319921589090083, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:40:33.205559+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4150,1773081633.205559016,'{"timestamp": "2026-03-09T19:40:33.205559+0100", "flow_id": 319923188257061, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:40:33.205559+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4151,1773081638.574764967,'{"timestamp": "2026-03-09T19:40:38.574765+0100", "flow_id": 1905647237061607, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:40:38.574765+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4152,1773081638.574764967,'{"timestamp": "2026-03-09T19:40:38.574765+0100", "flow_id": 1905650105624145, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:40:38.574765+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4153,1773081661.0068779,'{"timestamp": "2026-03-09T19:41:01.006878+0100", "flow_id": 1436915983307498, "event_type": "alert", "src_ip": "205.210.31.193", "src_port": 53900, "dest_ip": "134.19.55.199", "dest_port": 3050, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:41:01.006878+0100", "src_ip": "205.210.31.193", "dest_ip": "134.19.55.199", "src_port": 53900, "dest_port": 3050}}'); INSERT INTO alerts VALUES(4154,1773081661.740278006,'{"timestamp": "2026-03-09T19:41:01.740278+0100", "flow_id": 1490622091627525, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60510, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58422, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:41:01.740278+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60510, "dest_port": 53}}'); INSERT INTO alerts VALUES(4155,1773081664.135910987,'{"timestamp": "2026-03-09T19:41:04.135911+0100", "flow_id": 20785706858275, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:41:04.135911+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4156,1773081664.135911941,'{"timestamp": "2026-03-09T19:41:04.135912+0100", "flow_id": 20791600992549, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:41:04.135912+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4157,1773081669.797821998,'{"timestamp": "2026-03-09T19:41:09.797822+0100", "flow_id": 1456294873652199, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:41:09.797822+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4158,1773081669.797822953,'{"timestamp": "2026-03-09T19:41:09.797823+0100", "flow_id": 1456302037182033, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:41:09.797823+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4159,1773081701.110835076,'{"timestamp": "2026-03-09T19:41:41.110835+0100", "flow_id": 1601932919692263, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:41:41.110835+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4160,1773081701.110835076,'{"timestamp": "2026-03-09T19:41:41.110835+0100", "flow_id": 1601935788254801, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:41:41.110835+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4161,1773081731.73213005,'{"timestamp": "2026-03-09T19:42:11.732130+0100", "flow_id": 892676981607627, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49274, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14634, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:42:11.732130+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49274, "dest_port": 53}}'); INSERT INTO alerts VALUES(4162,1773081732.45263505,'{"timestamp": "2026-03-09T19:42:12.452635+0100", "flow_id": 1381102881201127, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:42:12.452635+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4163,1773081732.455501079,'{"timestamp": "2026-03-09T19:42:12.455501+0100", "flow_id": 1393415126034001, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:42:12.455501+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4164,1773081748.063294888,'{"timestamp": "2026-03-09T19:42:28.063295+0100", "flow_id": 1397752221955875, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:42:28.063295+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4165,1773081748.063296079,'{"timestamp": "2026-03-09T19:42:28.063296+0100", "flow_id": 1397758116090149, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:42:28.063296+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4166,1773081752.148550034,'{"timestamp": "2026-03-09T19:42:32.148550+0100", "flow_id": 75069347239723, "event_type": "alert", "src_ip": "204.76.203.17", "src_port": 47534, "dest_ip": "134.19.55.199", "dest_port": 19133, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 61, "bytes_toclient": 0, "start": "2026-03-09T19:42:32.148550+0100", "src_ip": "204.76.203.17", "dest_ip": "134.19.55.199", "src_port": 47534, "dest_port": 19133}}'); INSERT INTO alerts VALUES(4167,1773081752.148550034,'{"timestamp": "2026-03-09T19:42:32.148550+0100", "flow_id": 75069347239723, "event_type": "alert", "src_ip": "204.76.203.17", "src_port": 47534, "dest_ip": "134.19.55.199", "dest_port": 19133, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 61, "bytes_toclient": 0, "start": "2026-03-09T19:42:32.148550+0100", "src_ip": "204.76.203.17", "dest_ip": "134.19.55.199", "src_port": 47534, "dest_port": 19133}}'); INSERT INTO alerts VALUES(4168,1773081763.68402791,'{"timestamp": "2026-03-09T19:42:43.684028+0100", "flow_id": 967553365171175, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:42:43.684028+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4169,1773081763.684516906,'{"timestamp": "2026-03-09T19:42:43.684517+0100", "flow_id": 969656472741457, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:42:43.684517+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4170,1773081778.196203948,'{"timestamp": "2026-03-09T19:42:58.196204+0100", "flow_id": 842692123457315, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:42:58.196204+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4171,1773081778.196203948,'{"timestamp": "2026-03-09T19:42:58.196204+0100", "flow_id": 842693722624293, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:42:58.196204+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4172,1773081778.437977076,'{"timestamp": "2026-03-09T19:42:58.437977+0100", "flow_id": 755200903291469, "event_type": "alert", "src_ip": "205.210.31.45", "src_port": 54417, "dest_ip": "134.19.55.199", "dest_port": 8081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:42:58.437977+0100", "src_ip": "205.210.31.45", "dest_ip": "134.19.55.199", "src_port": 54417, "dest_port": 8081}}'); INSERT INTO alerts VALUES(4173,1773081790.209131957,'{"timestamp": "2026-03-09T19:43:10.209132+0100", "flow_id": 1742644129349206, "event_type": "alert", "src_ip": "205.210.31.88", "src_port": 55840, "dest_ip": "134.19.55.199", "dest_port": 5916, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:43:10.209132+0100", "src_ip": "205.210.31.88", "dest_ip": "134.19.55.199", "src_port": 55840, "dest_port": 5916}}'); INSERT INTO alerts VALUES(4174,1773081795.1789999,'{"timestamp": "2026-03-09T19:43:15.179000+0100", "flow_id": 1050274435292135, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:43:15.179000+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4175,1773081795.1789999,'{"timestamp": "2026-03-09T19:43:15.179000+0100", "flow_id": 1050277303854673, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:43:15.179000+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4176,1773081809.248620033,'{"timestamp": "2026-03-09T19:43:29.248620+0100", "flow_id": 504867175823139, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:43:29.248620+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4177,1773081809.248620033,'{"timestamp": "2026-03-09T19:43:29.248620+0100", "flow_id": 504868774990117, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:43:29.248620+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4178,1773081825.845976114,'{"timestamp": "2026-03-09T19:43:45.845976+0100", "flow_id": 537214821981159, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:43:45.845976+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4179,1773081825.846569061,'{"timestamp": "2026-03-09T19:43:45.846569+0100", "flow_id": 539764606150225, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:43:45.846569+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4180,1773081839.314623118,'{"timestamp": "2026-03-09T19:43:59.314623+0100", "flow_id": 2195722785814307, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:43:59.314623+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4181,1773081839.314623118,'{"timestamp": "2026-03-09T19:43:59.314623+0100", "flow_id": 2195724384981285, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:43:59.314623+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4182,1773081841.31374693,'{"timestamp": "2026-03-09T19:44:01.313747+0100", "flow_id": 503108342544748, "event_type": "alert", "src_ip": "167.94.138.124", "src_port": 64702, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:44:01.313747+0100", "src_ip": "167.94.138.124", "dest_ip": "134.19.55.199", "src_port": 64702, "dest_port": 5060}}'); INSERT INTO alerts VALUES(4183,1773081856.227770091,'{"timestamp": "2026-03-09T19:44:16.227770+0100", "flow_id": 133840083475431, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:44:16.227770+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4184,1773081856.227770091,'{"timestamp": "2026-03-09T19:44:16.227770+0100", "flow_id": 133842952037969, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:44:16.227770+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4185,1773081866.569376946,'{"timestamp": "2026-03-09T19:44:26.569377+0100", "flow_id": 756606301572183, "event_type": "alert", "src_ip": "147.185.132.233", "src_port": 49983, "dest_ip": "134.19.55.199", "dest_port": 51210, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:44:26.569377+0100", "src_ip": "147.185.132.233", "dest_ip": "134.19.55.199", "src_port": 49983, "dest_port": 51210}}'); INSERT INTO alerts VALUES(4186,1773081869.59795189,'{"timestamp": "2026-03-09T19:44:29.597952+0100", "flow_id": 1442286737848099, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:44:29.597952+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4187,1773081869.597953081,'{"timestamp": "2026-03-09T19:44:29.597953+0100", "flow_id": 1442292631982373, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54102, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:44:29.597953+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54102, "dest_port": 53}}'); INSERT INTO alerts VALUES(4188,1773081877.309773921,'{"timestamp": "2026-03-09T19:44:37.309774+0100", "flow_id": 1611947711612257, "event_type": "alert", "src_ip": "205.210.31.175", "src_port": 51055, "dest_ip": "134.19.55.199", "dest_port": 135, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:44:37.309774+0100", "src_ip": "205.210.31.175", "dest_ip": "134.19.55.199", "src_port": 51055, "dest_port": 135}}'); INSERT INTO alerts VALUES(4189,1773081878.53162694,'{"timestamp": "2026-03-09T19:44:38.531627+0100", "flow_id": 1720371196741424, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64356, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5153, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:44:38.531627+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64356, "dest_port": 53}}'); INSERT INTO alerts VALUES(4190,1773081878.531627893,'{"timestamp": "2026-03-09T19:44:38.531628+0100", "flow_id": 1720377967734622, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61117, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51058, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:44:38.531628+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61117, "dest_port": 53}}'); INSERT INTO alerts VALUES(4191,1773081887.714747905,'{"timestamp": "2026-03-09T19:44:47.714748+0100", "flow_id": 2225394667346919, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:44:47.714748+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4192,1773081887.714747905,'{"timestamp": "2026-03-09T19:44:47.714748+0100", "flow_id": 2225397535909457, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:44:47.714748+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4193,1773081902.298410893,'{"timestamp": "2026-03-09T19:45:02.298411+0100", "flow_id": 1844617625161194, "event_type": "alert", "src_ip": "205.210.31.81", "src_port": 51054, "dest_ip": "134.19.55.199", "dest_port": 6697, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:45:02.298411+0100", "src_ip": "205.210.31.81", "dest_ip": "134.19.55.199", "src_port": 51054, "dest_port": 6697}}'); INSERT INTO alerts VALUES(4194,1773081902.429589987,'{"timestamp": "2026-03-09T19:45:02.429590+0100", "flow_id": 1845078052260586, "event_type": "alert", "src_ip": "193.163.125.187", "src_port": 34506, "dest_ip": "134.19.55.199", "dest_port": 1200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:45:02.429590+0100", "src_ip": "193.163.125.187", "dest_ip": "134.19.55.199", "src_port": 34506, "dest_port": 1200}}'); INSERT INTO alerts VALUES(4195,1773081918.702615023,'{"timestamp": "2026-03-09T19:45:18.702615+0100", "flow_id": 1891808852433895, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:45:18.702615+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4196,1773081918.702615023,'{"timestamp": "2026-03-09T19:45:18.702615+0100", "flow_id": 1891811720996433, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:45:18.702615+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4197,1773081931.798533916,'{"timestamp": "2026-03-09T19:45:31.798534+0100", "flow_id": 896405316702913, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59861, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58054, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:45:31.798534+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59861, "dest_port": 53}}'); INSERT INTO alerts VALUES(4198,1773081949.646852017,'{"timestamp": "2026-03-09T19:45:49.646852+0100", "flow_id": 1652308591107047, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:45:49.646852+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4199,1773081949.646852017,'{"timestamp": "2026-03-09T19:45:49.646852+0100", "flow_id": 1652311459669585, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:45:49.646852+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4200,1773081963.343772889,'{"timestamp": "2026-03-09T19:46:03.343773+0100", "flow_id": 913546984774950, "event_type": "alert", "src_ip": "205.210.31.90", "src_port": 52432, "dest_ip": "134.19.55.199", "dest_port": 49502, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:46:03.343773+0100", "src_ip": "205.210.31.90", "dest_ip": "134.19.55.199", "src_port": 52432, "dest_port": 49502}}'); INSERT INTO alerts VALUES(4201,1773081981.019699097,'{"timestamp": "2026-03-09T19:46:21.019699+0100", "flow_id": 1491981756914663, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:46:21.019699+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4202,1773081981.021697044,'{"timestamp": "2026-03-09T19:46:21.021697+0100", "flow_id": 1500565970134609, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:46:21.021697+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4203,1773082011.336699009,'{"timestamp": "2026-03-09T19:46:51.336699+0100", "flow_id": 883161552772071, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:46:51.336699+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4204,1773082011.336699962,'{"timestamp": "2026-03-09T19:46:51.336700+0100", "flow_id": 883168716301905, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:46:51.336700+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4205,1773082024.171255111,'{"timestamp": "2026-03-09T19:47:04.171255+0100", "flow_id": 172587590748927, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 22191, "dest_ip": "134.19.55.199", "dest_port": 598, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:47:04.171255+0100", "src_ip": "167.94.146.32", "dest_ip": "134.19.55.199", "src_port": 22191, "dest_port": 598}}'); INSERT INTO alerts VALUES(4206,1773082041.401786089,'{"timestamp": "2026-03-09T19:47:21.401786+0100", "flow_id": 318283159034855, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:47:21.401786+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4207,1773082041.402105093,'{"timestamp": "2026-03-09T19:47:21.402105+0100", "flow_id": 319656122164817, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:47:21.402105+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4208,1773082057.811589003,'{"timestamp": "2026-03-09T19:47:37.811589+0100", "flow_id": 389525264899274, "event_type": "alert", "src_ip": "198.235.24.170", "src_port": 50467, "dest_ip": "134.19.55.199", "dest_port": 8531, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:47:37.811589+0100", "src_ip": "198.235.24.170", "dest_ip": "134.19.55.199", "src_port": 50467, "dest_port": 8531}}'); INSERT INTO alerts VALUES(4209,1773082072.709264993,'{"timestamp": "2026-03-09T19:47:52.709265+0100", "flow_id": 231520524688359, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:47:52.709265+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4210,1773082072.709264993,'{"timestamp": "2026-03-09T19:47:52.709265+0100", "flow_id": 231523393250897, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:47:52.709265+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4211,1773082083.118056058,'{"timestamp": "2026-03-09T19:48:03.118056+0100", "flow_id": 1069997073069298, "event_type": "alert", "src_ip": "198.235.24.123", "src_port": 51263, "dest_ip": "134.19.55.199", "dest_port": 2323, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:48:03.118056+0100", "src_ip": "198.235.24.123", "dest_ip": "134.19.55.199", "src_port": 51263, "dest_port": 2323}}'); INSERT INTO alerts VALUES(4212,1773082102.866384983,'{"timestamp": "2026-03-09T19:48:22.866385+0100", "flow_id": 1750770716367847, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:48:22.866385+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4213,1773082102.867647887,'{"timestamp": "2026-03-09T19:48:22.867648+0100", "flow_id": 1756198128625233, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:48:22.867648+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4214,1773082122.388914109,'{"timestamp": "2026-03-09T19:48:42.388914+0100", "flow_id": 825952008512434, "event_type": "alert", "src_ip": "80.94.92.168", "src_port": 34590, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:48:42.388914+0100", "src_ip": "80.94.92.168", "dest_ip": "134.19.55.199", "src_port": 34590, "dest_port": 22}}'); INSERT INTO alerts VALUES(4215,1773082134.283843995,'{"timestamp": "2026-03-09T19:48:54.283844+0100", "flow_id": 1782050963184615, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:48:54.283844+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4216,1773082134.284794093,'{"timestamp": "2026-03-09T19:48:54.284794+0100", "flow_id": 1786134050678353, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:48:54.284794+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4217,1773082146.453862906,'{"timestamp": "2026-03-09T19:49:06.453863+0100", "flow_id": 823427069382510, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58141, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49881, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:49:06.453863+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58141, "dest_port": 53}}'); INSERT INTO alerts VALUES(4218,1773082146.454550982,'{"timestamp": "2026-03-09T19:49:06.454551+0100", "flow_id": 826384865768861, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63060, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14232, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:49:06.454551+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63060, "dest_port": 53}}'); INSERT INTO alerts VALUES(4219,1773082161.73221898,'{"timestamp": "2026-03-09T19:49:21.732219+0100", "flow_id": 330107196985160, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56387, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39684, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:49:21.732219+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56387, "dest_port": 53}}'); INSERT INTO alerts VALUES(4220,1773082164.536691905,'{"timestamp": "2026-03-09T19:49:24.536692+0100", "flow_id": 1179174993779687, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:49:24.536692+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4221,1773082164.536693096,'{"timestamp": "2026-03-09T19:49:24.536693+0100", "flow_id": 1179182157309521, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:49:24.536693+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4222,1773082188.884736061,'{"timestamp": "2026-03-09T19:49:48.884736+0100", "flow_id": 1266640829038927, "event_type": "alert", "src_ip": "147.185.132.13", "src_port": 51470, "dest_ip": "134.19.55.199", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-09T19:49:48.884736+0100", "src_ip": "147.185.132.13", "dest_ip": "134.19.55.199", "src_port": 51470, "dest_port": 53}}'); INSERT INTO alerts VALUES(4223,1773082188.884736061,'{"timestamp": "2026-03-09T19:49:48.884736+0100", "flow_id": 1266640829038927, "event_type": "alert", "src_ip": "147.185.132.13", "src_port": 51470, "dest_ip": "134.19.55.199", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2101616, "rev": 9, "signature": "GPL DNS named version attempt", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_07_26"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-09T19:49:48.884736+0100", "src_ip": "147.185.132.13", "dest_ip": "134.19.55.199", "src_port": 51470, "dest_port": 53}}'); INSERT INTO alerts VALUES(4224,1773082195.796283006,'{"timestamp": "2026-03-09T19:49:55.796283+0100", "flow_id": 886734965562343, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:49:55.796283+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4225,1773082195.796283006,'{"timestamp": "2026-03-09T19:49:55.796283+0100", "flow_id": 886737834124881, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:49:55.796283+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4226,1773082208.865582942,'{"timestamp": "2026-03-09T19:50:08.865583+0100", "flow_id": 58476036565381, "event_type": "alert", "src_ip": "43.228.157.10", "src_port": 40489, "dest_ip": "134.19.55.199", "dest_port": 40922, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:50:08.865583+0100", "src_ip": "43.228.157.10", "dest_ip": "134.19.55.199", "src_port": 40489, "dest_port": 40922}}'); INSERT INTO alerts VALUES(4227,1773082209.526884079,'{"timestamp": "2026-03-09T19:50:09.526884+0100", "flow_id": 292626997731809, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 41549, "dest_ip": "134.19.55.199", "dest_port": 48503, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:50:09.526884+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 41549, "dest_port": 48503}}'); INSERT INTO alerts VALUES(4228,1773082227.012365102,'{"timestamp": "2026-03-09T19:50:27.012365+0100", "flow_id": 897532513344487, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:50:27.012365+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4229,1773082227.012365102,'{"timestamp": "2026-03-09T19:50:27.012365+0100", "flow_id": 897535381907025, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:50:27.012365+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4230,1773082257.945794105,'{"timestamp": "2026-03-09T19:50:57.945794+0100", "flow_id": 402979914111975, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:50:57.945794+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4231,1773082257.945794105,'{"timestamp": "2026-03-09T19:50:57.945794+0100", "flow_id": 402982782674513, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:50:57.945794+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4232,1773082270.247328042,'{"timestamp": "2026-03-09T19:51:10.247328+0100", "flow_id": 1906690968803300, "event_type": "alert", "src_ip": "167.94.146.39", "src_port": 18239, "dest_ip": "134.19.55.199", "dest_port": 34129, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:51:10.247328+0100", "src_ip": "167.94.146.39", "dest_ip": "134.19.55.199", "src_port": 18239, "dest_port": 34129}}'); INSERT INTO alerts VALUES(4233,1773082274.758723975,'{"timestamp": "2026-03-09T19:51:14.758724+0100", "flow_id": 725423394347013, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63759, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57185, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:51:14.758724+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63759, "dest_port": 53}}'); INSERT INTO alerts VALUES(4234,1773082274.758723975,'{"timestamp": "2026-03-09T19:51:14.758724+0100", "flow_id": 725423472027872, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53201, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43997, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:51:14.758724+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53201, "dest_port": 53}}'); INSERT INTO alerts VALUES(4235,1773082279.132426978,'{"timestamp": "2026-03-09T19:51:19.132427+0100", "flow_id": 1976148398014205, "event_type": "alert", "src_ip": "147.185.132.198", "src_port": 53992, "dest_ip": "134.19.55.199", "dest_port": 3929, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:51:19.132427+0100", "src_ip": "147.185.132.198", "dest_ip": "134.19.55.199", "src_port": 53992, "dest_port": 3929}}'); INSERT INTO alerts VALUES(4236,1773082289.044923068,'{"timestamp": "2026-03-09T19:51:29.044923+0100", "flow_id": 474418105146343, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:51:29.044923+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4237,1773082289.044923068,'{"timestamp": "2026-03-09T19:51:29.044923+0100", "flow_id": 474420973708881, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:51:29.044923+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4238,1773082294.355500937,'{"timestamp": "2026-03-09T19:51:34.355501+0100", "flow_id": 1808340775108279, "event_type": "alert", "src_ip": "45.135.194.48", "src_port": 60427, "dest_ip": "134.19.55.199", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T19:51:34.355501+0100", "src_ip": "45.135.194.48", "dest_ip": "134.19.55.199", "src_port": 60427, "dest_port": 5555}}'); INSERT INTO alerts VALUES(4239,1773082308.137043953,'{"timestamp": "2026-03-09T19:51:48.137044+0100", "flow_id": 1151553479461496, "event_type": "alert", "src_ip": "167.94.146.44", "src_port": 15309, "dest_ip": "134.19.55.199", "dest_port": 56275, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:51:48.137044+0100", "src_ip": "167.94.146.44", "dest_ip": "134.19.55.199", "src_port": 15309, "dest_port": 56275}}'); INSERT INTO alerts VALUES(4240,1773082312.920725107,'{"timestamp": "2026-03-09T19:51:52.920725+0100", "flow_id": 13836596929621, "event_type": "alert", "src_ip": "195.184.76.177", "src_port": 3733, "dest_ip": "134.19.55.199", "dest_port": 5397, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T19:51:52.920725+0100", "src_ip": "195.184.76.177", "dest_ip": "134.19.55.199", "src_port": 3733, "dest_port": 5397}}'); INSERT INTO alerts VALUES(4241,1773082320.465933084,'{"timestamp": "2026-03-09T19:52:00.465933+0100", "flow_id": 30842472750055, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:52:00.465933+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4242,1773082320.471940995,'{"timestamp": "2026-03-09T19:52:00.471941+0100", "flow_id": 56649504826961, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:52:00.471941+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4243,1773082351.596560955,'{"timestamp": "2026-03-09T19:52:31.596561+0100", "flow_id": 1999260344245223, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:52:31.596561+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4244,1773082351.596937895,'{"timestamp": "2026-03-09T19:52:31.596938+0100", "flow_id": 2000882415478353, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:52:31.596938+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4245,1773082383.100801945,'{"timestamp": "2026-03-09T19:53:03.100802+0100", "flow_id": 2121791466232807, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:53:03.100802+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4246,1773082383.100802898,'{"timestamp": "2026-03-09T19:53:03.100803+0100", "flow_id": 2121798629762641, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:53:03.100803+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4247,1773082398.147840977,'{"timestamp": "2026-03-09T19:53:18.147841+0100", "flow_id": 1760872999096739, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 42309, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:53:18.147841+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 42309, "dest_port": 3306}}'); INSERT INTO alerts VALUES(4248,1773082398.147840977,'{"timestamp": "2026-03-09T19:53:18.147841+0100", "flow_id": 1760872999096739, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 42309, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:53:18.147841+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 42309, "dest_port": 3306}}'); INSERT INTO alerts VALUES(4249,1773082414.383950948,'{"timestamp": "2026-03-09T19:53:34.383951+0100", "flow_id": 1930532277574631, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:53:34.383951+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4250,1773082414.383951902,'{"timestamp": "2026-03-09T19:53:34.383952+0100", "flow_id": 1930539441104465, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:53:34.383952+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4251,1773082423.526958942,'{"timestamp": "2026-03-09T19:53:43.526959+0100", "flow_id": 1981798444246936, "event_type": "alert", "src_ip": "185.156.73.180", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 4434, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:53:43.526959+0100", "src_ip": "185.156.73.180", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 4434}}'); INSERT INTO alerts VALUES(4252,1773082443.766782999,'{"timestamp": "2026-03-09T19:54:03.766783+0100", "flow_id": 1041511157375103, "event_type": "alert", "src_ip": "205.210.31.215", "src_port": 55039, "dest_ip": "134.19.55.199", "dest_port": 2002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:54:03.766783+0100", "src_ip": "205.210.31.215", "dest_ip": "134.19.55.199", "src_port": 55039, "dest_port": 2002}}'); INSERT INTO alerts VALUES(4253,1773082445.845120907,'{"timestamp": "2026-03-09T19:54:05.845121+0100", "flow_id": 1659442531785703, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:54:05.845121+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4254,1773082445.845120907,'{"timestamp": "2026-03-09T19:54:05.845121+0100", "flow_id": 1659445400348241, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:54:05.845121+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4255,1773082453.040508985,'{"timestamp": "2026-03-09T19:54:13.040509+0100", "flow_id": 1581363933864745, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 8008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:54:13.040509+0100", "src_ip": "204.76.203.73", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 8008}}'); INSERT INTO alerts VALUES(4256,1773082453.040508985,'{"timestamp": "2026-03-09T19:54:13.040509+0100", "flow_id": 1581363933864745, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 8008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:54:13.040509+0100", "src_ip": "204.76.203.73", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 8008}}'); INSERT INTO alerts VALUES(4257,1773082462.270107031,'{"timestamp": "2026-03-09T19:54:22.270107+0100", "flow_id": 1723051435398189, "event_type": "alert", "src_ip": "198.235.24.104", "src_port": 50061, "dest_ip": "134.19.55.199", "dest_port": 1200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:54:22.270107+0100", "src_ip": "198.235.24.104", "dest_ip": "134.19.55.199", "src_port": 50061, "dest_port": 1200}}'); INSERT INTO alerts VALUES(4258,1773082476.940397025,'{"timestamp": "2026-03-09T19:54:36.940397+0100", "flow_id": 1224224905747431, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:54:36.940397+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4259,1773082476.940397978,'{"timestamp": "2026-03-09T19:54:36.940398+0100", "flow_id": 1224232069277265, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:54:36.940398+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4260,1773082479.123821021,'{"timestamp": "2026-03-09T19:54:39.123821+0100", "flow_id": 2220660580287566, "event_type": "alert", "src_ip": "2.57.122.238", "src_port": 41515, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2500026, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:54:39.123821+0100", "src_ip": "2.57.122.238", "dest_ip": "134.19.55.199", "src_port": 41515, "dest_port": 22}}'); INSERT INTO alerts VALUES(4261,1773082503.565231085,'{"timestamp": "2026-03-09T19:55:03.565231+0100", "flow_id": 2146176888561919, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 41245, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:55:03.565231+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.55.199", "src_port": 41245, "dest_port": 22}}'); INSERT INTO alerts VALUES(4262,1773082503.565231085,'{"timestamp": "2026-03-09T19:55:03.565231+0100", "flow_id": 2146176888561919, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 41245, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:55:03.565231+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.55.199", "src_port": 41245, "dest_port": 22}}'); INSERT INTO alerts VALUES(4263,1773082508.435667991,'{"timestamp": "2026-03-09T19:55:08.435668+0100", "flow_id": 1308230171089895, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:55:08.435668+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4264,1773082508.435667991,'{"timestamp": "2026-03-09T19:55:08.435668+0100", "flow_id": 1308233039652433, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:55:08.435668+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4265,1773082539.609152078,'{"timestamp": "2026-03-09T19:55:39.609152+0100", "flow_id": 927438366390950, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 40869, "dest_ip": "134.19.55.199", "dest_port": 9090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:55:39.609152+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 40869, "dest_port": 9090}}'); INSERT INTO alerts VALUES(4266,1773082539.609152078,'{"timestamp": "2026-03-09T19:55:39.609152+0100", "flow_id": 927438366390950, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 40869, "dest_ip": "134.19.55.199", "dest_port": 9090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:55:39.609152+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 40869, "dest_port": 9090}}'); INSERT INTO alerts VALUES(4267,1773082539.919162988,'{"timestamp": "2026-03-09T19:55:39.919163+0100", "flow_id": 851550593473511, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:55:39.919163+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4268,1773082539.920331955,'{"timestamp": "2026-03-09T19:55:39.920332+0100", "flow_id": 856574278805073, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:55:39.920332+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4269,1773082549.550074101,'{"timestamp": "2026-03-09T19:55:49.550074+0100", "flow_id": 1518126993457431, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53915, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33389, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:55:49.550074+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53915, "dest_port": 53}}'); INSERT INTO alerts VALUES(4270,1773082549.550075055,'{"timestamp": "2026-03-09T19:55:49.550075+0100", "flow_id": 1518132004861740, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55143, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63432, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:55:49.550075+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55143, "dest_port": 53}}'); INSERT INTO alerts VALUES(4271,1773082549.550075055,'{"timestamp": "2026-03-09T19:55:49.550075+0100", "flow_id": 1518130733291244, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62527, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17198, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:55:49.550075+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62527, "dest_port": 53}}'); INSERT INTO alerts VALUES(4272,1773082549.550075055,'{"timestamp": "2026-03-09T19:55:49.550075+0100", "flow_id": 1518129510797128, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56387, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39684, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:55:49.550075+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56387, "dest_port": 53}}'); INSERT INTO alerts VALUES(4273,1773082549.550076007,'{"timestamp": "2026-03-09T19:55:49.550076+0100", "flow_id": 1518135977902522, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61324, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21144, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:55:49.550076+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61324, "dest_port": 53}}'); INSERT INTO alerts VALUES(4274,1773082549.550076007,'{"timestamp": "2026-03-09T19:55:49.550076+0100", "flow_id": 1518134135245697, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57354, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53471, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:55:49.550076+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57354, "dest_port": 53}}'); INSERT INTO alerts VALUES(4275,1773082549.550076007,'{"timestamp": "2026-03-09T19:55:49.550076+0100", "flow_id": 1518137741177110, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64320, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55239, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:55:49.550076+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64320, "dest_port": 53}}'); INSERT INTO alerts VALUES(4276,1773082549.55081892,'{"timestamp": "2026-03-09T19:55:49.550819+0100", "flow_id": 1521327844598120, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54703, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50024, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:55:49.550819+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54703, "dest_port": 53}}'); INSERT INTO alerts VALUES(4277,1773082556.301410913,'{"timestamp": "2026-03-09T19:55:56.301411+0100", "flow_id": 1294550645380764, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54631, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49701, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:55:56.301411+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54631, "dest_port": 53}}'); INSERT INTO alerts VALUES(4278,1773082571.223256111,'{"timestamp": "2026-03-09T19:56:11.223256+0100", "flow_id": 958877531233255, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:56:11.223256+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4279,1773082571.223257065,'{"timestamp": "2026-03-09T19:56:11.223257+0100", "flow_id": 958884694763089, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:56:11.223257+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4280,1773082602.413286924,'{"timestamp": "2026-03-09T19:56:42.413287+0100", "flow_id": 649154554616807, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:56:42.413287+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4281,1773082602.413286924,'{"timestamp": "2026-03-09T19:56:42.413287+0100", "flow_id": 649157423179345, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:56:42.413287+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4282,1773082633.425410986,'{"timestamp": "2026-03-09T19:57:13.425411+0100", "flow_id": 419751761402855, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:57:13.425411+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4283,1773082633.425411939,'{"timestamp": "2026-03-09T19:57:13.425412+0100", "flow_id": 419758924932689, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:57:13.425412+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4284,1773082650.655390024,'{"timestamp": "2026-03-09T19:57:30.655390+0100", "flow_id": 563081280160186, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61324, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21144, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:57:30.655390+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61324, "dest_port": 53}}'); INSERT INTO alerts VALUES(4285,1773082650.655390977,'{"timestamp": "2026-03-09T19:57:30.655391+0100", "flow_id": 563083732470657, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57354, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53471, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:57:30.655391+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57354, "dest_port": 53}}'); INSERT INTO alerts VALUES(4286,1773082650.655390977,'{"timestamp": "2026-03-09T19:57:30.655391+0100", "flow_id": 563087338402070, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64320, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55239, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:57:30.655391+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64320, "dest_port": 53}}'); INSERT INTO alerts VALUES(4287,1773082650.655390977,'{"timestamp": "2026-03-09T19:57:30.655391+0100", "flow_id": 563086281122152, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54703, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50024, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:57:30.655391+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54703, "dest_port": 53}}'); INSERT INTO alerts VALUES(4288,1773082664.911628008,'{"timestamp": "2026-03-09T19:57:44.911628+0100", "flow_id": 256238061476839, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:57:44.911628+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4289,1773082664.911628008,'{"timestamp": "2026-03-09T19:57:44.911628+0100", "flow_id": 256240930039377, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:57:44.911628+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4290,1773082679.160425902,'{"timestamp": "2026-03-09T19:57:59.160426+0100", "flow_id": 2096401322824326, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 14439, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:57:59.160426+0100", "src_ip": "185.156.73.181", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 14439}}'); INSERT INTO alerts VALUES(4291,1773082682.089082956,'{"timestamp": "2026-03-09T19:58:02.089083+0100", "flow_id": 664086026060218, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61324, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21144, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:58:02.089083+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61324, "dest_port": 53}}'); INSERT INTO alerts VALUES(4292,1773082682.232410907,'{"timestamp": "2026-03-09T19:58:02.232411+0100", "flow_id": 716723302583169, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57354, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53471, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:58:02.232411+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57354, "dest_port": 53}}'); INSERT INTO alerts VALUES(4293,1773082682.232410907,'{"timestamp": "2026-03-09T19:58:02.232411+0100", "flow_id": 716726908514582, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64320, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55239, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:58:02.232411+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64320, "dest_port": 53}}'); INSERT INTO alerts VALUES(4294,1773082682.232410907,'{"timestamp": "2026-03-09T19:58:02.232411+0100", "flow_id": 716725851234664, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54703, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50024, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:58:02.232411+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54703, "dest_port": 53}}'); INSERT INTO alerts VALUES(4295,1773082686.327126026,'{"timestamp": "2026-03-09T19:58:06.327126+0100", "flow_id": 1967948607434210, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 62313, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:58:06.327126+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 62313}}'); INSERT INTO alerts VALUES(4296,1773082686.327126026,'{"timestamp": "2026-03-09T19:58:06.327126+0100", "flow_id": 1967948607434210, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 62313, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T19:58:06.327126+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 62313}}'); INSERT INTO alerts VALUES(4297,1773082689.021415948,'{"timestamp": "2026-03-09T19:58:09.021416+0100", "flow_id": 373457056094058, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52056, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7529, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:58:09.021416+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52056, "dest_port": 53}}'); INSERT INTO alerts VALUES(4298,1773082689.021416903,'{"timestamp": "2026-03-09T19:58:09.021417+0100", "flow_id": 373463483166490, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47054, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:58:09.021417+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64876, "dest_port": 53}}'); INSERT INTO alerts VALUES(4299,1773082696.299464942,'{"timestamp": "2026-03-09T19:58:16.299465+0100", "flow_id": 160292787051495, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:58:16.299465+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4300,1773082696.299465895,'{"timestamp": "2026-03-09T19:58:16.299466+0100", "flow_id": 160299950581329, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:58:16.299466+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4301,1773082722.405174016,'{"timestamp": "2026-03-09T19:58:42.405174+0100", "flow_id": 614309879398512, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52821, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:58:42.405174+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57596, "dest_port": 53}}'); INSERT INTO alerts VALUES(4302,1773082722.405174016,'{"timestamp": "2026-03-09T19:58:42.405174+0100", "flow_id": 614310754761242, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55227, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24093, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:58:42.405174+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55227, "dest_port": 53}}'); INSERT INTO alerts VALUES(4303,1773082727.679100037,'{"timestamp": "2026-03-09T19:58:47.679100+0100", "flow_id": 2072288518375071, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63017, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:58:47.679100+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63017, "dest_port": 53}}'); INSERT INTO alerts VALUES(4304,1773082727.679100037,'{"timestamp": "2026-03-09T19:58:47.679100+0100", "flow_id": 2072289979307808, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58408, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39647, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T19:58:47.679100+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58408, "dest_port": 53}}'); INSERT INTO alerts VALUES(4305,1773082727.682564021,'{"timestamp": "2026-03-09T19:58:47.682564+0100", "flow_id": 2087165439892455, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:58:47.682564+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4306,1773082727.682564973,'{"timestamp": "2026-03-09T19:58:47.682565+0100", "flow_id": 2087172603422289, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:58:47.682565+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4307,1773082741.274554967,'{"timestamp": "2026-03-09T19:59:01.274555+0100", "flow_id": 1646668074842344, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 45850, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:59:01.252322+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 45850, "dest_port": 853}}'); INSERT INTO alerts VALUES(4308,1773082748.431493997,'{"timestamp": "2026-03-09T19:59:08.431494+0100", "flow_id": 1290303508132610, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51475, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49840, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T19:59:08.431494+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51475, "dest_port": 53}}'); INSERT INTO alerts VALUES(4309,1773082749.447722912,'{"timestamp": "2026-03-09T19:59:09.447723+0100", "flow_id": 1544401251810203, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39442, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T19:59:09.425119+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 39442, "dest_port": 853}}'); INSERT INTO alerts VALUES(4310,1773082753.09532094,'{"timestamp": "2026-03-09T19:59:13.095321+0100", "flow_id": 409404319094111, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59854, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30654, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:59:13.095321+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59854, "dest_port": 53}}'); INSERT INTO alerts VALUES(4311,1773082754.312232971,'{"timestamp": "2026-03-09T19:59:14.312233+0100", "flow_id": 778081008376868, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53363, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64332, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:59:14.312233+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53363, "dest_port": 53}}'); INSERT INTO alerts VALUES(4312,1773082757.785653114,'{"timestamp": "2026-03-09T19:59:17.785653+0100", "flow_id": 1685507725746739, "event_type": "alert", "src_ip": "198.235.24.114", "src_port": 50616, "dest_ip": "134.19.55.199", "dest_port": 4343, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T19:59:17.785653+0100", "src_ip": "198.235.24.114", "dest_ip": "134.19.55.199", "src_port": 50616, "dest_port": 4343}}'); INSERT INTO alerts VALUES(4313,1773082759.095865012,'{"timestamp": "2026-03-09T19:59:19.095865+0100", "flow_id": 2100587212692455, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:59:19.095865+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4314,1773082759.095865012,'{"timestamp": "2026-03-09T19:59:19.095865+0100", "flow_id": 2100590081254993, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:59:19.095865+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4315,1773082790.349181891,'{"timestamp": "2026-03-09T19:59:50.349182+0100", "flow_id": 1781200559660007, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:59:50.349182+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4316,1773082790.349181891,'{"timestamp": "2026-03-09T19:59:50.349182+0100", "flow_id": 1781203428222545, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T19:59:50.349182+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4317,1773082792.206659078,'{"timestamp": "2026-03-09T19:59:52.206659+0100", "flow_id": 43170336068192, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59030, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6790, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:59:52.206659+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59030, "dest_port": 53}}'); INSERT INTO alerts VALUES(4318,1773082792.206659078,'{"timestamp": "2026-03-09T19:59:52.206659+0100", "flow_id": 43171120381714, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64084, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10276, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T19:59:52.206659+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64084, "dest_port": 53}}'); INSERT INTO alerts VALUES(4319,1773082806.841063022,'{"timestamp": "2026-03-09T20:00:06.841063+0100", "flow_id": 1923489193796262, "event_type": "alert", "src_ip": "198.235.24.82", "src_port": 52424, "dest_ip": "134.19.55.199", "dest_port": 2602, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:00:06.841063+0100", "src_ip": "198.235.24.82", "dest_ip": "134.19.55.199", "src_port": 52424, "dest_port": 2602}}'); INSERT INTO alerts VALUES(4320,1773082821.837523938,'{"timestamp": "2026-03-09T20:00:21.837524+0100", "flow_id": 1626813665237991, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:00:21.837524+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4321,1773082821.837523938,'{"timestamp": "2026-03-09T20:00:21.837524+0100", "flow_id": 1626816533800529, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:00:21.837524+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4322,1773082827.193722963,'{"timestamp": "2026-03-09T20:00:27.193723+0100", "flow_id": 1113513184180082, "event_type": "alert", "src_ip": "178.20.210.151", "src_port": 55419, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:00:27.193723+0100", "src_ip": "178.20.210.151", "dest_ip": "134.19.55.199", "src_port": 55419, "dest_port": 22}}'); INSERT INTO alerts VALUES(4323,1773082831.677234889,'{"timestamp": "2026-03-09T20:00:31.677235+0100", "flow_id": 2064277478060065, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 54334, "dest_ip": "134.19.55.199", "dest_port": 8081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:00:31.677235+0100", "src_ip": "87.121.84.57", "dest_ip": "134.19.55.199", "src_port": 54334, "dest_port": 8081}}'); INSERT INTO alerts VALUES(4324,1773082848.913736105,'{"timestamp": "2026-03-09T20:00:48.913736+0100", "flow_id": 265294017659322, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61324, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21144, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:00:48.913736+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61324, "dest_port": 53}}'); INSERT INTO alerts VALUES(4325,1773082848.913736105,'{"timestamp": "2026-03-09T20:00:48.913736+0100", "flow_id": 265292175002497, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57354, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53471, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:00:48.913736+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57354, "dest_port": 53}}'); INSERT INTO alerts VALUES(4326,1773082848.913736105,'{"timestamp": "2026-03-09T20:00:48.913736+0100", "flow_id": 265295780933910, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64320, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55239, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:00:48.913736+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64320, "dest_port": 53}}'); INSERT INTO alerts VALUES(4327,1773082848.913737058,'{"timestamp": "2026-03-09T20:00:48.913737+0100", "flow_id": 265299018621288, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54703, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50024, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:00:48.913737+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54703, "dest_port": 53}}'); INSERT INTO alerts VALUES(4328,1773082848.913737058,'{"timestamp": "2026-03-09T20:00:48.913737+0100", "flow_id": 265299075767951, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52207, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16203, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:00:48.913737+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52207, "dest_port": 53}}'); INSERT INTO alerts VALUES(4329,1773082848.913737058,'{"timestamp": "2026-03-09T20:00:48.913737+0100", "flow_id": 265296472513690, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56594, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43882, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:00:48.913737+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56594, "dest_port": 53}}'); INSERT INTO alerts VALUES(4330,1773082848.913738012,'{"timestamp": "2026-03-09T20:00:48.913738+0100", "flow_id": 265302232976097, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55122, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8896, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:00:48.913738+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55122, "dest_port": 53}}'); INSERT INTO alerts VALUES(4331,1773082853.221229076,'{"timestamp": "2026-03-09T20:00:53.221229+0100", "flow_id": 1513121585945575, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:00:53.221229+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4332,1773082853.221230031,'{"timestamp": "2026-03-09T20:00:53.221230+0100", "flow_id": 1513128749475409, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:00:53.221230+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4333,1773082860.352294921,'{"timestamp": "2026-03-09T20:01:00.352295+0100", "flow_id": 1231621090927766, "event_type": "alert", "src_ip": "91.196.152.189", "src_port": 23781, "dest_ip": "134.19.55.199", "dest_port": 20154, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:01:00.352295+0100", "src_ip": "91.196.152.189", "dest_ip": "134.19.55.199", "src_port": 23781, "dest_port": 20154}}'); INSERT INTO alerts VALUES(4334,1773082869.447428941,'{"timestamp": "2026-03-09T20:01:09.447429+0100", "flow_id": 1548987914719822, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 52034, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:01:09.426187+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 52034, "dest_port": 853}}'); INSERT INTO alerts VALUES(4335,1773082884.568905116,'{"timestamp": "2026-03-09T20:01:24.568905+0100", "flow_id": 1317528775285735, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:01:24.568905+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4336,1773082884.568905116,'{"timestamp": "2026-03-09T20:01:24.568905+0100", "flow_id": 1317531643848273, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:01:24.568905+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4337,1773082890.327826023,'{"timestamp": "2026-03-09T20:01:30.327826+0100", "flow_id": 563581286556823, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 58402, "dest_ip": "134.19.55.199", "dest_port": 30604, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:01:30.327826+0100", "src_ip": "167.94.146.40", "dest_ip": "134.19.55.199", "src_port": 58402, "dest_port": 30604}}'); INSERT INTO alerts VALUES(4338,1773082909.244685888,'{"timestamp": "2026-03-09T20:01:49.244686+0100", "flow_id": 1518966870398517, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53676, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:01:49.222590+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 53676, "dest_port": 853}}'); INSERT INTO alerts VALUES(4339,1773082911.949003935,'{"timestamp": "2026-03-09T20:01:51.949004+0100", "flow_id": 2105617810857198, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62243, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60668, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "geo-applefinance-cache.internal.query.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 100, "bytes_toclient": 0, "start": "2026-03-09T20:01:51.949004+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62243, "dest_port": 53}}'); INSERT INTO alerts VALUES(4340,1773082913.2784791,'{"timestamp": "2026-03-09T20:01:53.278479+0100", "flow_id": 351636781324098, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50015, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T20:01:53.278479+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61876, "dest_port": 53}}'); INSERT INTO alerts VALUES(4341,1773082915.052167893,'{"timestamp": "2026-03-09T20:01:55.052168+0100", "flow_id": 1068485717554337, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53446, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4528, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:01:55.052168+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53446, "dest_port": 53}}'); INSERT INTO alerts VALUES(4342,1773082915.052169084,'{"timestamp": "2026-03-09T20:01:55.052169+0100", "flow_id": 1068490445394380, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61316, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60435, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:01:55.052169+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61316, "dest_port": 53}}'); INSERT INTO alerts VALUES(4343,1773082915.052169084,'{"timestamp": "2026-03-09T20:01:55.052169+0100", "flow_id": 1068489391594471, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:01:55.052169+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4344,1773082915.052169084,'{"timestamp": "2026-03-09T20:01:55.052169+0100", "flow_id": 1068492260157009, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:01:55.052169+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4345,1773082920.083894969,'{"timestamp": "2026-03-09T20:02:00.083895+0100", "flow_id": 78854824415529, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 42930, "dest_ip": "134.19.55.199", "dest_port": 49666, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:02:00.083895+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 42930, "dest_port": 49666}}'); INSERT INTO alerts VALUES(4346,1773082927.984082938,'{"timestamp": "2026-03-09T20:02:07.984083+0100", "flow_id": 1974807458594902, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52357, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26663, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:02:07.984083+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52357, "dest_port": 53}}'); INSERT INTO alerts VALUES(4347,1773082930.831417084,'{"timestamp": "2026-03-09T20:02:10.831417+0100", "flow_id": 756159712041879, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61717, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20108, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T20:02:10.831417+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61717, "dest_port": 53}}'); INSERT INTO alerts VALUES(4348,1773082930.831418038,'{"timestamp": "2026-03-09T20:02:10.831418+0100", "flow_id": 756164508174877, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62334, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38196, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T20:02:10.831418+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62334, "dest_port": 53}}'); INSERT INTO alerts VALUES(4349,1773082946.086698055,'{"timestamp": "2026-03-09T20:02:26.086698+0100", "flow_id": 653840363936743, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:02:26.086698+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4350,1773082946.086698055,'{"timestamp": "2026-03-09T20:02:26.086698+0100", "flow_id": 653843232499281, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:02:26.086698+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4351,1773082955.587985992,'{"timestamp": "2026-03-09T20:02:35.587986+0100", "flow_id": 1118005980569217, "event_type": "alert", "src_ip": "198.235.24.203", "src_port": 52027, "dest_ip": "134.19.55.199", "dest_port": 8090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:02:35.587986+0100", "src_ip": "198.235.24.203", "dest_ip": "134.19.55.199", "src_port": 52027, "dest_port": 8090}}'); INSERT INTO alerts VALUES(4352,1773082976.080959081,'{"timestamp": "2026-03-09T20:02:56.080959+0100", "flow_id": 66242321112406, "event_type": "alert", "src_ip": "195.184.76.141", "src_port": 17643, "dest_ip": "134.19.55.199", "dest_port": 7008, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:02:56.080959+0100", "src_ip": "195.184.76.141", "dest_ip": "134.19.55.199", "src_port": 17643, "dest_port": 7008}}'); INSERT INTO alerts VALUES(4353,1773082976.35569501,'{"timestamp": "2026-03-09T20:02:56.355695+0100", "flow_id": 120326438122527, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55228, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44956, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:02:56.355695+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55228, "dest_port": 53}}'); INSERT INTO alerts VALUES(4354,1773082977.581671953,'{"timestamp": "2026-03-09T20:02:57.581672+0100", "flow_id": 527937692621799, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:02:57.581672+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4355,1773082977.581672907,'{"timestamp": "2026-03-09T20:02:57.581673+0100", "flow_id": 527944856151633, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:02:57.581673+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4356,1773082983.261807918,'{"timestamp": "2026-03-09T20:03:03.261808+0100", "flow_id": 2250358024249565, "event_type": "alert", "src_ip": "167.94.146.42", "src_port": 20142, "dest_ip": "134.19.55.199", "dest_port": 45805, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:03:03.261808+0100", "src_ip": "167.94.146.42", "dest_ip": "134.19.55.199", "src_port": 20142, "dest_port": 45805}}'); INSERT INTO alerts VALUES(4357,1773082983.54377389,'{"timestamp": "2026-03-09T20:03:03.543774+0100", "flow_id": 2054020275765370, "event_type": "alert", "src_ip": "167.94.146.33", "src_port": 3853, "dest_ip": "134.19.55.199", "dest_port": 20652, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:03:03.543774+0100", "src_ip": "167.94.146.33", "dest_ip": "134.19.55.199", "src_port": 3853, "dest_port": 20652}}'); INSERT INTO alerts VALUES(4358,1773083008.989825964,'{"timestamp": "2026-03-09T20:03:28.989826+0100", "flow_id": 29145960668135, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:03:28.989826+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4359,1773083008.989825964,'{"timestamp": "2026-03-09T20:03:28.989826+0100", "flow_id": 29148829230673, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:03:28.989826+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4360,1773083016.085223914,'{"timestamp": "2026-03-09T20:03:36.085224+0100", "flow_id": 84562831337760, "event_type": "alert", "src_ip": "195.184.76.173", "src_port": 401, "dest_ip": "134.19.55.199", "dest_port": 6601, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:03:36.085224+0100", "src_ip": "195.184.76.173", "dest_ip": "134.19.55.199", "src_port": 401, "dest_port": 6601}}'); INSERT INTO alerts VALUES(4361,1773083018.837758064,'{"timestamp": "2026-03-09T20:03:38.837758+0100", "flow_id": 783394469838866, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56430, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65054, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:03:38.837758+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56430, "dest_port": 53}}'); INSERT INTO alerts VALUES(4362,1773083018.839055062,'{"timestamp": "2026-03-09T20:03:38.839055+0100", "flow_id": 788966730002034, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60779, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8558, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:03:38.839055+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60779, "dest_port": 53}}'); INSERT INTO alerts VALUES(4363,1773083027.354896069,'{"timestamp": "2026-03-09T20:03:47.354896+0100", "flow_id": 961317809546204, "event_type": "alert", "src_ip": "195.184.76.165", "src_port": 21916, "dest_ip": "134.19.55.199", "dest_port": 6112, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:03:47.354896+0100", "src_ip": "195.184.76.165", "dest_ip": "134.19.55.199", "src_port": 21916, "dest_port": 6112}}'); INSERT INTO alerts VALUES(4364,1773083029.217514992,'{"timestamp": "2026-03-09T20:03:49.217515+0100", "flow_id": 1497171274361993, "event_type": "alert", "src_ip": "147.185.132.10", "src_port": 51477, "dest_ip": "134.19.55.199", "dest_port": 9001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:03:49.217515+0100", "src_ip": "147.185.132.10", "dest_ip": "134.19.55.199", "src_port": 51477, "dest_port": 9001}}'); INSERT INTO alerts VALUES(4365,1773083029.246264934,'{"timestamp": "2026-03-09T20:03:49.246265+0100", "flow_id": 1527763774517729, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 57046, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:03:49.224638+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 57046, "dest_port": 853}}'); INSERT INTO alerts VALUES(4366,1773083029.832144975,'{"timestamp": "2026-03-09T20:03:49.832145+0100", "flow_id": 1603714493253883, "event_type": "alert", "src_ip": "91.196.152.37", "src_port": 1906, "dest_ip": "134.19.55.199", "dest_port": 20087, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:03:49.832145+0100", "src_ip": "91.196.152.37", "dest_ip": "134.19.55.199", "src_port": 1906, "dest_port": 20087}}'); INSERT INTO alerts VALUES(4367,1773083037.218172074,'{"timestamp": "2026-03-09T20:03:57.218172+0100", "flow_id": 1499993232174611, "event_type": "alert", "src_ip": "91.196.152.181", "src_port": 43507, "dest_ip": "134.19.55.199", "dest_port": 2156, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:03:57.218172+0100", "src_ip": "91.196.152.181", "dest_ip": "134.19.55.199", "src_port": 43507, "dest_port": 2156}}'); INSERT INTO alerts VALUES(4368,1773083050.739008904,'{"timestamp": "2026-03-09T20:04:10.739009+0100", "flow_id": 640748585615731, "event_type": "alert", "src_ip": "195.184.76.117", "src_port": 1406, "dest_ip": "134.19.55.199", "dest_port": 6012, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:04:10.739009+0100", "src_ip": "195.184.76.117", "dest_ip": "134.19.55.199", "src_port": 1406, "dest_port": 6012}}'); INSERT INTO alerts VALUES(4369,1773083060.267098903,'{"timestamp": "2026-03-09T20:04:20.267099+0100", "flow_id": 1147182147775136, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 36735, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:04:20.267099+0100", "src_ip": "130.12.180.174", "dest_ip": "134.19.55.199", "src_port": 36735, "dest_port": 23}}'); INSERT INTO alerts VALUES(4370,1773083060.267098903,'{"timestamp": "2026-03-09T20:04:20.267099+0100", "flow_id": 1147182147775136, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 36735, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:04:20.267099+0100", "src_ip": "130.12.180.174", "dest_ip": "134.19.55.199", "src_port": 36735, "dest_port": 23}}'); INSERT INTO alerts VALUES(4371,1773083072.446943044,'{"timestamp": "2026-03-09T20:04:32.446943+0100", "flow_id": 230757285482105, "event_type": "alert", "src_ip": "198.235.24.121", "src_port": 49497, "dest_ip": "134.19.55.199", "dest_port": 1900, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 125, "bytes_toclient": 0, "start": "2026-03-09T20:04:32.446943+0100", "src_ip": "198.235.24.121", "dest_ip": "134.19.55.199", "src_port": 49497, "dest_port": 1900}}'); INSERT INTO alerts VALUES(4372,1773083082.822247982,'{"timestamp": "2026-03-09T20:04:42.822248+0100", "flow_id": 716778814692327, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:04:42.822248+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4373,1773083082.822248936,'{"timestamp": "2026-03-09T20:04:42.822249+0100", "flow_id": 716785978222161, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:04:42.822249+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4374,1773083093.294528962,'{"timestamp": "2026-03-09T20:04:53.294529+0100", "flow_id": 1455469706555122, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 37298, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:04:53.273341+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 37298, "dest_port": 853}}'); INSERT INTO alerts VALUES(4375,1773083113.321672917,'{"timestamp": "2026-03-09T20:05:13.321673+0100", "flow_id": 537150397471719, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:05:13.321673+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4376,1773083113.321674108,'{"timestamp": "2026-03-09T20:05:13.321674+0100", "flow_id": 537157561001553, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:05:13.321674+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4377,1773083140.030901909,'{"timestamp": "2026-03-09T20:05:40.030902+0100", "flow_id": 1258624561080751, "event_type": "alert", "src_ip": "195.184.76.37", "src_port": 26404, "dest_ip": "134.19.55.199", "dest_port": 7014, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:05:40.030902+0100", "src_ip": "195.184.76.37", "dest_ip": "134.19.55.199", "src_port": 26404, "dest_port": 7014}}'); INSERT INTO alerts VALUES(4378,1773083167.515130044,'{"timestamp": "2026-03-09T20:06:07.515130+0100", "flow_id": 2212469271838278, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53839, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30354, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:06:07.515130+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53839, "dest_port": 53}}'); INSERT INTO alerts VALUES(4379,1773083167.515130044,'{"timestamp": "2026-03-09T20:06:07.515130+0100", "flow_id": 2212467181757828, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57933, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44590, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:06:07.515130+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57933, "dest_port": 53}}'); INSERT INTO alerts VALUES(4380,1773083173.716520072,'{"timestamp": "2026-03-09T20:06:13.716520+0100", "flow_id": 1670056210148430, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62982, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 465, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T20:06:13.716520+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62982, "dest_port": 53}}'); INSERT INTO alerts VALUES(4381,1773083179.190308095,'{"timestamp": "2026-03-09T20:06:19.190308+0100", "flow_id": 1098844734251725, "event_type": "alert", "src_ip": "167.94.138.148", "src_port": 1454, "dest_ip": "134.19.55.199", "dest_port": 5351, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 32, "bytes_toclient": 0, "start": "2026-03-09T20:06:19.190308+0100", "src_ip": "167.94.138.148", "dest_ip": "134.19.55.199", "src_port": 1454, "dest_port": 5351}}'); INSERT INTO alerts VALUES(4382,1773083185.055856943,'{"timestamp": "2026-03-09T20:06:25.055857+0100", "flow_id": 521379277560807, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:06:25.055857+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4383,1773083185.055856943,'{"timestamp": "2026-03-09T20:06:25.055857+0100", "flow_id": 521382146123345, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:06:25.055857+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4384,1773083198.307152033,'{"timestamp": "2026-03-09T20:06:38.307152+0100", "flow_id": 1882160502975624, "event_type": "alert", "src_ip": "205.210.31.101", "src_port": 49989, "dest_ip": "134.19.55.199", "dest_port": 8991, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:06:38.307152+0100", "src_ip": "205.210.31.101", "dest_ip": "134.19.55.199", "src_port": 49989, "dest_port": 8991}}'); INSERT INTO alerts VALUES(4385,1773083201.828660011,'{"timestamp": "2026-03-09T20:06:41.828660+0100", "flow_id": 462845030266282, "event_type": "alert", "src_ip": "176.65.148.197", "src_port": 43218, "dest_ip": "134.19.55.199", "dest_port": 5006, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:06:41.828660+0100", "src_ip": "176.65.148.197", "dest_ip": "134.19.55.199", "src_port": 43218, "dest_port": 5006}}'); INSERT INTO alerts VALUES(4386,1773083201.828660011,'{"timestamp": "2026-03-09T20:06:41.828660+0100", "flow_id": 462845030266282, "event_type": "alert", "src_ip": "176.65.148.197", "src_port": 43218, "dest_ip": "134.19.55.199", "dest_port": 5006, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:06:41.828660+0100", "src_ip": "176.65.148.197", "dest_ip": "134.19.55.199", "src_port": 43218, "dest_port": 5006}}'); INSERT INTO alerts VALUES(4387,1773083210.282505035,'{"timestamp": "2026-03-09T20:06:50.282505+0100", "flow_id": 650402090013041, "event_type": "alert", "src_ip": "195.184.76.133", "src_port": 46703, "dest_ip": "134.19.55.199", "dest_port": 8060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:06:50.282505+0100", "src_ip": "195.184.76.133", "dest_ip": "134.19.55.199", "src_port": 46703, "dest_port": 8060}}'); INSERT INTO alerts VALUES(4388,1773083213.297604085,'{"timestamp": "2026-03-09T20:06:53.297604+0100", "flow_id": 1468558955689408, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 37016, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:06:53.276389+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 37016, "dest_port": 853}}'); INSERT INTO alerts VALUES(4389,1773083216.388020992,'{"timestamp": "2026-03-09T20:06:56.388021+0100", "flow_id": 259162934205415, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:06:56.388021+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4390,1773083216.388020992,'{"timestamp": "2026-03-09T20:06:56.388021+0100", "flow_id": 259165802767953, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:06:56.388021+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4391,1773083238.903436899,'{"timestamp": "2026-03-09T20:07:18.903437+0100", "flow_id": 1909911095948845, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57196, "dest_ip": "74.125.250.129", "dest_port": 19302, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2033078, "rev": 4, "signature": "ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard High Port)", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2021_06_03"], "deployment": ["alert_only", "Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2023_04_28"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 48, "bytes_toclient": 0, "start": "2026-03-09T20:07:18.903437+0100", "src_ip": "192.168.2.37", "dest_ip": "74.125.250.129", "src_port": 57196, "dest_port": 19302}}'); INSERT INTO alerts VALUES(4392,1773083239.156548024,'{"timestamp": "2026-03-09T20:07:19.156548+0100", "flow_id": 1909911095948845, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57196, "dest_ip": "74.125.250.129", "dest_port": 19302, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2033078, "rev": 4, "signature": "ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard High Port)", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2021_06_03"], "deployment": ["alert_only", "Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2023_04_28"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 96, "bytes_toclient": 0, "start": "2026-03-09T20:07:18.903437+0100", "src_ip": "192.168.2.37", "dest_ip": "74.125.250.129", "src_port": 57196, "dest_port": 19302}}'); INSERT INTO alerts VALUES(4393,1773083239.660392999,'{"timestamp": "2026-03-09T20:07:19.660393+0100", "flow_id": 1909911095948845, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57196, "dest_ip": "74.125.250.129", "dest_port": 19302, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2033078, "rev": 4, "signature": "ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard High Port)", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2021_06_03"], "deployment": ["alert_only", "Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2023_04_28"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 3, "pkts_toclient": 0, "bytes_toserver": 144, "bytes_toclient": 0, "start": "2026-03-09T20:07:18.903437+0100", "src_ip": "192.168.2.37", "dest_ip": "74.125.250.129", "src_port": 57196, "dest_port": 19302}}'); INSERT INTO alerts VALUES(4394,1773083240.663314105,'{"timestamp": "2026-03-09T20:07:20.663314+0100", "flow_id": 1909911095948845, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57196, "dest_ip": "74.125.250.129", "dest_port": 19302, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2033078, "rev": 4, "signature": "ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard High Port)", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2021_06_03"], "deployment": ["alert_only", "Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2023_04_28"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 0, "bytes_toserver": 192, "bytes_toclient": 0, "start": "2026-03-09T20:07:18.903437+0100", "src_ip": "192.168.2.37", "dest_ip": "74.125.250.129", "src_port": 57196, "dest_port": 19302}}'); INSERT INTO alerts VALUES(4395,1773083242.675373077,'{"timestamp": "2026-03-09T20:07:22.675373+0100", "flow_id": 1909911095948845, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57196, "dest_ip": "74.125.250.129", "dest_port": 19302, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2033078, "rev": 4, "signature": "ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard High Port)", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2021_06_03"], "deployment": ["alert_only", "Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2023_04_28"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 5, "pkts_toclient": 0, "bytes_toserver": 240, "bytes_toclient": 0, "start": "2026-03-09T20:07:18.903437+0100", "src_ip": "192.168.2.37", "dest_ip": "74.125.250.129", "src_port": 57196, "dest_port": 19302}}'); INSERT INTO alerts VALUES(4396,1773083246.670608997,'{"timestamp": "2026-03-09T20:07:26.670609+0100", "flow_id": 1909911095948845, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57196, "dest_ip": "74.125.250.129", "dest_port": 19302, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2033078, "rev": 4, "signature": "ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard High Port)", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2021_06_03"], "deployment": ["alert_only", "Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2023_04_28"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 6, "pkts_toclient": 0, "bytes_toserver": 288, "bytes_toclient": 0, "start": "2026-03-09T20:07:18.903437+0100", "src_ip": "192.168.2.37", "dest_ip": "74.125.250.129", "src_port": 57196, "dest_port": 19302}}'); INSERT INTO alerts VALUES(4397,1773083247.650798082,'{"timestamp": "2026-03-09T20:07:27.650798+0100", "flow_id": 2232206485478375, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:07:27.650798+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4398,1773083247.650798082,'{"timestamp": "2026-03-09T20:07:27.650798+0100", "flow_id": 2232209354040913, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:07:27.650798+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4399,1773083252.61789298,'{"timestamp": "2026-03-09T20:07:32.617893+0100", "flow_id": 1155697460495988, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 37424, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:07:32.596761+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 37424, "dest_port": 853}}'); INSERT INTO alerts VALUES(4400,1773083254.674124957,'{"timestamp": "2026-03-09T20:07:34.674125+0100", "flow_id": 1909911095948845, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57196, "dest_ip": "74.125.250.129", "dest_port": 19302, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2033078, "rev": 4, "signature": "ET INFO Session Traversal Utilities for NAT (STUN Binding Request On Non-Standard High Port)", "category": "Misc activity", "severity": 3, "metadata": {"confidence": ["High"], "created_at": ["2021_06_03"], "deployment": ["alert_only", "Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2023_04_28"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 7, "pkts_toclient": 0, "bytes_toserver": 336, "bytes_toclient": 0, "start": "2026-03-09T20:07:18.903437+0100", "src_ip": "192.168.2.37", "dest_ip": "74.125.250.129", "src_port": 57196, "dest_port": 19302}}'); INSERT INTO alerts VALUES(4401,1773083298.782481909,'{"timestamp": "2026-03-09T20:08:18.782482+0100", "flow_id": 827463539523022, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64470, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23015, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:08:18.782482+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64470, "dest_port": 53}}'); INSERT INTO alerts VALUES(4402,1773083318.239408969,'{"timestamp": "2026-03-09T20:08:38.239409+0100", "flow_id": 1872678962399180, "event_type": "alert", "src_ip": "196.202.110.24", "src_port": 57199, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:08:38.239409+0100", "src_ip": "196.202.110.24", "dest_ip": "134.19.55.199", "src_port": 57199, "dest_port": 1433}}'); INSERT INTO alerts VALUES(4403,1773083337.266171932,'{"timestamp": "2026-03-09T20:08:57.266172+0100", "flow_id": 298775417576423, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:08:57.266172+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4404,1773083337.266172886,'{"timestamp": "2026-03-09T20:08:57.266173+0100", "flow_id": 298782581106257, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:08:57.266173+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4405,1773083340.61777711,'{"timestamp": "2026-03-09T20:09:00.617777+0100", "flow_id": 1245960879162607, "event_type": "alert", "src_ip": "185.242.3.25", "src_port": 42167, "dest_ip": "134.19.55.199", "dest_port": 8089, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:09:00.617777+0100", "src_ip": "185.242.3.25", "dest_ip": "134.19.55.199", "src_port": 42167, "dest_port": 8089}}'); INSERT INTO alerts VALUES(4406,1773083343.070533038,'{"timestamp": "2026-03-09T20:09:03.070533+0100", "flow_id": 1991788563711082, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 35657, "dest_ip": "134.19.55.199", "dest_port": 37582, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:09:03.070533+0100", "src_ip": "167.94.146.45", "dest_ip": "134.19.55.199", "src_port": 35657, "dest_port": 37582}}'); INSERT INTO alerts VALUES(4407,1773083360.949039936,'{"timestamp": "2026-03-09T20:09:20.949040+0100", "flow_id": 135446566951780, "event_type": "alert", "src_ip": "91.196.152.92", "src_port": 35164, "dest_ip": "134.19.55.199", "dest_port": 55555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:09:20.949040+0100", "src_ip": "91.196.152.92", "dest_ip": "134.19.55.199", "src_port": 35164, "dest_port": 55555}}'); INSERT INTO alerts VALUES(4408,1773083367.505417109,'{"timestamp": "2026-03-09T20:09:27.505417+0100", "flow_id": 2170751425757856, "event_type": "alert", "src_ip": "167.94.138.135", "src_port": 41639, "dest_ip": "134.19.55.199", "dest_port": 8389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:09:27.505417+0100", "src_ip": "167.94.138.135", "dest_ip": "134.19.55.199", "src_port": 41639, "dest_port": 8389}}'); INSERT INTO alerts VALUES(4409,1773083367.998646975,'{"timestamp": "2026-03-09T20:09:27.998647+0100", "flow_id": 2037356704160743, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:09:27.998647+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4410,1773083367.998647928,'{"timestamp": "2026-03-09T20:09:27.998648+0100", "flow_id": 2037363867690577, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:09:27.998648+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4411,1773083372.621354103,'{"timestamp": "2026-03-09T20:09:32.621354+0100", "flow_id": 1167322115987061, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 58948, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:09:32.599468+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 58948, "dest_port": 853}}'); INSERT INTO alerts VALUES(4412,1773083383.990291119,'{"timestamp": "2026-03-09T20:09:43.990291+0100", "flow_id": 2001471375048142, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64470, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23015, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:09:43.990291+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64470, "dest_port": 53}}'); INSERT INTO alerts VALUES(4413,1773083383.990292072,'{"timestamp": "2026-03-09T20:09:43.990292+0100", "flow_id": 2001474009122933, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59171, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17775, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:09:43.990292+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59171, "dest_port": 53}}'); INSERT INTO alerts VALUES(4414,1773083404.680339098,'{"timestamp": "2026-03-09T20:10:04.680339+0100", "flow_id": 1233183900299341, "event_type": "alert", "src_ip": "193.163.125.212", "src_port": 55461, "dest_ip": "134.19.55.199", "dest_port": 6443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:10:04.680339+0100", "src_ip": "193.163.125.212", "dest_ip": "134.19.55.199", "src_port": 55461, "dest_port": 6443}}'); INSERT INTO alerts VALUES(4415,1773083444.865359068,'{"timestamp": "2026-03-09T20:10:44.865359+0100", "flow_id": 1183414126500839, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:10:44.865359+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4416,1773083444.865359068,'{"timestamp": "2026-03-09T20:10:44.865359+0100", "flow_id": 1183416995063377, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:10:44.865359+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4417,1773083476.284064054,'{"timestamp": "2026-03-09T20:11:16.284064+0100", "flow_id": 1220045902568423, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:11:16.284064+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4418,1773083476.284065009,'{"timestamp": "2026-03-09T20:11:16.284065+0100", "flow_id": 1220053066098257, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:11:16.284065+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4419,1773083482.709470987,'{"timestamp": "2026-03-09T20:11:22.709471+0100", "flow_id": 795358669617522, "event_type": "alert", "src_ip": "205.210.31.222", "src_port": 50413, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:11:22.709471+0100", "src_ip": "205.210.31.222", "dest_ip": "134.19.55.199", "src_port": 50413, "dest_port": 3000}}'); INSERT INTO alerts VALUES(4420,1773083486.30624199,'{"timestamp": "2026-03-09T20:11:26.306242+0100", "flow_id": 1878249859525588, "event_type": "alert", "src_ip": "91.196.152.108", "src_port": 19066, "dest_ip": "134.19.55.199", "dest_port": 6466, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:11:26.306242+0100", "src_ip": "91.196.152.108", "dest_ip": "134.19.55.199", "src_port": 19066, "dest_port": 6466}}'); INSERT INTO alerts VALUES(4421,1773083492.622215032,'{"timestamp": "2026-03-09T20:11:32.622215+0100", "flow_id": 1176156838933803, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 44734, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:11:32.601525+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 44734, "dest_port": 853}}'); INSERT INTO alerts VALUES(4422,1773083498.195278882,'{"timestamp": "2026-03-09T20:11:38.195279+0100", "flow_id": 838719189851646, "event_type": "alert", "src_ip": "205.210.31.43", "src_port": 49993, "dest_ip": "134.19.55.199", "dest_port": 20256, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:11:38.195279+0100", "src_ip": "205.210.31.43", "dest_ip": "134.19.55.199", "src_port": 49993, "dest_port": 20256}}'); INSERT INTO alerts VALUES(4423,1773083506.319176913,'{"timestamp": "2026-03-09T20:11:46.319177+0100", "flow_id": 807905135811559, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:11:46.319177+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4424,1773083506.319178104,'{"timestamp": "2026-03-09T20:11:46.319178+0100", "flow_id": 807912299341393, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:11:46.319178+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4425,1773083515.549313068,'{"timestamp": "2026-03-09T20:11:55.549313+0100", "flow_id": 951908137448058, "event_type": "alert", "src_ip": "147.185.132.225", "src_port": 56591, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 400, "bytes_toclient": 0, "start": "2026-03-09T20:11:55.549313+0100", "src_ip": "147.185.132.225", "dest_ip": "134.19.55.199", "src_port": 56591, "dest_port": 5060}}'); INSERT INTO alerts VALUES(4426,1773083517.692574977,'{"timestamp": "2026-03-09T20:11:57.692575+0100", "flow_id": 1567214865784039, "event_type": "alert", "src_ip": "195.184.76.228", "src_port": 2587, "dest_ip": "134.19.55.199", "dest_port": 19233, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:11:57.692575+0100", "src_ip": "195.184.76.228", "dest_ip": "134.19.55.199", "src_port": 2587, "dest_port": 19233}}'); INSERT INTO alerts VALUES(4427,1773083523.755203009,'{"timestamp": "2026-03-09T20:12:03.755203+0100", "flow_id": 991773161658203, "event_type": "alert", "src_ip": "195.184.76.236", "src_port": 13303, "dest_ip": "134.19.55.199", "dest_port": 10323, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:12:03.755203+0100", "src_ip": "195.184.76.236", "dest_ip": "134.19.55.199", "src_port": 13303, "dest_port": 10323}}'); INSERT INTO alerts VALUES(4428,1773083536.577621937,'{"timestamp": "2026-03-09T20:12:16.577622+0100", "flow_id": 229068098362343, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:12:16.577622+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4429,1773083536.57762289,'{"timestamp": "2026-03-09T20:12:16.577623+0100", "flow_id": 229075261892177, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:12:16.577623+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4430,1773083539.201802969,'{"timestamp": "2026-03-09T20:12:19.201803+0100", "flow_id": 866738598541718, "event_type": "alert", "src_ip": "195.184.76.108", "src_port": 34309, "dest_ip": "134.19.55.199", "dest_port": 10002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:12:19.201803+0100", "src_ip": "195.184.76.108", "dest_ip": "134.19.55.199", "src_port": 34309, "dest_port": 10002}}'); INSERT INTO alerts VALUES(4431,1773083539.85404706,'{"timestamp": "2026-03-09T20:12:19.854047+0100", "flow_id": 853356438960788, "event_type": "alert", "src_ip": "195.184.76.124", "src_port": 51024, "dest_ip": "134.19.55.199", "dest_port": 2000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:12:19.854047+0100", "src_ip": "195.184.76.124", "dest_ip": "134.19.55.199", "src_port": 51024, "dest_port": 2000}}'); INSERT INTO alerts VALUES(4432,1773083546.678889036,'{"timestamp": "2026-03-09T20:12:26.678889+0100", "flow_id": 664007832962775, "event_type": "alert", "src_ip": "193.163.125.182", "src_port": 54516, "dest_ip": "134.19.55.199", "dest_port": 40005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:12:26.678889+0100", "src_ip": "193.163.125.182", "dest_ip": "134.19.55.199", "src_port": 54516, "dest_port": 40005}}'); INSERT INTO alerts VALUES(4433,1773083546.895813941,'{"timestamp": "2026-03-09T20:12:26.895814+0100", "flow_id": 751267145337293, "event_type": "alert", "src_ip": "147.185.132.130", "src_port": 51683, "dest_ip": "134.19.55.199", "dest_port": 19282, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:12:26.895814+0100", "src_ip": "147.185.132.130", "dest_ip": "134.19.55.199", "src_port": 51683, "dest_port": 19282}}'); INSERT INTO alerts VALUES(4434,1773083550.286364079,'{"timestamp": "2026-03-09T20:12:30.286364+0100", "flow_id": 1792878031503587, "event_type": "alert", "src_ip": "91.196.152.100", "src_port": 13150, "dest_ip": "134.19.55.199", "dest_port": 58000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:12:30.286364+0100", "src_ip": "91.196.152.100", "dest_ip": "134.19.55.199", "src_port": 13150, "dest_port": 58000}}'); INSERT INTO alerts VALUES(4435,1773083563.490919114,'{"timestamp": "2026-03-09T20:12:43.490919+0100", "flow_id": 982584759828919, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63909, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1092, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:12:43.490919+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63909, "dest_port": 53}}'); INSERT INTO alerts VALUES(4436,1773083567.811208009,'{"timestamp": "2026-03-09T20:12:47.811208+0100", "flow_id": 2076737259297767, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:12:47.811208+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4437,1773083567.811208009,'{"timestamp": "2026-03-09T20:12:47.811208+0100", "flow_id": 2076740127860305, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:12:47.811208+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4438,1773083573.239780902,'{"timestamp": "2026-03-09T20:12:53.239781+0100", "flow_id": 1592805702808752, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57090, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46791, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:12:53.239781+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57090, "dest_port": 53}}'); INSERT INTO alerts VALUES(4439,1773083592.358859062,'{"timestamp": "2026-03-09T20:13:12.358859+0100", "flow_id": 133913288590734, "event_type": "alert", "src_ip": "205.210.31.183", "src_port": 56155, "dest_ip": "134.19.55.199", "dest_port": 2379, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:13:12.358859+0100", "src_ip": "205.210.31.183", "dest_ip": "134.19.55.199", "src_port": 56155, "dest_port": 2379}}'); INSERT INTO alerts VALUES(4440,1773083598.713057041,'{"timestamp": "2026-03-09T20:13:18.713057+0100", "flow_id": 1936656900938727, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:13:18.713057+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4441,1773083598.713057041,'{"timestamp": "2026-03-09T20:13:18.713057+0100", "flow_id": 1936659769501265, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:13:18.713057+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4442,1773083611.542026042,'{"timestamp": "2026-03-09T20:13:31.542026+0100", "flow_id": 920611318159125, "event_type": "alert", "src_ip": "45.156.87.91", "src_port": 60322, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:13:31.542026+0100", "src_ip": "45.156.87.91", "dest_ip": "134.19.55.199", "src_port": 60322, "dest_port": 8080}}'); INSERT INTO alerts VALUES(4443,1773083612.626451969,'{"timestamp": "2026-03-09T20:13:32.626452+0100", "flow_id": 1193687783730365, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 59826, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:13:32.605607+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 59826, "dest_port": 853}}'); INSERT INTO alerts VALUES(4444,1773083613.673820018,'{"timestamp": "2026-03-09T20:13:33.673820+0100", "flow_id": 1486661956505587, "event_type": "alert", "src_ip": "45.153.34.187", "src_port": 40327, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:13:33.673820+0100", "src_ip": "45.153.34.187", "dest_ip": "134.19.55.199", "src_port": 40327, "dest_port": 80}}'); INSERT INTO alerts VALUES(4445,1773083629.510103941,'{"timestamp": "2026-03-09T20:13:49.510104+0100", "flow_id": 1627930356734951, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:13:49.510104+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4446,1773083629.510103941,'{"timestamp": "2026-03-09T20:13:49.510104+0100", "flow_id": 1627933225297489, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:13:49.510104+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4447,1773083636.782938004,'{"timestamp": "2026-03-09T20:13:56.782938+0100", "flow_id": 1392368296111760, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64871, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2039594, "rev": 1, "signature": "ET INFO External IP Address Lookup Domain (get .geojs .io) in DNS Lookup", "category": "Device Retrieving External IP Address Detected", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2022_10_28"], "deployment": ["Perimeter"], "performance_impact": ["Low"], "reviewed_at": ["2025_04_17"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_10_28"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53495, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "get.geojs.io", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-09T20:13:56.782938+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64871, "dest_port": 53}}'); INSERT INTO alerts VALUES(4448,1773083636.784657955,'{"timestamp": "2026-03-09T20:13:56.784658+0100", "flow_id": 1399756539377863, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49964, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2039594, "rev": 1, "signature": "ET INFO External IP Address Lookup Domain (get .geojs .io) in DNS Lookup", "category": "Device Retrieving External IP Address Detected", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2022_10_28"], "deployment": ["Perimeter"], "performance_impact": ["Low"], "reviewed_at": ["2025_04_17"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_10_28"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44700, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "get.geojs.io", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-09T20:13:56.784658+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49964, "dest_port": 53}}'); INSERT INTO alerts VALUES(4449,1773083636.796967983,'{"timestamp": "2026-03-09T20:13:56.796968+0100", "flow_id": 1171154507224016, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52756, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33373, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:13:56.796968+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52756, "dest_port": 53}}'); INSERT INTO alerts VALUES(4450,1773083636.799489975,'{"timestamp": "2026-03-09T20:13:56.799490+0100", "flow_id": 1181986707763064, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61047, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37371, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:13:56.799490+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61047, "dest_port": 53}}'); INSERT INTO alerts VALUES(4451,1773083639.009538888,'{"timestamp": "2026-03-09T20:13:59.009539+0100", "flow_id": 2011297253084144, "event_type": "alert", "src_ip": "91.196.152.116", "src_port": 14034, "dest_ip": "134.19.55.199", "dest_port": 50805, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:13:59.009539+0100", "src_ip": "91.196.152.116", "dest_ip": "134.19.55.199", "src_port": 14034, "dest_port": 50805}}'); INSERT INTO alerts VALUES(4452,1773083651.109824895,'{"timestamp": "2026-03-09T20:14:11.109825+0100", "flow_id": 1034646806022261, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59171, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17775, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:14:11.109825+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59171, "dest_port": 53}}'); INSERT INTO alerts VALUES(4453,1773083651.109824895,'{"timestamp": "2026-03-09T20:14:11.109825+0100", "flow_id": 1034647687573777, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57989, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2928, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:14:11.109825+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57989, "dest_port": 53}}'); INSERT INTO alerts VALUES(4454,1773083651.275247098,'{"timestamp": "2026-03-09T20:14:11.275247+0100", "flow_id": 900704860927121, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63577, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1422, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:14:11.275247+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63577, "dest_port": 53}}'); INSERT INTO alerts VALUES(4455,1773083660.298110962,'{"timestamp": "2026-03-09T20:14:20.298111+0100", "flow_id": 1280377308175335, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:14:20.298111+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4456,1773083660.298110962,'{"timestamp": "2026-03-09T20:14:20.298111+0100", "flow_id": 1280380176737873, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:14:20.298111+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4457,1773083685.554321051,'{"timestamp": "2026-03-09T20:14:45.554321+0100", "flow_id": 1536366999632755, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50654, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2039594, "rev": 1, "signature": "ET INFO External IP Address Lookup Domain (get .geojs .io) in DNS Lookup", "category": "Device Retrieving External IP Address Detected", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2022_10_28"], "deployment": ["Perimeter"], "performance_impact": ["Low"], "reviewed_at": ["2025_04_17"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_10_28"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5006, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "get.geojs.io", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-09T20:14:45.554321+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50654, "dest_port": 53}}'); INSERT INTO alerts VALUES(4458,1773083685.5546,'{"timestamp": "2026-03-09T20:14:45.554600+0100", "flow_id": 1537567954190080, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53035, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2039594, "rev": 1, "signature": "ET INFO External IP Address Lookup Domain (get .geojs .io) in DNS Lookup", "category": "Device Retrieving External IP Address Detected", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2022_10_28"], "deployment": ["Perimeter"], "performance_impact": ["Low"], "reviewed_at": ["2025_04_17"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_10_28"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "get.geojs.io", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-09T20:14:45.554600+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53035, "dest_port": 53}}'); INSERT INTO alerts VALUES(4459,1773083686.952212095,'{"timestamp": "2026-03-09T20:14:46.952212+0100", "flow_id": 1837920798549683, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49460, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2063117, "rev": 1, "signature": "ET INFO Abused Hosting Domain in DNS Lookup (azurewebsites .net)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_and_Server"], "confidence": ["Medium"], "created_at": ["2025_06_20"], "deployment": ["Perimeter"], "mitre_tactic_id": ["TA0011"], "mitre_tactic_name": ["Command_And_Control"], "mitre_technique_id": ["T1102"], "mitre_technique_name": ["Web_Service"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "updated_at": ["2025_06_20"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61915, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "msha-slice-4-am2-0.msha-slice-4-am2-0-ase.p.azurewebsites.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 107, "bytes_toclient": 0, "start": "2026-03-09T20:14:46.952212+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49460, "dest_port": 53}}'); INSERT INTO alerts VALUES(4460,1773083686.953346968,'{"timestamp": "2026-03-09T20:14:46.953347+0100", "flow_id": 1842798014660984, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49245, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2063117, "rev": 1, "signature": "ET INFO Abused Hosting Domain in DNS Lookup (azurewebsites .net)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_and_Server"], "confidence": ["Medium"], "created_at": ["2025_06_20"], "deployment": ["Perimeter"], "mitre_tactic_id": ["TA0011"], "mitre_tactic_name": ["Command_And_Control"], "mitre_technique_id": ["T1102"], "mitre_technique_name": ["Web_Service"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "updated_at": ["2025_06_20"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6890, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "msha-slice-4-am2-0.msha-slice-4-am2-0-ase.p.azurewebsites.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 107, "bytes_toclient": 0, "start": "2026-03-09T20:14:46.953347+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49245, "dest_port": 53}}'); INSERT INTO alerts VALUES(4461,1773083689.805967093,'{"timestamp": "2026-03-09T20:14:49.805967+0100", "flow_id": 365379687242255, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58351, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8071, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T20:14:49.805967+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58351, "dest_port": 53}}'); INSERT INTO alerts VALUES(4462,1773083691.703840017,'{"timestamp": "2026-03-09T20:14:51.703840+0100", "flow_id": 1052645257239527, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:14:51.703840+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4463,1773083691.703840017,'{"timestamp": "2026-03-09T20:14:51.703840+0100", "flow_id": 1052648125802065, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:14:51.703840+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4464,1773083706.517754078,'{"timestamp": "2026-03-09T20:15:06.517754+0100", "flow_id": 816361814356638, "event_type": "alert", "src_ip": "147.185.132.29", "src_port": 54003, "dest_ip": "134.19.55.199", "dest_port": 63846, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:15:06.517754+0100", "src_ip": "147.185.132.29", "dest_ip": "134.19.55.199", "src_port": 54003, "dest_port": 63846}}'); INSERT INTO alerts VALUES(4465,1773083719.264153004,'{"timestamp": "2026-03-09T20:15:19.264153+0100", "flow_id": 1978956295438472, "event_type": "alert", "src_ip": "176.65.132.93", "src_port": 43643, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:15:19.264153+0100", "src_ip": "176.65.132.93", "dest_ip": "134.19.55.199", "src_port": 43643, "dest_port": 27017}}'); INSERT INTO alerts VALUES(4466,1773083723.185323954,'{"timestamp": "2026-03-09T20:15:23.185324+0100", "flow_id": 1077435808472039, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:15:23.185324+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4467,1773083723.186136008,'{"timestamp": "2026-03-09T20:15:23.186136+0100", "flow_id": 1080926190478929, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:15:23.186136+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4468,1773083732.630430937,'{"timestamp": "2026-03-09T20:15:32.630431+0100", "flow_id": 1213444698200815, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 36260, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:15:32.610207+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 36260, "dest_port": 853}}'); INSERT INTO alerts VALUES(4469,1773083733.389329911,'{"timestamp": "2026-03-09T20:15:33.389330+0100", "flow_id": 1672160882686723, "event_type": "alert", "src_ip": "45.156.87.70", "src_port": 58589, "dest_ip": "134.19.55.199", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:15:33.389330+0100", "src_ip": "45.156.87.70", "dest_ip": "134.19.55.199", "src_port": 58589, "dest_port": 443}}'); INSERT INTO alerts VALUES(4470,1773083741.836301088,'{"timestamp": "2026-03-09T20:15:41.836301+0100", "flow_id": 1621562412282177, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58788, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2026888, "rev": 4, "signature": "ET INFO DNS Query for Suspicious .icu Domain", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["Medium"], "created_at": ["2019_02_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_11_21"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39494, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "prreqcroab.icu", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:15:41.836301+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58788, "dest_port": 53}}'); INSERT INTO alerts VALUES(4471,1773083753.415030957,'{"timestamp": "2026-03-09T20:15:53.415031+0100", "flow_id": 375170000870375, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:15:53.415031+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4472,1773083753.415030957,'{"timestamp": "2026-03-09T20:15:53.415031+0100", "flow_id": 375172869432913, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:15:53.415031+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4473,1773083778.820581912,'{"timestamp": "2026-03-09T20:16:18.820582+0100", "flow_id": 709623359444639, "event_type": "alert", "src_ip": "205.210.31.102", "src_port": 55461, "dest_ip": "134.19.55.199", "dest_port": 1028, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:16:18.820582+0100", "src_ip": "205.210.31.102", "dest_ip": "134.19.55.199", "src_port": 55461, "dest_port": 1028}}'); INSERT INTO alerts VALUES(4474,1773083784.642956973,'{"timestamp": "2026-03-09T20:16:24.642957+0100", "flow_id": 228204809935847, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:16:24.642957+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4475,1773083784.642957925,'{"timestamp": "2026-03-09T20:16:24.642958+0100", "flow_id": 228211973465681, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:16:24.642958+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4476,1773083818.356601953,'{"timestamp": "2026-03-09T20:16:58.356602+0100", "flow_id": 687172388339318, "event_type": "alert", "src_ip": "193.163.125.194", "src_port": 46878, "dest_ip": "134.19.55.199", "dest_port": 6046, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:16:58.356602+0100", "src_ip": "193.163.125.194", "dest_ip": "134.19.55.199", "src_port": 46878, "dest_port": 6046}}'); INSERT INTO alerts VALUES(4477,1773083852.635642052,'{"timestamp": "2026-03-09T20:17:32.635642+0100", "flow_id": 1232480224394227, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 43096, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:17:32.614639+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 43096, "dest_port": 853}}'); INSERT INTO alerts VALUES(4478,1773083867.866269112,'{"timestamp": "2026-03-09T20:17:47.866269+0100", "flow_id": 905847570029543, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:17:47.866269+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4479,1773083867.866270065,'{"timestamp": "2026-03-09T20:17:47.866270+0100", "flow_id": 905854733559377, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:17:47.866270+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4480,1773083899.363671064,'{"timestamp": "2026-03-09T20:18:19.363671+0100", "flow_id": 999005410679783, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:18:19.363671+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4481,1773083899.363671064,'{"timestamp": "2026-03-09T20:18:19.363671+0100", "flow_id": 999008279242321, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:18:19.363671+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4482,1773083901.575287103,'{"timestamp": "2026-03-09T20:18:21.575287+0100", "flow_id": 1626414522326191, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53259, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42507, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:18:21.575287+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53259, "dest_port": 53}}'); INSERT INTO alerts VALUES(4483,1773083901.577289105,'{"timestamp": "2026-03-09T20:18:21.577289+0100", "flow_id": 1635016205242945, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53294, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14885, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:18:21.577289+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53294, "dest_port": 53}}'); INSERT INTO alerts VALUES(4484,1773083907.472096921,'{"timestamp": "2026-03-09T20:18:27.472097+0100", "flow_id": 901741501457392, "event_type": "alert", "src_ip": "147.185.132.49", "src_port": 37769, "dest_ip": "134.19.55.199", "dest_port": 13646, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T20:18:27.472097+0100", "src_ip": "147.185.132.49", "dest_ip": "134.19.55.199", "src_port": 37769, "dest_port": 13646}}'); INSERT INTO alerts VALUES(4485,1773083930.028966904,'{"timestamp": "2026-03-09T20:18:50.028967+0100", "flow_id": 687362583682023, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:18:50.028967+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4486,1773083930.028968096,'{"timestamp": "2026-03-09T20:18:50.028968+0100", "flow_id": 687369747211857, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:18:50.028968+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4487,1773083961.495214939,'{"timestamp": "2026-03-09T20:19:21.495215+0100", "flow_id": 438082681822183, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:19:21.495215+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4488,1773083961.495214939,'{"timestamp": "2026-03-09T20:19:21.495215+0100", "flow_id": 438085550384721, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:19:21.495215+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4489,1773083972.639770984,'{"timestamp": "2026-03-09T20:19:32.639771+0100", "flow_id": 1251759318031815, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 38268, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:19:32.619127+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 38268, "dest_port": 853}}'); INSERT INTO alerts VALUES(4490,1773083992.506232977,'{"timestamp": "2026-03-09T20:19:52.506233+0100", "flow_id": 203929654778855, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:19:52.506233+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4491,1773083992.50623393,'{"timestamp": "2026-03-09T20:19:52.506234+0100", "flow_id": 203936818308689, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:19:52.506234+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4492,1773084001.735110998,'{"timestamp": "2026-03-09T20:20:01.735111+0100", "flow_id": 342531316266524, "event_type": "alert", "src_ip": "167.94.138.103", "src_port": 14764, "dest_ip": "134.19.55.199", "dest_port": 36399, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:20:01.735111+0100", "src_ip": "167.94.138.103", "dest_ip": "134.19.55.199", "src_port": 14764, "dest_port": 36399}}'); INSERT INTO alerts VALUES(4493,1773084023.649355888,'{"timestamp": "2026-03-09T20:20:23.649356+0100", "flow_id": 2226013142637543, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:20:23.649356+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4494,1773084023.649355888,'{"timestamp": "2026-03-09T20:20:23.649356+0100", "flow_id": 2226016011200081, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:20:23.649356+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4495,1773084054.895618915,'{"timestamp": "2026-03-09T20:20:54.895619+0100", "flow_id": 1876329790299111, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:20:54.895619+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4496,1773084054.895618915,'{"timestamp": "2026-03-09T20:20:54.895619+0100", "flow_id": 1876332658861649, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:20:54.895619+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4497,1773084069.777606964,'{"timestamp": "2026-03-09T20:21:09.777607+0100", "flow_id": 1650949537726066, "event_type": "alert", "src_ip": "167.94.138.110", "src_port": 39370, "dest_ip": "134.19.55.199", "dest_port": 27275, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:21:09.777607+0100", "src_ip": "167.94.138.110", "dest_ip": "134.19.55.199", "src_port": 39370, "dest_port": 27275}}'); INSERT INTO alerts VALUES(4498,1773084076.913470029,'{"timestamp": "2026-03-09T20:21:16.913470+0100", "flow_id": 1390049344730545, "event_type": "alert", "src_ip": "167.94.138.145", "src_port": 47883, "dest_ip": "134.19.55.199", "dest_port": 8880, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:21:16.913470+0100", "src_ip": "167.94.138.145", "dest_ip": "134.19.55.199", "src_port": 47883, "dest_port": 8880}}'); INSERT INTO alerts VALUES(4499,1773084079.432677984,'{"timestamp": "2026-03-09T20:21:19.432678+0100", "flow_id": 2139815772361845, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4677, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T20:21:19.432678+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65064, "dest_port": 53}}'); INSERT INTO alerts VALUES(4500,1773084085.176207066,'{"timestamp": "2026-03-09T20:21:25.176207+0100", "flow_id": 1601228545055719, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:21:25.176207+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4501,1773084085.17620802,'{"timestamp": "2026-03-09T20:21:25.176208+0100", "flow_id": 1601235708585553, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:21:25.176208+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4502,1773084086.273509026,'{"timestamp": "2026-03-09T20:21:26.273509+0100", "flow_id": 1737663126738056, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52009, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54979, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:21:26.273509+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52009, "dest_port": 53}}'); INSERT INTO alerts VALUES(4503,1773084092.643789053,'{"timestamp": "2026-03-09T20:21:32.643789+0100", "flow_id": 1263296285451790, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 58020, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:21:32.621814+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 58020, "dest_port": 853}}'); INSERT INTO alerts VALUES(4504,1773084104.025613069,'{"timestamp": "2026-03-09T20:21:44.025613+0100", "flow_id": 110008708911732, "event_type": "alert", "src_ip": "147.185.132.99", "src_port": 50346, "dest_ip": "134.19.55.199", "dest_port": 10004, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:21:44.025613+0100", "src_ip": "147.185.132.99", "dest_ip": "134.19.55.199", "src_port": 50346, "dest_port": 10004}}'); INSERT INTO alerts VALUES(4505,1773084120.072602987,'{"timestamp": "2026-03-09T20:22:00.072603+0100", "flow_id": 30355019652121, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 11377, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:22:00.072603+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 11377}}'); INSERT INTO alerts VALUES(4506,1773084139.280019998,'{"timestamp": "2026-03-09T20:22:19.280020+0100", "flow_id": 921202653128141, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55975, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15986, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:22:19.280020+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55975, "dest_port": 53}}'); INSERT INTO alerts VALUES(4507,1773084139.280287982,'{"timestamp": "2026-03-09T20:22:19.280288+0100", "flow_id": 922352886209092, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56287, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27750, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:22:19.280288+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56287, "dest_port": 53}}'); INSERT INTO alerts VALUES(4508,1773084148.779443025,'{"timestamp": "2026-03-09T20:22:28.779443+0100", "flow_id": 1377359568528611, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 44119, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:22:28.779443+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 44119, "dest_port": 3306}}'); INSERT INTO alerts VALUES(4509,1773084150.486493111,'{"timestamp": "2026-03-09T20:22:30.486493+0100", "flow_id": 1807996860619751, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:22:30.486493+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4510,1773084150.486493111,'{"timestamp": "2026-03-09T20:22:30.486493+0100", "flow_id": 1807999729182289, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:22:30.486493+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4511,1773084181.625746011,'{"timestamp": "2026-03-09T20:23:01.625746+0100", "flow_id": 1561659011357671, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:23:01.625746+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4512,1773084181.625746965,'{"timestamp": "2026-03-09T20:23:01.625747+0100", "flow_id": 1561666174887505, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:23:01.625747+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4513,1773084187.613681078,'{"timestamp": "2026-03-09T20:23:07.613681+0100", "flow_id": 946892121167895, "event_type": "alert", "src_ip": "185.156.73.182", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:23:07.613681+0100", "src_ip": "185.156.73.182", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 888}}'); INSERT INTO alerts VALUES(4514,1773084211.647684097,'{"timestamp": "2026-03-09T20:23:31.647684+0100", "flow_id": 1092932050476007, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:23:31.647684+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4515,1773084211.647684097,'{"timestamp": "2026-03-09T20:23:31.647684+0100", "flow_id": 1092934919038545, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:23:31.647684+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4516,1773084212.648181916,'{"timestamp": "2026-03-09T20:23:32.648182+0100", "flow_id": 1285366209510810, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 47042, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:23:32.626952+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 47042, "dest_port": 853}}'); INSERT INTO alerts VALUES(4517,1773084240.095369101,'{"timestamp": "2026-03-09T20:24:00.095369+0100", "flow_id": 128135886252403, "event_type": "alert", "src_ip": "176.65.148.66", "src_port": 50381, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:24:00.095369+0100", "src_ip": "176.65.148.66", "dest_ip": "134.19.55.199", "src_port": 50381, "dest_port": 3000}}'); INSERT INTO alerts VALUES(4518,1773084240.095369101,'{"timestamp": "2026-03-09T20:24:00.095369+0100", "flow_id": 128135886252403, "event_type": "alert", "src_ip": "176.65.148.66", "src_port": 50381, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:24:00.095369+0100", "src_ip": "176.65.148.66", "dest_ip": "134.19.55.199", "src_port": 50381, "dest_port": 3000}}'); INSERT INTO alerts VALUES(4519,1773084242.025904894,'{"timestamp": "2026-03-09T20:24:02.025905+0100", "flow_id": 674211393821671, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:24:02.025905+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4520,1773084242.025904894,'{"timestamp": "2026-03-09T20:24:02.025905+0100", "flow_id": 674214262384209, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:24:02.025905+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4521,1773084265.242892027,'{"timestamp": "2026-03-09T20:24:25.242892+0100", "flow_id": 480266217354385, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63577, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1422, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:24:25.242892+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63577, "dest_port": 53}}'); INSERT INTO alerts VALUES(4522,1773084265.243240119,'{"timestamp": "2026-03-09T20:24:25.243240+0100", "flow_id": 481760842526993, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57989, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2928, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:24:25.243240+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57989, "dest_port": 53}}'); INSERT INTO alerts VALUES(4523,1773084265.243240119,'{"timestamp": "2026-03-09T20:24:25.243240+0100", "flow_id": 481759745125561, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52426, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58297, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:24:25.243240+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52426, "dest_port": 53}}'); INSERT INTO alerts VALUES(4524,1773084265.243240119,'{"timestamp": "2026-03-09T20:24:25.243240+0100", "flow_id": 481760195992845, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53251, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45623, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:24:25.243240+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53251, "dest_port": 53}}'); INSERT INTO alerts VALUES(4525,1773084273.064876079,'{"timestamp": "2026-03-09T20:24:33.064876+0100", "flow_id": 560115587603431, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:24:33.064876+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4526,1773084273.064876079,'{"timestamp": "2026-03-09T20:24:33.064876+0100", "flow_id": 560118456165969, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:24:33.064876+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4527,1773084290.365717887,'{"timestamp": "2026-03-09T20:24:50.365718+0100", "flow_id": 726322521070767, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53259, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42507, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:24:50.365718+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53259, "dest_port": 53}}'); INSERT INTO alerts VALUES(4528,1773084290.365717887,'{"timestamp": "2026-03-09T20:24:50.365718+0100", "flow_id": 726325679460929, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53294, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14885, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:24:50.365718+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53294, "dest_port": 53}}'); INSERT INTO alerts VALUES(4529,1773084290.365719079,'{"timestamp": "2026-03-09T20:24:50.365719+0100", "flow_id": 726330127001979, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50230, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16148, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:24:50.365719+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50230, "dest_port": 53}}'); INSERT INTO alerts VALUES(4530,1773084290.365719079,'{"timestamp": "2026-03-09T20:24:50.365719+0100", "flow_id": 726328418301285, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64541, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25548, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:24:50.365719+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64541, "dest_port": 53}}'); INSERT INTO alerts VALUES(4531,1773084303.784173966,'{"timestamp": "2026-03-09T20:25:03.784174+0100", "flow_id": 2242102090128359, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:25:03.784174+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4532,1773084303.784173966,'{"timestamp": "2026-03-09T20:25:03.784174+0100", "flow_id": 2242104958690897, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:25:03.784174+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4533,1773084314.039037943,'{"timestamp": "2026-03-09T20:25:14.039038+0100", "flow_id": 730617744462277, "event_type": "alert", "src_ip": "198.235.24.118", "src_port": 51889, "dest_ip": "134.19.55.199", "dest_port": 5800, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:25:14.039038+0100", "src_ip": "198.235.24.118", "dest_ip": "134.19.55.199", "src_port": 51889, "dest_port": 5800}}'); INSERT INTO alerts VALUES(4534,1773084332.653413058,'{"timestamp": "2026-03-09T20:25:32.653413+0100", "flow_id": 1302081095467389, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 52732, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:25:32.630844+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 52732, "dest_port": 853}}'); INSERT INTO alerts VALUES(4535,1773084334.762670041,'{"timestamp": "2026-03-09T20:25:34.762670+0100", "flow_id": 1868268136684519, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:25:34.762670+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4536,1773084334.762670041,'{"timestamp": "2026-03-09T20:25:34.762670+0100", "flow_id": 1868271005247057, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:25:34.762670+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4537,1773084334.893599033,'{"timestamp": "2026-03-09T20:25:34.893599+0100", "flow_id": 1867656170239385, "event_type": "alert", "src_ip": "195.184.76.219", "src_port": 57251, "dest_ip": "134.19.55.199", "dest_port": 5401, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:25:34.893599+0100", "src_ip": "195.184.76.219", "dest_ip": "134.19.55.199", "src_port": 57251, "dest_port": 5401}}'); INSERT INTO alerts VALUES(4538,1773084365.627546073,'{"timestamp": "2026-03-09T20:26:05.627546+0100", "flow_id": 1569389952490471, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:26:05.627546+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4539,1773084365.627547026,'{"timestamp": "2026-03-09T20:26:05.627547+0100", "flow_id": 1569397116020305, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:26:05.627547+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4540,1773084365.986475945,'{"timestamp": "2026-03-09T20:26:05.986476+0100", "flow_id": 1422134202411673, "event_type": "alert", "src_ip": "167.94.138.107", "src_port": 29512, "dest_ip": "134.19.55.199", "dest_port": 30714, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:26:05.986476+0100", "src_ip": "167.94.138.107", "dest_ip": "134.19.55.199", "src_port": 29512, "dest_port": 30714}}'); INSERT INTO alerts VALUES(4541,1773084378.967792987,'{"timestamp": "2026-03-09T20:26:18.967793+0100", "flow_id": 778940268316247, "event_type": "alert", "src_ip": "198.235.24.115", "src_port": 50170, "dest_ip": "134.19.55.199", "dest_port": 110, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:26:18.967793+0100", "src_ip": "198.235.24.115", "dest_ip": "134.19.55.199", "src_port": 50170, "dest_port": 110}}'); INSERT INTO alerts VALUES(4542,1773084396.615132094,'{"timestamp": "2026-03-09T20:26:36.615132+0100", "flow_id": 1234597251767271, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:26:36.615132+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4543,1773084396.615132094,'{"timestamp": "2026-03-09T20:26:36.615132+0100", "flow_id": 1234600120329809, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:26:36.615132+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4544,1773084412.43541789,'{"timestamp": "2026-03-09T20:26:52.435418+0100", "flow_id": 1307156346172920, "event_type": "alert", "src_ip": "204.76.203.30", "src_port": 58955, "dest_ip": "134.19.55.199", "dest_port": 3128, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:26:52.435418+0100", "src_ip": "204.76.203.30", "dest_ip": "134.19.55.199", "src_port": 58955, "dest_port": 3128}}'); INSERT INTO alerts VALUES(4545,1773084412.43541789,'{"timestamp": "2026-03-09T20:26:52.435418+0100", "flow_id": 1307156346172920, "event_type": "alert", "src_ip": "204.76.203.30", "src_port": 58955, "dest_ip": "134.19.55.199", "dest_port": 3128, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:26:52.435418+0100", "src_ip": "204.76.203.30", "dest_ip": "134.19.55.199", "src_port": 58955, "dest_port": 3128}}'); INSERT INTO alerts VALUES(4546,1773084416.302979946,'{"timestamp": "2026-03-09T20:26:56.302980+0100", "flow_id": 175391089144129, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58788, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2026888, "rev": 4, "signature": "ET INFO DNS Query for Suspicious .icu Domain", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["Medium"], "created_at": ["2019_02_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_11_21"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39494, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "prreqcroab.icu", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:26:56.302980+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58788, "dest_port": 53}}'); INSERT INTO alerts VALUES(4547,1773084417.597989083,'{"timestamp": "2026-03-09T20:26:57.597989+0100", "flow_id": 316546486969319, "event_type": "alert", "src_ip": "198.235.24.124", "src_port": 49763, "dest_ip": "134.19.55.199", "dest_port": 8880, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:26:57.597989+0100", "src_ip": "198.235.24.124", "dest_ip": "134.19.55.199", "src_port": 49763, "dest_port": 8880}}'); INSERT INTO alerts VALUES(4548,1773084426.795583964,'{"timestamp": "2026-03-09T20:27:06.795584+0100", "flow_id": 602257806711783, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:27:06.795584+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4549,1773084426.795583964,'{"timestamp": "2026-03-09T20:27:06.795584+0100", "flow_id": 602260675274321, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:27:06.795584+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4550,1773084452.262042999,'{"timestamp": "2026-03-09T20:27:32.262043+0100", "flow_id": 1406945059024461, "event_type": "alert", "src_ip": "185.242.226.95", "src_port": 50635, "dest_ip": "134.19.55.199", "dest_port": 8503, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:27:32.262043+0100", "src_ip": "185.242.226.95", "dest_ip": "134.19.55.199", "src_port": 50635, "dest_port": 8503}}'); INSERT INTO alerts VALUES(4551,1773084457.045456887,'{"timestamp": "2026-03-09T20:27:37.045457+0100", "flow_id": 476711617682407, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:27:37.045457+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4552,1773084457.045456887,'{"timestamp": "2026-03-09T20:27:37.045457+0100", "flow_id": 476714486244945, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:27:37.045457+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4553,1773084466.434617043,'{"timestamp": "2026-03-09T20:27:46.434617+0100", "flow_id": 740766819364973, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 47855, "dest_ip": "134.19.55.199", "dest_port": 3495, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:27:46.434617+0100", "src_ip": "45.142.193.7", "dest_ip": "134.19.55.199", "src_port": 47855, "dest_port": 3495}}'); INSERT INTO alerts VALUES(4554,1773084469.445413113,'{"timestamp": "2026-03-09T20:27:49.445413+0100", "flow_id": 1631560052824888, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 56878, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:27:49.445413+0100", "src_ip": "79.124.40.82", "dest_ip": "134.19.55.199", "src_port": 56878, "dest_port": 5060}}'); INSERT INTO alerts VALUES(4555,1773084477.192370892,'{"timestamp": "2026-03-09T20:27:57.192371+0100", "flow_id": 1670655990471982, "event_type": "alert", "src_ip": "88.210.63.69", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 44437, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:27:57.192371+0100", "src_ip": "88.210.63.69", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 44437}}'); INSERT INTO alerts VALUES(4556,1773084488.302180052,'{"timestamp": "2026-03-09T20:28:08.302180+0100", "flow_id": 171953623260135, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:28:08.302180+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4557,1773084488.302181006,'{"timestamp": "2026-03-09T20:28:08.302181+0100", "flow_id": 171960786789969, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:28:08.302181+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4558,1773084494.292685032,'{"timestamp": "2026-03-09T20:28:14.292685+0100", "flow_id": 1820026079001178, "event_type": "alert", "src_ip": "198.235.24.100", "src_port": 52607, "dest_ip": "134.19.55.199", "dest_port": 3333, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:28:14.292685+0100", "src_ip": "198.235.24.100", "dest_ip": "134.19.55.199", "src_port": 52607, "dest_port": 3333}}'); INSERT INTO alerts VALUES(4559,1773084519.587254047,'{"timestamp": "2026-03-09T20:28:39.587254+0100", "flow_id": 2240762060332007, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:28:39.587254+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4560,1773084519.587254047,'{"timestamp": "2026-03-09T20:28:39.587254+0100", "flow_id": 2240764928894545, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:28:39.587254+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4561,1773084549.641119003,'{"timestamp": "2026-03-09T20:29:09.641119+0100", "flow_id": 1627685543599079, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:29:09.641119+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4562,1773084549.641119957,'{"timestamp": "2026-03-09T20:29:09.641120+0100", "flow_id": 1627692707128913, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:29:09.641120+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4563,1773084557.317351103,'{"timestamp": "2026-03-09T20:29:17.317351+0100", "flow_id": 1644489575858469, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57256, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37991, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:29:17.317351+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57256, "dest_port": 53}}'); INSERT INTO alerts VALUES(4564,1773084557.317811966,'{"timestamp": "2026-03-09T20:29:17.317812+0100", "flow_id": 1646470229732669, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54162, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40659, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:29:17.317812+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54162, "dest_port": 53}}'); INSERT INTO alerts VALUES(4565,1773084574.0262599,'{"timestamp": "2026-03-09T20:29:34.026260+0100", "flow_id": 1801637623115124, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 46739, "dest_ip": "134.19.55.199", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T20:29:34.026260+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 46739, "dest_port": 8332}}'); INSERT INTO alerts VALUES(4566,1773084574.0262599,'{"timestamp": "2026-03-09T20:29:34.026260+0100", "flow_id": 1801637623115124, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 46739, "dest_ip": "134.19.55.199", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T20:29:34.026260+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 46739, "dest_port": 8332}}'); INSERT INTO alerts VALUES(4567,1773084581.042484045,'{"timestamp": "2026-03-09T20:29:41.042484+0100", "flow_id": 1589842586754023, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:29:41.042484+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4568,1773084581.042484998,'{"timestamp": "2026-03-09T20:29:41.042485+0100", "flow_id": 1589849750283857, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:29:41.042485+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4569,1773084593.47914505,'{"timestamp": "2026-03-09T20:29:53.479145+0100", "flow_id": 369064098245817, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52426, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58297, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:29:53.479145+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52426, "dest_port": 53}}'); INSERT INTO alerts VALUES(4570,1773084593.47914505,'{"timestamp": "2026-03-09T20:29:53.479145+0100", "flow_id": 369064549113101, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53251, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45623, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:29:53.479145+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53251, "dest_port": 53}}'); INSERT INTO alerts VALUES(4571,1773084593.47914505,'{"timestamp": "2026-03-09T20:29:53.479145+0100", "flow_id": 369063550593340, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58578, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22061, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:29:53.479145+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58578, "dest_port": 53}}'); INSERT INTO alerts VALUES(4572,1773084593.479146003,'{"timestamp": "2026-03-09T20:29:53.479146+0100", "flow_id": 369068931942115, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65442, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3905, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:29:53.479146+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65442, "dest_port": 53}}'); INSERT INTO alerts VALUES(4573,1773084594.535662889,'{"timestamp": "2026-03-09T20:29:54.535663+0100", "flow_id": 611808896213851, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49204, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54128, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:29:54.535663+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49204, "dest_port": 53}}'); INSERT INTO alerts VALUES(4574,1773084594.535664082,'{"timestamp": "2026-03-09T20:29:54.535664+0100", "flow_id": 611813579805041, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64061, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17271, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:29:54.535664+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64061, "dest_port": 53}}'); INSERT INTO alerts VALUES(4575,1773084612.320404052,'{"timestamp": "2026-03-09T20:30:12.320404+0100", "flow_id": 1376125014105063, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:30:12.320404+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4576,1773084612.320404052,'{"timestamp": "2026-03-09T20:30:12.320404+0100", "flow_id": 1376127882667601, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:30:12.320404+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4577,1773084643.497262002,'{"timestamp": "2026-03-09T20:30:43.497262+0100", "flow_id": 1009824433298407, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:30:43.497262+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4578,1773084643.497262954,'{"timestamp": "2026-03-09T20:30:43.497263+0100", "flow_id": 1009831596828241, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:30:43.497263+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4579,1773084673.884686946,'{"timestamp": "2026-03-09T20:31:13.884687+0100", "flow_id": 422002324265959, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:31:13.884687+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4580,1773084673.8846879,'{"timestamp": "2026-03-09T20:31:13.884688+0100", "flow_id": 422009487795793, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:31:13.884688+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4581,1773084676.643853902,'{"timestamp": "2026-03-09T20:31:16.643854+0100", "flow_id": 1357957156215486, "event_type": "alert", "src_ip": "176.65.149.219", "src_port": 63527, "dest_ip": "134.19.55.199", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 48, "bytes_toclient": 0, "start": "2026-03-09T20:31:16.643854+0100", "src_ip": "176.65.149.219", "dest_ip": "134.19.55.199", "src_port": 63527, "dest_port": 25565}}'); INSERT INTO alerts VALUES(4582,1773084680.692380906,'{"timestamp": "2026-03-09T20:31:20.692381+0100", "flow_id": 159006907437338, "event_type": "alert", "src_ip": "185.242.226.73", "src_port": 45342, "dest_ip": "134.19.55.199", "dest_port": 8428, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:31:20.692381+0100", "src_ip": "185.242.226.73", "dest_ip": "134.19.55.199", "src_port": 45342, "dest_port": 8428}}'); INSERT INTO alerts VALUES(4583,1773084683.947468042,'{"timestamp": "2026-03-09T20:31:23.947468+0100", "flow_id": 973122288728666, "event_type": "alert", "src_ip": "87.121.84.72", "src_port": 59189, "dest_ip": "134.19.55.199", "dest_port": 128, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:31:23.947468+0100", "src_ip": "87.121.84.72", "dest_ip": "134.19.55.199", "src_port": 59189, "dest_port": 128}}'); INSERT INTO alerts VALUES(4584,1773084685.645925046,'{"timestamp": "2026-03-09T20:31:25.645925+0100", "flow_id": 1648330840726455, "event_type": "alert", "src_ip": "167.94.146.41", "src_port": 26729, "dest_ip": "134.19.55.199", "dest_port": 6382, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:31:25.645925+0100", "src_ip": "167.94.146.41", "dest_ip": "134.19.55.199", "src_port": 26729, "dest_port": 6382}}'); INSERT INTO alerts VALUES(4585,1773084697.586739063,'{"timestamp": "2026-03-09T20:31:37.586739+0100", "flow_id": 549702730448946, "event_type": "alert", "src_ip": "167.94.146.46", "src_port": 15815, "dest_ip": "134.19.55.199", "dest_port": 13419, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:31:37.586739+0100", "src_ip": "167.94.146.46", "dest_ip": "134.19.55.199", "src_port": 15815, "dest_port": 13419}}'); INSERT INTO alerts VALUES(4586,1773084704.14611411,'{"timestamp": "2026-03-09T20:31:44.146114+0100", "flow_id": 64605210663911, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:31:44.146114+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4587,1773084704.147241116,'{"timestamp": "2026-03-09T20:31:44.147241+0100", "flow_id": 69448507369041, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:31:44.147241+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4588,1773084725.77559805,'{"timestamp": "2026-03-09T20:32:05.775598+0100", "flow_id": 1642318436026516, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59044, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65012, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:32:05.775598+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59044, "dest_port": 53}}'); INSERT INTO alerts VALUES(4589,1773084725.775599003,'{"timestamp": "2026-03-09T20:32:05.775599+0100", "flow_id": 1642323834723107, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56791, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49879, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:32:05.775599+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56791, "dest_port": 53}}'); INSERT INTO alerts VALUES(4590,1773084734.793220997,'{"timestamp": "2026-03-09T20:32:14.793221+0100", "flow_id": 1718008705833959, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:32:14.793221+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4591,1773084734.79322195,'{"timestamp": "2026-03-09T20:32:14.793222+0100", "flow_id": 1718015869363793, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:32:14.793222+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4592,1773084754.897356033,'{"timestamp": "2026-03-09T20:32:34.897356+0100", "flow_id": 757891211315917, "event_type": "alert", "src_ip": "205.210.31.105", "src_port": 54900, "dest_ip": "134.19.55.199", "dest_port": 8443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:32:34.897356+0100", "src_ip": "205.210.31.105", "dest_ip": "134.19.55.199", "src_port": 54900, "dest_port": 8443}}'); INSERT INTO alerts VALUES(4593,1773084765.011419058,'{"timestamp": "2026-03-09T20:32:45.011419+0100", "flow_id": 1456419427703783, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:32:45.011419+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4594,1773084765.011420011,'{"timestamp": "2026-03-09T20:32:45.011420+0100", "flow_id": 1456426591233617, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:32:45.011420+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4595,1773084795.528491974,'{"timestamp": "2026-03-09T20:33:15.528492+0100", "flow_id": 862481285241831, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:33:15.528492+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4596,1773084795.528491974,'{"timestamp": "2026-03-09T20:33:15.528492+0100", "flow_id": 862484153804369, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:33:15.528492+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4597,1773084843.434148074,'{"timestamp": "2026-03-09T20:34:03.434148+0100", "flow_id": 1020230560481695, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65183, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40096, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:34:03.434148+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65183, "dest_port": 53}}'); INSERT INTO alerts VALUES(4598,1773084843.434148074,'{"timestamp": "2026-03-09T20:34:03.434148+0100", "flow_id": 1020230707285617, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60010, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25588, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:34:03.434148+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60010, "dest_port": 53}}'); INSERT INTO alerts VALUES(4599,1773084853.421520948,'{"timestamp": "2026-03-09T20:34:13.421521+0100", "flow_id": 1528944207716213, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52457, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11713, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:34:13.421521+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52457, "dest_port": 53}}'); INSERT INTO alerts VALUES(4600,1773084859.237149,'{"timestamp": "2026-03-09T20:34:19.237149+0100", "flow_id": 1018548520455710, "event_type": "alert", "src_ip": "147.185.132.84", "src_port": 50191, "dest_ip": "134.19.55.199", "dest_port": 1000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:34:19.237149+0100", "src_ip": "147.185.132.84", "dest_ip": "134.19.55.199", "src_port": 50191, "dest_port": 1000}}'); INSERT INTO alerts VALUES(4601,1773084867.294516086,'{"timestamp": "2026-03-09T20:34:27.294516+0100", "flow_id": 983461924035559, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:34:27.294516+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4602,1773084867.29451704,'{"timestamp": "2026-03-09T20:34:27.294517+0100", "flow_id": 983469087565393, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:34:27.294517+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4603,1773084897.858618022,'{"timestamp": "2026-03-09T20:34:57.858618+0100", "flow_id": 310036821826535, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:34:57.858618+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4604,1773084897.858618022,'{"timestamp": "2026-03-09T20:34:57.858618+0100", "flow_id": 310039690389073, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:34:57.858618+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4605,1773084914.327816963,'{"timestamp": "2026-03-09T20:35:14.327817+0100", "flow_id": 563538938359809, "event_type": "alert", "src_ip": "167.94.138.137", "src_port": 33849, "dest_ip": "134.19.55.199", "dest_port": 2363, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 42, "bytes_toclient": 0, "start": "2026-03-09T20:35:14.327817+0100", "src_ip": "167.94.138.137", "dest_ip": "134.19.55.199", "src_port": 33849, "dest_port": 2363}}'); INSERT INTO alerts VALUES(4606,1773084926.393480062,'{"timestamp": "2026-03-09T20:35:26.393480+0100", "flow_id": 1880472760479791, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 45338, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:35:26.372295+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 45338, "dest_port": 853}}'); INSERT INTO alerts VALUES(4607,1773084929.341762065,'{"timestamp": "2026-03-09T20:35:29.341762+0100", "flow_id": 341957018770407, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:35:29.341762+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4608,1773084929.34292698,'{"timestamp": "2026-03-09T20:35:29.342927+0100", "flow_id": 346963524232785, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:35:29.342927+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4609,1773084944.984678031,'{"timestamp": "2026-03-09T20:35:44.984678+0100", "flow_id": 186032699972182, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 59972, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:35:44.960818+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 59972, "dest_port": 853}}'); INSERT INTO alerts VALUES(4610,1773084959.980278969,'{"timestamp": "2026-03-09T20:35:59.980279+0100", "flow_id": 2239941721578471, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:35:59.980279+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4611,1773084959.980278969,'{"timestamp": "2026-03-09T20:35:59.980279+0100", "flow_id": 2239944590141009, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:35:59.980279+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4612,1773084965.088351965,'{"timestamp": "2026-03-09T20:36:05.088352+0100", "flow_id": 1505372886368671, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65183, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40096, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:36:05.088352+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65183, "dest_port": 53}}'); INSERT INTO alerts VALUES(4613,1773084965.088351965,'{"timestamp": "2026-03-09T20:36:05.088352+0100", "flow_id": 1505373033172593, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60010, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25588, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:36:05.088352+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60010, "dest_port": 53}}'); INSERT INTO alerts VALUES(4614,1773084978.637329102,'{"timestamp": "2026-03-09T20:36:18.637329+0100", "flow_id": 766983020350793, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52640, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33751, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "geo-applefinance-cache.internal.query.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 100, "bytes_toclient": 0, "start": "2026-03-09T20:36:18.637329+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52640, "dest_port": 53}}'); INSERT INTO alerts VALUES(4615,1773084991.196984053,'{"timestamp": "2026-03-09T20:36:31.196984+0100", "flow_id": 1971940057275367, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:36:31.196984+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4616,1773084991.196985007,'{"timestamp": "2026-03-09T20:36:31.196985+0100", "flow_id": 1971947220805201, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:36:31.196985+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4617,1773085009.102874994,'{"timestamp": "2026-03-09T20:36:49.102875+0100", "flow_id": 441846008896506, "event_type": "alert", "src_ip": "147.185.132.27", "src_port": 56589, "dest_ip": "134.19.55.199", "dest_port": 3978, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:36:49.102875+0100", "src_ip": "147.185.132.27", "dest_ip": "134.19.55.199", "src_port": 56589, "dest_port": 3978}}'); INSERT INTO alerts VALUES(4618,1773085021.256834984,'{"timestamp": "2026-03-09T20:37:01.256835+0100", "flow_id": 1666048191486951, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:37:01.256835+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4619,1773085021.256835937,'{"timestamp": "2026-03-09T20:37:01.256836+0100", "flow_id": 1666055355016785, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:37:01.256836+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4620,1773085045.157648087,'{"timestamp": "2026-03-09T20:37:25.157648+0100", "flow_id": 1521518725455247, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51372, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2049132, "rev": 1, "signature": "ET INFO Supabase Development Platform Related Domain in DNS Lookup", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2023_11_09"], "deployment": ["Perimeter"], "performance_impact": ["Low"], "reviewed_at": ["2024_04_09"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2023_11_09"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49648, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "uagvwyhbnlutltxparir.supabase.co", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-09T20:37:25.157648+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51372, "dest_port": 53}}'); INSERT INTO alerts VALUES(4621,1773085045.157649041,'{"timestamp": "2026-03-09T20:37:25.157649+0100", "flow_id": 1521524315310328, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58908, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2049132, "rev": 1, "signature": "ET INFO Supabase Development Platform Related Domain in DNS Lookup", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2023_11_09"], "deployment": ["Perimeter"], "performance_impact": ["Low"], "reviewed_at": ["2024_04_09"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2023_11_09"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18850, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "uagvwyhbnlutltxparir.supabase.co", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-09T20:37:25.157649+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58908, "dest_port": 53}}'); INSERT INTO alerts VALUES(4622,1773085052.182938099,'{"timestamp": "2026-03-09T20:37:32.182938+0100", "flow_id": 1348662993214439, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:37:32.182938+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4623,1773085052.182938099,'{"timestamp": "2026-03-09T20:37:32.182938+0100", "flow_id": 1348665861776977, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:37:32.182938+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4624,1773085053.842624903,'{"timestamp": "2026-03-09T20:37:33.842625+0100", "flow_id": 1648724414676540, "event_type": "alert", "src_ip": "193.163.125.209", "src_port": 33529, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:37:33.842625+0100", "src_ip": "193.163.125.209", "dest_ip": "134.19.55.199", "src_port": 33529, "dest_port": 3306}}'); INSERT INTO alerts VALUES(4625,1773085053.842624903,'{"timestamp": "2026-03-09T20:37:33.842625+0100", "flow_id": 1648724414676540, "event_type": "alert", "src_ip": "193.163.125.209", "src_port": 33529, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:37:33.842625+0100", "src_ip": "193.163.125.209", "dest_ip": "134.19.55.199", "src_port": 33529, "dest_port": 3306}}'); INSERT INTO alerts VALUES(4626,1773085064.986072064,'{"timestamp": "2026-03-09T20:37:44.986072+0100", "flow_id": 200655110392313, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 42258, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:37:44.964222+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 42258, "dest_port": 853}}'); INSERT INTO alerts VALUES(4627,1773085078.771729946,'{"timestamp": "2026-03-09T20:37:58.771730+0100", "flow_id": 1907181731225518, "event_type": "alert", "src_ip": "88.210.63.191", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 56443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:37:58.771730+0100", "src_ip": "88.210.63.191", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 56443}}'); INSERT INTO alerts VALUES(4628,1773085081.67919302,'{"timestamp": "2026-03-09T20:38:01.679193+0100", "flow_id": 383838365976803, "event_type": "alert", "src_ip": "46.151.182.157", "src_port": 44881, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:38:01.679193+0100", "src_ip": "46.151.182.157", "dest_ip": "134.19.55.199", "src_port": 44881, "dest_port": 3306}}'); INSERT INTO alerts VALUES(4629,1773085081.67919302,'{"timestamp": "2026-03-09T20:38:01.679193+0100", "flow_id": 383838365976803, "event_type": "alert", "src_ip": "46.151.182.157", "src_port": 44881, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:38:01.679193+0100", "src_ip": "46.151.182.157", "dest_ip": "134.19.55.199", "src_port": 44881, "dest_port": 3306}}'); INSERT INTO alerts VALUES(4630,1773085082.517189026,'{"timestamp": "2026-03-09T20:38:02.517189+0100", "flow_id": 813935269895143, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:38:02.517189+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4631,1773085082.517189979,'{"timestamp": "2026-03-09T20:38:02.517190+0100", "flow_id": 813942433424977, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:38:02.517190+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4632,1773085100.77367711,'{"timestamp": "2026-03-09T20:38:20.773677+0100", "flow_id": 1352594306609953, "event_type": "alert", "src_ip": "147.185.132.78", "src_port": 54922, "dest_ip": "134.19.55.199", "dest_port": 9418, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:38:20.773677+0100", "src_ip": "147.185.132.78", "dest_ip": "134.19.55.199", "src_port": 54922, "dest_port": 9418}}'); INSERT INTO alerts VALUES(4633,1773085113.813462973,'{"timestamp": "2026-03-09T20:38:33.813463+0100", "flow_id": 397572550286311, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:38:33.813463+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4634,1773085113.813463926,'{"timestamp": "2026-03-09T20:38:33.813464+0100", "flow_id": 397579713816145, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:38:33.813464+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4635,1773085119.191420079,'{"timestamp": "2026-03-09T20:38:39.191420+0100", "flow_id": 2229519391400009, "event_type": "alert", "src_ip": "147.185.132.37", "src_port": 10028, "dest_ip": "134.19.55.199", "dest_port": 12546, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T20:38:39.191420+0100", "src_ip": "147.185.132.37", "dest_ip": "134.19.55.199", "src_port": 10028, "dest_port": 12546}}'); INSERT INTO alerts VALUES(4636,1773085145.09730196,'{"timestamp": "2026-03-09T20:39:05.097302+0100", "flow_id": 417909220432871, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:39:05.097302+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4637,1773085145.097302914,'{"timestamp": "2026-03-09T20:39:05.097303+0100", "flow_id": 417916383962705, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:39:05.097303+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4638,1773085175.230242968,'{"timestamp": "2026-03-09T20:39:35.230243+0100", "flow_id": 2114786374573031, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:39:35.230243+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4639,1773085175.230243921,'{"timestamp": "2026-03-09T20:39:35.230244+0100", "flow_id": 2114793538102865, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:39:35.230244+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4640,1773085176.810877085,'{"timestamp": "2026-03-09T20:39:36.810877+0100", "flow_id": 8740368909177, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 51512, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:39:36.788467+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 51512, "dest_port": 853}}'); INSERT INTO alerts VALUES(4641,1773085184.987631083,'{"timestamp": "2026-03-09T20:39:44.987631+0100", "flow_id": 207508039416762, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 60166, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:39:44.965818+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 60166, "dest_port": 853}}'); INSERT INTO alerts VALUES(4642,1773085206.354257107,'{"timestamp": "2026-03-09T20:40:06.354257+0100", "flow_id": 1802997518687207, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:40:06.354257+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4643,1773085206.354257107,'{"timestamp": "2026-03-09T20:40:06.354257+0100", "flow_id": 1803000387249745, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:40:06.354257+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4644,1773085208.609217882,'{"timestamp": "2026-03-09T20:40:08.609218+0100", "flow_id": 83299856446679, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 59639, "dest_ip": "134.19.55.199", "dest_port": 40232, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:40:08.609218+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 59639, "dest_port": 40232}}'); INSERT INTO alerts VALUES(4645,1773085235.039323092,'{"timestamp": "2026-03-09T20:40:35.039323+0100", "flow_id": 1013318104379845, "event_type": "alert", "src_ip": "66.132.153.154", "src_port": 27148, "dest_ip": "134.19.55.199", "dest_port": 5000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:40:35.039323+0100", "src_ip": "66.132.153.154", "dest_ip": "134.19.55.199", "src_port": 27148, "dest_port": 5000}}'); INSERT INTO alerts VALUES(4646,1773085236.497580051,'{"timestamp": "2026-03-09T20:40:36.497580+0100", "flow_id": 1292665209609191, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:40:36.497580+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4647,1773085236.497580051,'{"timestamp": "2026-03-09T20:40:36.497580+0100", "flow_id": 1292668078171729, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:40:36.497580+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4648,1773085245.825814963,'{"timestamp": "2026-03-09T20:40:45.825815+0100", "flow_id": 1576524130681095, "event_type": "alert", "src_ip": "195.184.76.76", "src_port": 43034, "dest_ip": "134.19.55.199", "dest_port": 2443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:40:45.825815+0100", "src_ip": "195.184.76.76", "dest_ip": "134.19.55.199", "src_port": 43034, "dest_port": 2443}}'); INSERT INTO alerts VALUES(4649,1773085266.527735949,'{"timestamp": "2026-03-09T20:41:06.527736+0100", "flow_id": 577759313255399, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:41:06.527736+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4650,1773085266.527735949,'{"timestamp": "2026-03-09T20:41:06.527736+0100", "flow_id": 577762181817937, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:41:06.527736+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4651,1773085297.744054079,'{"timestamp": "2026-03-09T20:41:37.744054+0100", "flow_id": 380938141948903, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:41:37.744054+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4652,1773085297.744055033,'{"timestamp": "2026-03-09T20:41:37.744055+0100", "flow_id": 380945305478737, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:41:37.744055+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4653,1773085304.991306066,'{"timestamp": "2026-03-09T20:41:44.991306+0100", "flow_id": 230245319552839, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 45172, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:41:44.971112+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 45172, "dest_port": 853}}'); INSERT INTO alerts VALUES(4654,1773085357.719641923,'{"timestamp": "2026-03-09T20:42:37.719642+0100", "flow_id": 1683465477266830, "event_type": "alert", "src_ip": "147.185.132.234", "src_port": 51620, "dest_ip": "134.19.55.199", "dest_port": 50100, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:42:37.719642+0100", "src_ip": "147.185.132.234", "dest_ip": "134.19.55.199", "src_port": 51620, "dest_port": 50100}}'); INSERT INTO alerts VALUES(4655,1773085358.328722,'{"timestamp": "2026-03-09T20:42:38.328722+0100", "flow_id": 1693326522001724, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58578, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22061, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:42:38.328722+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58578, "dest_port": 53}}'); INSERT INTO alerts VALUES(4656,1773085358.328722,'{"timestamp": "2026-03-09T20:42:38.328722+0100", "flow_id": 1693327608383203, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65442, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3905, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:42:38.328722+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65442, "dest_port": 53}}'); INSERT INTO alerts VALUES(4657,1773085358.328722,'{"timestamp": "2026-03-09T20:42:38.328722+0100", "flow_id": 1693326330396152, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51960, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44498, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:42:38.328722+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51960, "dest_port": 53}}'); INSERT INTO alerts VALUES(4658,1773085358.328722953,'{"timestamp": "2026-03-09T20:42:38.328723+0100", "flow_id": 1693332356246541, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62153, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7535, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:42:38.328723+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62153, "dest_port": 53}}'); INSERT INTO alerts VALUES(4659,1773085361.385492086,'{"timestamp": "2026-03-09T20:42:41.385492+0100", "flow_id": 529778131320258, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64996, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23783, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "calendars.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T20:42:41.385492+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64996, "dest_port": 53}}'); INSERT INTO alerts VALUES(4660,1773085376.124609948,'{"timestamp": "2026-03-09T20:42:56.124610+0100", "flow_id": 253721210641383, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:42:56.124610+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4661,1773085376.125312089,'{"timestamp": "2026-03-09T20:42:56.125312+0100", "flow_id": 256739146245713, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:42:56.125312+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4662,1773085406.408991098,'{"timestamp": "2026-03-09T20:43:26.408991+0100", "flow_id": 1756603281955815, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:43:26.408991+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4663,1773085406.409815073,'{"timestamp": "2026-03-09T20:43:26.409815+0100", "flow_id": 1760145203570257, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:43:26.409815+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4664,1773085414.56791091,'{"timestamp": "2026-03-09T20:43:34.567911+0100", "flow_id": 1876209719974824, "event_type": "alert", "src_ip": "193.163.125.202", "src_port": 33362, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:43:34.567911+0100", "src_ip": "193.163.125.202", "dest_ip": "134.19.55.199", "src_port": 33362, "dest_port": 23}}'); INSERT INTO alerts VALUES(4665,1773085424.993081092,'{"timestamp": "2026-03-09T20:43:44.993081+0100", "flow_id": 236383469330923, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 56656, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:43:44.972541+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 56656, "dest_port": 853}}'); INSERT INTO alerts VALUES(4666,1773085436.666172027,'{"timestamp": "2026-03-09T20:43:56.666172+0100", "flow_id": 1172337405844455, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:43:56.666172+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4667,1773085436.666426897,'{"timestamp": "2026-03-09T20:43:56.666427+0100", "flow_id": 1173435491067473, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:43:56.666427+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4668,1773085438.821537018,'{"timestamp": "2026-03-09T20:43:58.821537+0100", "flow_id": 1839626884062787, "event_type": "alert", "src_ip": "147.185.132.222", "src_port": 57236, "dest_ip": "134.19.55.199", "dest_port": 9002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:43:58.821537+0100", "src_ip": "147.185.132.222", "dest_ip": "134.19.55.199", "src_port": 57236, "dest_port": 9002}}'); INSERT INTO alerts VALUES(4669,1773085438.897147894,'{"timestamp": "2026-03-09T20:43:58.897148+0100", "flow_id": 1882898199098273, "event_type": "alert", "src_ip": "205.210.31.193", "src_port": 53553, "dest_ip": "134.19.55.199", "dest_port": 873, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:43:58.897148+0100", "src_ip": "205.210.31.193", "dest_ip": "134.19.55.199", "src_port": 53553, "dest_port": 873}}'); INSERT INTO alerts VALUES(4670,1773085439.953310967,'{"timestamp": "2026-03-09T20:43:59.953311+0100", "flow_id": 2124114858910247, "event_type": "alert", "src_ip": "205.210.31.41", "src_port": 52055, "dest_ip": "134.19.55.199", "dest_port": 2161, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:43:59.953311+0100", "src_ip": "205.210.31.41", "dest_ip": "134.19.55.199", "src_port": 52055, "dest_port": 2161}}'); INSERT INTO alerts VALUES(4671,1773085444.693896055,'{"timestamp": "2026-03-09T20:44:04.693896+0100", "flow_id": 1291413172725395, "event_type": "alert", "src_ip": "193.163.125.188", "src_port": 34531, "dest_ip": "134.19.55.199", "dest_port": 59139, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:44:04.693896+0100", "src_ip": "193.163.125.188", "dest_ip": "134.19.55.199", "src_port": 34531, "dest_port": 59139}}'); INSERT INTO alerts VALUES(4672,1773085467.152683974,'{"timestamp": "2026-03-09T20:44:27.152684+0100", "flow_id": 937248075930599, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:44:27.152684+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4673,1773085467.152684926,'{"timestamp": "2026-03-09T20:44:27.152685+0100", "flow_id": 937255239460433, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:44:27.152685+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4674,1773085497.886331082,'{"timestamp": "2026-03-09T20:44:57.886331+0100", "flow_id": 429063250500583, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:44:57.886331+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4675,1773085497.886331082,'{"timestamp": "2026-03-09T20:44:57.886331+0100", "flow_id": 429066119063121, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:44:57.886331+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4676,1773085503.961344003,'{"timestamp": "2026-03-09T20:45:03.961344+0100", "flow_id": 2158618928695557, "event_type": "alert", "src_ip": "147.185.132.33", "src_port": 56071, "dest_ip": "134.19.55.199", "dest_port": 9191, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:45:03.961344+0100", "src_ip": "147.185.132.33", "dest_ip": "134.19.55.199", "src_port": 56071, "dest_port": 9191}}'); INSERT INTO alerts VALUES(4677,1773085527.337466955,'{"timestamp": "2026-03-09T20:45:27.337467+0100", "flow_id": 2012361492780577, "event_type": "alert", "src_ip": "66.132.153.156", "src_port": 60741, "dest_ip": "134.19.55.199", "dest_port": 8085, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:45:27.337467+0100", "src_ip": "66.132.153.156", "dest_ip": "134.19.55.199", "src_port": 60741, "dest_port": 8085}}'); INSERT INTO alerts VALUES(4678,1773085527.905219078,'{"timestamp": "2026-03-09T20:45:27.905219+0100", "flow_id": 2199036453051367, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:45:27.905219+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4679,1773085527.905219078,'{"timestamp": "2026-03-09T20:45:27.905219+0100", "flow_id": 2199039321613905, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:45:27.905219+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4680,1773085544.999619008,'{"timestamp": "2026-03-09T20:45:44.999619+0100", "flow_id": 259177377075315, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 54592, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:45:44.977848+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 54592, "dest_port": 853}}'); INSERT INTO alerts VALUES(4681,1773085545.325737954,'{"timestamp": "2026-03-09T20:45:45.325738+0100", "flow_id": 554609924097710, "event_type": "alert", "src_ip": "66.132.153.143", "src_port": 50193, "dest_ip": "134.19.55.199", "dest_port": 500, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ike", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 364, "bytes_toclient": 0, "start": "2026-03-09T20:45:45.325738+0100", "src_ip": "66.132.153.143", "dest_ip": "134.19.55.199", "src_port": 50193, "dest_port": 500}}'); INSERT INTO alerts VALUES(4682,1773085558.183212041,'{"timestamp": "2026-03-09T20:45:58.183212+0100", "flow_id": 1912789767674855, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:45:58.183212+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4683,1773085558.183212996,'{"timestamp": "2026-03-09T20:45:58.183213+0100", "flow_id": 1912796931204689, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:45:58.183213+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4684,1773085558.23989606,'{"timestamp": "2026-03-09T20:45:58.239896+0100", "flow_id": 1874771518782968, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51960, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44498, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:45:58.239896+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51960, "dest_port": 53}}'); INSERT INTO alerts VALUES(4685,1773085558.246368885,'{"timestamp": "2026-03-09T20:45:58.246369+0100", "flow_id": 1902574572973069, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62153, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7535, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:45:58.246369+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62153, "dest_port": 53}}'); INSERT INTO alerts VALUES(4686,1773085558.252599955,'{"timestamp": "2026-03-09T20:45:58.252600+0100", "flow_id": 1929335077459879, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59115, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49264, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:45:58.252600+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59115, "dest_port": 53}}'); INSERT INTO alerts VALUES(4687,1773085558.25526309,'{"timestamp": "2026-03-09T20:45:58.255263+0100", "flow_id": 1940773958590385, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49346, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48714, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:45:58.255263+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49346, "dest_port": 53}}'); INSERT INTO alerts VALUES(4688,1773085558.672796964,'{"timestamp": "2026-03-09T20:45:58.672797+0100", "flow_id": 1763743664340772, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62626, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58244, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:45:58.672797+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62626, "dest_port": 53}}'); INSERT INTO alerts VALUES(4689,1773085558.6750381,'{"timestamp": "2026-03-09T20:45:58.675038+0100", "flow_id": 1773367707441011, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56049, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6535, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:45:58.675038+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56049, "dest_port": 53}}'); INSERT INTO alerts VALUES(4690,1773085577.323971034,'{"timestamp": "2026-03-09T20:46:17.323971+0100", "flow_id": 547022962926563, "event_type": "alert", "src_ip": "195.184.76.84", "src_port": 3632, "dest_ip": "134.19.55.199", "dest_port": 20000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:46:17.323971+0100", "src_ip": "195.184.76.84", "dest_ip": "134.19.55.199", "src_port": 3632, "dest_port": 20000}}'); INSERT INTO alerts VALUES(4691,1773085589.223683118,'{"timestamp": "2026-03-09T20:46:29.223683+0100", "flow_id": 1523661435689959, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:46:29.223683+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4692,1773085589.223683118,'{"timestamp": "2026-03-09T20:46:29.223683+0100", "flow_id": 1523664304252497, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:46:29.223683+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4693,1773085620.682013034,'{"timestamp": "2026-03-09T20:47:00.682013+0100", "flow_id": 1240373982780391, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:47:00.682013+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4694,1773085620.682013988,'{"timestamp": "2026-03-09T20:47:00.682014+0100", "flow_id": 1240381146310225, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:47:00.682014+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4695,1773085633.400749921,'{"timestamp": "2026-03-09T20:47:13.400750+0100", "flow_id": 313837159882942, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 45871, "dest_ip": "134.19.55.199", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:47:13.400750+0100", "src_ip": "193.142.146.230", "dest_ip": "134.19.55.199", "src_port": 45871, "dest_port": 8888}}'); INSERT INTO alerts VALUES(4696,1773085645.595675945,'{"timestamp": "2026-03-09T20:47:25.595676+0100", "flow_id": 1432509598866133, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59044, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62022, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:47:25.595676+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59044, "dest_port": 53}}'); INSERT INTO alerts VALUES(4697,1773085645.59659791,'{"timestamp": "2026-03-09T20:47:25.596598+0100", "flow_id": 1436471060639119, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50995, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16070, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:47:25.596598+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50995, "dest_port": 53}}'); INSERT INTO alerts VALUES(4698,1773085649.496103049,'{"timestamp": "2026-03-09T20:47:29.496103+0100", "flow_id": 441898426935074, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64530, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44888, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:47:29.496103+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64530, "dest_port": 53}}'); INSERT INTO alerts VALUES(4699,1773085649.496103049,'{"timestamp": "2026-03-09T20:47:29.496103+0100", "flow_id": 441896639319428, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51145, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25353, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:47:29.496103+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51145, "dest_port": 53}}'); INSERT INTO alerts VALUES(4700,1773085659.84130001,'{"timestamp": "2026-03-09T20:47:39.841300+0100", "flow_id": 1080081921321964, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56534, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56017, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:47:39.841300+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56534, "dest_port": 53}}'); INSERT INTO alerts VALUES(4701,1773085659.841300965,'{"timestamp": "2026-03-09T20:47:39.841301+0100", "flow_id": 1080087797326473, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49320, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64177, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:47:39.841301+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49320, "dest_port": 53}}'); INSERT INTO alerts VALUES(4702,1773085662.693218947,'{"timestamp": "2026-03-09T20:47:42.693219+0100", "flow_id": 1851455727211555, "event_type": "alert", "src_ip": "198.235.24.58", "src_port": 52393, "dest_ip": "134.19.55.199", "dest_port": 2096, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:47:42.693219+0100", "src_ip": "198.235.24.58", "dest_ip": "134.19.55.199", "src_port": 52393, "dest_port": 2096}}'); INSERT INTO alerts VALUES(4703,1773085665.004226922,'{"timestamp": "2026-03-09T20:47:45.004227+0100", "flow_id": 278422780420263, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 59644, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:47:44.982329+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 59644, "dest_port": 853}}'); INSERT INTO alerts VALUES(4704,1773085692.197724104,'{"timestamp": "2026-03-09T20:48:12.197724+0100", "flow_id": 1130696781754713, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62725, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2063117, "rev": 1, "signature": "ET INFO Abused Hosting Domain in DNS Lookup (azurewebsites .net)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_and_Server"], "confidence": ["Medium"], "created_at": ["2025_06_20"], "deployment": ["Perimeter"], "mitre_tactic_id": ["TA0011"], "mitre_tactic_name": ["Command_And_Control"], "mitre_technique_id": ["T1102"], "mitre_technique_name": ["Web_Service"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "updated_at": ["2025_06_20"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41098, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "pinpoll-tracking-live-windows.azurewebsites.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T20:48:12.197724+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62725, "dest_port": 53}}'); INSERT INTO alerts VALUES(4705,1773085692.198587895,'{"timestamp": "2026-03-09T20:48:12.198588+0100", "flow_id": 1134405583571055, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50614, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2063117, "rev": 1, "signature": "ET INFO Abused Hosting Domain in DNS Lookup (azurewebsites .net)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_and_Server"], "confidence": ["Medium"], "created_at": ["2025_06_20"], "deployment": ["Perimeter"], "mitre_tactic_id": ["TA0011"], "mitre_tactic_name": ["Command_And_Control"], "mitre_technique_id": ["T1102"], "mitre_technique_name": ["Web_Service"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "updated_at": ["2025_06_20"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1981, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "pinpoll-tracking-live-windows.azurewebsites.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-09T20:48:12.198588+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50614, "dest_port": 53}}'); INSERT INTO alerts VALUES(4706,1773085711.878241062,'{"timestamp": "2026-03-09T20:48:31.878241+0100", "flow_id": 2083166825339879, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:48:31.878241+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4707,1773085711.878241062,'{"timestamp": "2026-03-09T20:48:31.878241+0100", "flow_id": 2083169693902417, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:48:31.878241+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4708,1773085731.693202972,'{"timestamp": "2026-03-09T20:48:51.693203+0100", "flow_id": 1006961759021566, "event_type": "alert", "src_ip": "167.94.138.154", "src_port": 21812, "dest_ip": "134.19.55.199", "dest_port": 44819, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:48:51.693203+0100", "src_ip": "167.94.138.154", "dest_ip": "134.19.55.199", "src_port": 21812, "dest_port": 44819}}'); INSERT INTO alerts VALUES(4709,1773085732.325253963,'{"timestamp": "2026-03-09T20:48:52.325254+0100", "flow_id": 1396956425875097, "event_type": "alert", "src_ip": "198.235.24.57", "src_port": 56257, "dest_ip": "134.19.55.199", "dest_port": 59382, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:48:52.325254+0100", "src_ip": "198.235.24.57", "dest_ip": "134.19.55.199", "src_port": 56257, "dest_port": 59382}}'); INSERT INTO alerts VALUES(4710,1773085743.178900958,'{"timestamp": "2026-03-09T20:49:03.178901+0100", "flow_id": 2175749140372455, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:49:03.178901+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4711,1773085743.178900958,'{"timestamp": "2026-03-09T20:49:03.178901+0100", "flow_id": 2175752008934993, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:49:03.178901+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4712,1773085774.148767949,'{"timestamp": "2026-03-09T20:49:34.148768+0100", "flow_id": 1764853914131431, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:49:34.148768+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4713,1773085774.148767949,'{"timestamp": "2026-03-09T20:49:34.148768+0100", "flow_id": 1764856782693969, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:49:34.148768+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4714,1773085783.263896942,'{"timestamp": "2026-03-09T20:49:43.263897+0100", "flow_id": 1977855826075765, "event_type": "alert", "src_ip": "205.210.31.69", "src_port": 54509, "dest_ip": "134.19.55.199", "dest_port": 8140, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:49:43.263897+0100", "src_ip": "205.210.31.69", "dest_ip": "134.19.55.199", "src_port": 54509, "dest_port": 8140}}'); INSERT INTO alerts VALUES(4715,1773085785.006160974,'{"timestamp": "2026-03-09T20:49:45.006161+0100", "flow_id": 10333517167168, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 55588, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:49:44.985445+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 55588, "dest_port": 853}}'); INSERT INTO alerts VALUES(4716,1773085805.276998044,'{"timestamp": "2026-03-09T20:50:05.276998+0100", "flow_id": 1471172640365543, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:50:05.276998+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4717,1773085805.276998044,'{"timestamp": "2026-03-09T20:50:05.276998+0100", "flow_id": 1471175508928081, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:50:05.276998+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4718,1773085836.158556938,'{"timestamp": "2026-03-09T20:50:36.158557+0100", "flow_id": 1243947395570663, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:50:36.158557+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4719,1773085836.159693003,'{"timestamp": "2026-03-09T20:50:36.159693+0100", "flow_id": 1248829346981457, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:50:36.159693+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4720,1773085870.094927073,'{"timestamp": "2026-03-09T20:51:10.094927+0100", "flow_id": 1815087520569996, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60245, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62449, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:51:10.094927+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60245, "dest_port": 53}}'); INSERT INTO alerts VALUES(4721,1773085870.094927073,'{"timestamp": "2026-03-09T20:51:10.094927+0100", "flow_id": 1815085519116290, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60780, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41829, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:51:10.094927+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60780, "dest_port": 53}}'); INSERT INTO alerts VALUES(4722,1773085873.061822892,'{"timestamp": "2026-03-09T20:51:13.061823+0100", "flow_id": 547003776038791, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 41549, "dest_ip": "134.19.55.199", "dest_port": 61091, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T20:51:13.061823+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 41549, "dest_port": 61091}}'); INSERT INTO alerts VALUES(4723,1773085905.007616997,'{"timestamp": "2026-03-09T20:51:45.007617+0100", "flow_id": 17348217259904, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 44708, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T20:51:44.987079+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 44708, "dest_port": 853}}'); INSERT INTO alerts VALUES(4724,1773085912.642438889,'{"timestamp": "2026-03-09T20:51:52.642439+0100", "flow_id": 225980016876519, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:51:52.642439+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4725,1773085912.642438889,'{"timestamp": "2026-03-09T20:51:52.642439+0100", "flow_id": 225982885439057, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:51:52.642439+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4726,1773085920.341392041,'{"timestamp": "2026-03-09T20:52:00.341392+0100", "flow_id": 58893250427042, "event_type": "alert", "src_ip": "45.142.154.87", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 3120, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:52:00.341392+0100", "src_ip": "45.142.154.87", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 3120}}'); INSERT INTO alerts VALUES(4727,1773085943.808012963,'{"timestamp": "2026-03-09T20:52:23.808013+0100", "flow_id": 2063014838787047, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:52:23.808013+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4728,1773085943.808012963,'{"timestamp": "2026-03-09T20:52:23.808013+0100", "flow_id": 2063017707349585, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:52:23.808013+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4729,1773085973.887707948,'{"timestamp": "2026-03-09T20:52:53.887708+0100", "flow_id": 1560881063080721, "event_type": "alert", "src_ip": "45.153.34.213", "src_port": 43855, "dest_ip": "134.19.55.199", "dest_port": 60002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T20:52:53.887708+0100", "src_ip": "45.153.34.213", "dest_ip": "134.19.55.199", "src_port": 43855, "dest_port": 60002}}'); INSERT INTO alerts VALUES(4730,1773085974.330600976,'{"timestamp": "2026-03-09T20:52:54.330601+0100", "flow_id": 1701395772333031, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:52:54.330601+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4731,1773085974.331053973,'{"timestamp": "2026-03-09T20:52:54.331054+0100", "flow_id": 1703344261080657, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:52:54.331054+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4732,1773085982.011812925,'{"timestamp": "2026-03-09T20:53:02.011813+0100", "flow_id": 1739588816919176, "event_type": "alert", "src_ip": "205.210.31.166", "src_port": 52114, "dest_ip": "134.19.55.199", "dest_port": 3909, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:53:02.011813+0100", "src_ip": "205.210.31.166", "dest_ip": "134.19.55.199", "src_port": 52114, "dest_port": 3909}}'); INSERT INTO alerts VALUES(4733,1773085983.495950937,'{"timestamp": "2026-03-09T20:53:03.495951+0100", "flow_id": 2130094382585741, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60973, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:53:03.495951+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60973, "dest_port": 53}}'); INSERT INTO alerts VALUES(4734,1773085983.49722004,'{"timestamp": "2026-03-09T20:53:03.497220+0100", "flow_id": 2135547872628650, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53977, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21982, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:53:03.497220+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53977, "dest_port": 53}}'); INSERT INTO alerts VALUES(4735,1773085986.42742896,'{"timestamp": "2026-03-09T20:53:06.427429+0100", "flow_id": 709894740150445, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54947, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42957, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:53:06.427429+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54947, "dest_port": 53}}'); INSERT INTO alerts VALUES(4736,1773085986.427429914,'{"timestamp": "2026-03-09T20:53:06.427430+0100", "flow_id": 709899921987393, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61979, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25916, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:53:06.427430+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61979, "dest_port": 53}}'); INSERT INTO alerts VALUES(4737,1773085996.075728894,'{"timestamp": "2026-03-09T20:53:16.075729+0100", "flow_id": 1169680981305429, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65338, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17140, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:53:16.075729+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65338, "dest_port": 53}}'); INSERT INTO alerts VALUES(4738,1773085996.076302052,'{"timestamp": "2026-03-09T20:53:16.076302+0100", "flow_id": 1172140586025620, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52612, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39131, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:53:16.076302+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52612, "dest_port": 53}}'); INSERT INTO alerts VALUES(4739,1773086005.82297206,'{"timestamp": "2026-03-09T20:53:25.822972+0100", "flow_id": 1564313301146599, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:53:25.822972+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4740,1773086005.82297206,'{"timestamp": "2026-03-09T20:53:25.822972+0100", "flow_id": 1564316169709137, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:53:25.822972+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4741,1773086036.606311083,'{"timestamp": "2026-03-09T20:53:56.606311+0100", "flow_id": 1196711345249255, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:53:56.606311+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4742,1773086036.606311083,'{"timestamp": "2026-03-09T20:53:56.606311+0100", "flow_id": 1196714213811793, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:53:56.606311+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4743,1773086036.98429799,'{"timestamp": "2026-03-09T20:53:56.984298+0100", "flow_id": 1131305495753976, "event_type": "alert", "src_ip": "198.235.24.177", "src_port": 35139, "dest_ip": "134.19.55.199", "dest_port": 3283, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 33, "bytes_toclient": 0, "start": "2026-03-09T20:53:56.984298+0100", "src_ip": "198.235.24.177", "dest_ip": "134.19.55.199", "src_port": 35139, "dest_port": 3283}}'); INSERT INTO alerts VALUES(4744,1773086052.329613924,'{"timestamp": "2026-03-09T20:54:12.329614+0100", "flow_id": 1134208846407765, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65338, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17140, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:54:12.329614+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65338, "dest_port": 53}}'); INSERT INTO alerts VALUES(4745,1773086052.329615116,'{"timestamp": "2026-03-09T20:54:12.329615+0100", "flow_id": 1134211729834644, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52612, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39131, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:54:12.329615+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52612, "dest_port": 53}}'); INSERT INTO alerts VALUES(4746,1773086052.32961607,'{"timestamp": "2026-03-09T20:54:12.329616+0100", "flow_id": 1134218648351093, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56942, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30424, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:54:12.329616+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56942, "dest_port": 53}}'); INSERT INTO alerts VALUES(4747,1773086052.32961607,'{"timestamp": "2026-03-09T20:54:12.329616+0100", "flow_id": 1134215102934440, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60107, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3107, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:54:12.329616+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60107, "dest_port": 53}}'); INSERT INTO alerts VALUES(4748,1773086052.32961607,'{"timestamp": "2026-03-09T20:54:12.329616+0100", "flow_id": 1134215974626750, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63836, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23656, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:54:12.329616+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63836, "dest_port": 53}}'); INSERT INTO alerts VALUES(4749,1773086052.330161095,'{"timestamp": "2026-03-09T20:54:12.330161+0100", "flow_id": 1136556090651775, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54788, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46098, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:54:12.330161+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54788, "dest_port": 53}}'); INSERT INTO alerts VALUES(4750,1773086056.459217072,'{"timestamp": "2026-03-09T20:54:16.459217+0100", "flow_id": 1998106324129, "event_type": "alert", "src_ip": "20.168.7.149", "src_port": 52565, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T20:54:16.459217+0100", "src_ip": "20.168.7.149", "dest_ip": "134.19.55.199", "src_port": 52565, "dest_port": 1433}}'); INSERT INTO alerts VALUES(4751,1773086067.681632041,'{"timestamp": "2026-03-09T20:54:27.681632+0100", "flow_id": 957262623529959, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:54:27.681632+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4752,1773086067.681632996,'{"timestamp": "2026-03-09T20:54:27.681633+0100", "flow_id": 957269787059793, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:54:27.681633+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4753,1773086087.297653914,'{"timestamp": "2026-03-09T20:54:47.297654+0100", "flow_id": 2122839257994141, "event_type": "alert", "src_ip": "167.94.138.142", "src_port": 40642, "dest_ip": "134.19.55.199", "dest_port": 2404, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:54:47.297654+0100", "src_ip": "167.94.138.142", "dest_ip": "134.19.55.199", "src_port": 40642, "dest_port": 2404}}'); INSERT INTO alerts VALUES(4754,1773086098.200581074,'{"timestamp": "2026-03-09T20:54:58.200581+0100", "flow_id": 580014171085799, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:54:58.200581+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4755,1773086098.200582028,'{"timestamp": "2026-03-09T20:54:58.200582+0100", "flow_id": 580021334615633, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:54:58.200582+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4756,1773086103.366764068,'{"timestamp": "2026-03-09T20:55:03.366764+0100", "flow_id": 2138192470385305, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53920, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27482, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:55:03.366764+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53920, "dest_port": 53}}'); INSERT INTO alerts VALUES(4757,1773086103.366765023,'{"timestamp": "2026-03-09T20:55:03.366765+0100", "flow_id": 2138195618474066, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57749, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65397, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:55:03.366765+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57749, "dest_port": 53}}'); INSERT INTO alerts VALUES(4758,1773086128.322705031,'{"timestamp": "2026-03-09T20:55:28.322705+0100", "flow_id": 260107827010535, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:55:28.322705+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4759,1773086128.322705031,'{"timestamp": "2026-03-09T20:55:28.322705+0100", "flow_id": 260110695573073, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:55:28.322705+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4760,1773086159.314182044,'{"timestamp": "2026-03-09T20:55:59.314182+0100", "flow_id": 2193826657721319, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:55:59.314182+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4761,1773086159.314182044,'{"timestamp": "2026-03-09T20:55:59.314182+0100", "flow_id": 2193829526283857, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:55:59.314182+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4762,1773086163.10648799,'{"timestamp": "2026-03-09T20:56:03.106488+0100", "flow_id": 1020313156430828, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56534, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56017, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:56:03.106488+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56534, "dest_port": 53}}'); INSERT INTO alerts VALUES(4763,1773086163.106488943,'{"timestamp": "2026-03-09T20:56:03.106489+0100", "flow_id": 1020319032435337, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49320, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64177, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:56:03.106489+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49320, "dest_port": 53}}'); INSERT INTO alerts VALUES(4764,1773086163.106739997,'{"timestamp": "2026-03-09T20:56:03.106740+0100", "flow_id": 1021398827910263, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53421, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:56:03.106740+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53421, "dest_port": 53}}'); INSERT INTO alerts VALUES(4765,1773086163.107286931,'{"timestamp": "2026-03-09T20:56:03.107287+0100", "flow_id": 1023744703972841, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50453, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:56:03.107287+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58176, "dest_port": 53}}'); INSERT INTO alerts VALUES(4766,1773086172.661633015,'{"timestamp": "2026-03-09T20:56:12.661633+0100", "flow_id": 1152844577888044, "event_type": "alert", "src_ip": "193.163.125.204", "src_port": 44853, "dest_ip": "134.19.55.199", "dest_port": 42477, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T20:56:12.661633+0100", "src_ip": "193.163.125.204", "dest_ip": "134.19.55.199", "src_port": 44853, "dest_port": 42477}}'); INSERT INTO alerts VALUES(4767,1773086188.534605027,'{"timestamp": "2026-03-09T20:56:28.534605+0100", "flow_id": 1170212088610412, "event_type": "alert", "src_ip": "66.132.153.153", "src_port": 8435, "dest_ip": "134.19.55.199", "dest_port": 9301, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:56:28.534605+0100", "src_ip": "66.132.153.153", "dest_ip": "134.19.55.199", "src_port": 8435, "dest_port": 9301}}'); INSERT INTO alerts VALUES(4768,1773086189.498100996,'{"timestamp": "2026-03-09T20:56:29.498101+0100", "flow_id": 1576377864281063, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:56:29.498101+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4769,1773086189.49810195,'{"timestamp": "2026-03-09T20:56:29.498102+0100", "flow_id": 1576385027810897, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:56:29.498102+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4770,1773086219.591273069,'{"timestamp": "2026-03-09T20:56:59.591273+0100", "flow_id": 850648650341351, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:56:59.591273+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4771,1773086219.591273069,'{"timestamp": "2026-03-09T20:56:59.591273+0100", "flow_id": 850651518903889, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:56:59.591273+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4772,1773086222.6916461,'{"timestamp": "2026-03-09T20:57:02.691646+0100", "flow_id": 1844697718041592, "event_type": "alert", "src_ip": "167.94.146.43", "src_port": 51634, "dest_ip": "134.19.55.199", "dest_port": 14473, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:57:02.691646+0100", "src_ip": "167.94.146.43", "dest_ip": "134.19.55.199", "src_port": 51634, "dest_port": 14473}}'); INSERT INTO alerts VALUES(4773,1773086250.351639033,'{"timestamp": "2026-03-09T20:57:30.351639+0100", "flow_id": 665853387463655, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:57:30.351639+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4774,1773086250.351639987,'{"timestamp": "2026-03-09T20:57:30.351640+0100", "flow_id": 665860550993489, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:57:30.351640+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4775,1773086274.548177003,'{"timestamp": "2026-03-09T20:57:54.548177+0100", "flow_id": 665555821380568, "event_type": "alert", "src_ip": "193.163.125.65", "src_port": 24670, "dest_ip": "134.19.55.199", "dest_port": 111, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-09T20:57:54.548177+0100", "src_ip": "193.163.125.65", "dest_ip": "134.19.55.199", "src_port": 24670, "dest_port": 111}}'); INSERT INTO alerts VALUES(4776,1773086281.020935059,'{"timestamp": "2026-03-09T20:58:01.020935+0100", "flow_id": 371390429649895, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:58:01.020935+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4777,1773086281.021193982,'{"timestamp": "2026-03-09T20:58:01.021194+0100", "flow_id": 372505694742097, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:58:01.021194+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4778,1773086312.464993954,'{"timestamp": "2026-03-09T20:58:32.464994+0100", "flow_id": 26809498459111, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:58:32.464994+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4779,1773086312.464994907,'{"timestamp": "2026-03-09T20:58:32.464995+0100", "flow_id": 26816661988945, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:58:32.464995+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4780,1773086336.06342411,'{"timestamp": "2026-03-09T20:58:56.063424+0100", "flow_id": 272407481743642, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55383, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56229, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:58:56.063424+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55383, "dest_port": 53}}'); INSERT INTO alerts VALUES(4781,1773086336.06342411,'{"timestamp": "2026-03-09T20:58:56.063424+0100", "flow_id": 272406912393220, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57155, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11649, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:58:56.063424+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57155, "dest_port": 53}}'); INSERT INTO alerts VALUES(4782,1773086343.294795036,'{"timestamp": "2026-03-09T20:59:03.294795+0100", "flow_id": 2110560126753767, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:59:03.294795+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4783,1773086343.294795036,'{"timestamp": "2026-03-09T20:59:03.294795+0100", "flow_id": 2110562995316305, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T20:59:03.294795+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4784,1773086354.372050046,'{"timestamp": "2026-03-09T20:59:14.372050+0100", "flow_id": 753521717658743, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53421, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51587, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:59:14.372050+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53421, "dest_port": 53}}'); INSERT INTO alerts VALUES(4785,1773086354.372050046,'{"timestamp": "2026-03-09T20:59:14.372050+0100", "flow_id": 753518246610409, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50453, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:59:14.372050+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58176, "dest_port": 53}}'); INSERT INTO alerts VALUES(4786,1773086354.372050046,'{"timestamp": "2026-03-09T20:59:14.372050+0100", "flow_id": 753520132729632, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62279, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:59:14.372050+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62279, "dest_port": 53}}'); INSERT INTO alerts VALUES(4787,1773086354.372051,'{"timestamp": "2026-03-09T20:59:14.372051+0100", "flow_id": 753523844852771, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43202, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T20:59:14.372051+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4788,1773086370.939704895,'{"timestamp": "2026-03-09T20:59:30.939705+0100", "flow_id": 658306009217736, "event_type": "alert", "src_ip": "195.184.76.181", "src_port": 39349, "dest_ip": "134.19.55.199", "dest_port": 5402, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T20:59:30.939705+0100", "src_ip": "195.184.76.181", "dest_ip": "134.19.55.199", "src_port": 39349, "dest_port": 5402}}'); INSERT INTO alerts VALUES(4789,1773086415.476615906,'{"timestamp": "2026-03-09T21:00:15.476616+0100", "flow_id": 2047050445347815, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:00:15.476616+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4790,1773086415.476617098,'{"timestamp": "2026-03-09T21:00:15.476617+0100", "flow_id": 2047057608877649, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:00:15.476617+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4791,1773086424.747287035,'{"timestamp": "2026-03-09T21:00:24.747287+0100", "flow_id": 113349113951282, "event_type": "alert", "src_ip": "167.94.146.35", "src_port": 24275, "dest_ip": "134.19.55.199", "dest_port": 23724, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:00:24.747287+0100", "src_ip": "167.94.146.35", "dest_ip": "134.19.55.199", "src_port": 24275, "dest_port": 23724}}'); INSERT INTO alerts VALUES(4792,1773086428.798950911,'{"timestamp": "2026-03-09T21:00:28.798951+0100", "flow_id": 1179669268386785, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62327, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2533, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:00:28.798951+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62327, "dest_port": 53}}'); INSERT INTO alerts VALUES(4793,1773086428.79928708,'{"timestamp": "2026-03-09T21:00:28.799287+0100", "flow_id": 1181114865363819, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52848, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32468, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:00:28.799287+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52848, "dest_port": 53}}'); INSERT INTO alerts VALUES(4794,1773086429.232609988,'{"timestamp": "2026-03-09T21:00:29.232610+0100", "flow_id": 1562002933995351, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55360, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12480, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:00:29.232610+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55360, "dest_port": 53}}'); INSERT INTO alerts VALUES(4795,1773086429.23261094,'{"timestamp": "2026-03-09T21:00:29.232611+0100", "flow_id": 1562007808433860, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54295, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60965, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:00:29.232611+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54295, "dest_port": 53}}'); INSERT INTO alerts VALUES(4796,1773086432.535418034,'{"timestamp": "2026-03-09T21:00:32.535418+0100", "flow_id": 47804662841249, "event_type": "alert", "src_ip": "198.235.24.241", "src_port": 54605, "dest_ip": "134.19.55.199", "dest_port": 5909, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:00:32.535418+0100", "src_ip": "198.235.24.241", "dest_ip": "134.19.55.199", "src_port": 54605, "dest_port": 5909}}'); INSERT INTO alerts VALUES(4797,1773086433.450371027,'{"timestamp": "2026-03-09T21:00:33.450371+0100", "flow_id": 526956047191742, "event_type": "alert", "src_ip": "205.210.31.56", "src_port": 53109, "dest_ip": "134.19.55.199", "dest_port": 5632, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 30, "bytes_toclient": 0, "start": "2026-03-09T21:00:33.450371+0100", "src_ip": "205.210.31.56", "dest_ip": "134.19.55.199", "src_port": 53109, "dest_port": 5632}}'); INSERT INTO alerts VALUES(4798,1773086445.748354911,'{"timestamp": "2026-03-09T21:00:45.748355+0100", "flow_id": 1525310703131623, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:00:45.748355+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4799,1773086445.748356103,'{"timestamp": "2026-03-09T21:00:45.748356+0100", "flow_id": 1525317866661457, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:00:45.748356+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4800,1773086451.961574078,'{"timestamp": "2026-03-09T21:00:51.961574+0100", "flow_id": 1033704982604248, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 45953, "dest_ip": "134.19.55.199", "dest_port": 2202, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:00:51.961574+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.55.199", "src_port": 45953, "dest_port": 2202}}'); INSERT INTO alerts VALUES(4801,1773086451.961574078,'{"timestamp": "2026-03-09T21:00:51.961574+0100", "flow_id": 1033704982604248, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 45953, "dest_ip": "134.19.55.199", "dest_port": 2202, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:00:51.961574+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.55.199", "src_port": 45953, "dest_port": 2202}}'); INSERT INTO alerts VALUES(4802,1773086462.327239036,'{"timestamp": "2026-03-09T21:01:02.327239+0100", "flow_id": 1968431384235159, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61646, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37784, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:01:02.327239+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61646, "dest_port": 53}}'); INSERT INTO alerts VALUES(4803,1773086462.327239036,'{"timestamp": "2026-03-09T21:01:02.327239+0100", "flow_id": 1968434533587182, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59980, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32925, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:01:02.327239+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59980, "dest_port": 53}}'); INSERT INTO alerts VALUES(4804,1773086477.146696091,'{"timestamp": "2026-03-09T21:01:17.146696+0100", "flow_id": 1474479765183463, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:01:17.146696+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4805,1773086477.146697044,'{"timestamp": "2026-03-09T21:01:17.146697+0100", "flow_id": 1474486928713297, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:01:17.146697+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4806,1773086507.531243085,'{"timestamp": "2026-03-09T21:01:47.531243+0100", "flow_id": 874296740273127, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:01:47.531243+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4807,1773086507.532267093,'{"timestamp": "2026-03-09T21:01:47.532267+0100", "flow_id": 878697655346769, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:01:47.532267+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4808,1773086514.977727891,'{"timestamp": "2026-03-09T21:01:54.977728+0100", "flow_id": 821614270245379, "event_type": "alert", "src_ip": "176.65.132.143", "src_port": 39861, "dest_ip": "134.19.55.199", "dest_port": 15653, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T21:01:54.977728+0100", "src_ip": "176.65.132.143", "dest_ip": "134.19.55.199", "src_port": 39861, "dest_port": 15653}}'); INSERT INTO alerts VALUES(4809,1773086535.659121037,'{"timestamp": "2026-03-09T21:02:15.659121+0100", "flow_id": 1986481135045764, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51966, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24485, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:02:15.659121+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51966, "dest_port": 53}}'); INSERT INTO alerts VALUES(4810,1773086535.66020894,'{"timestamp": "2026-03-09T21:02:15.660209+0100", "flow_id": 1991154874972897, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59842, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25700, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:02:15.660209+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59842, "dest_port": 53}}'); INSERT INTO alerts VALUES(4811,1773086597.968580961,'{"timestamp": "2026-03-09T21:03:17.968581+0100", "flow_id": 1626750882758025, "event_type": "alert", "src_ip": "167.94.146.39", "src_port": 50900, "dest_ip": "134.19.55.199", "dest_port": 28643, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:03:17.968581+0100", "src_ip": "167.94.146.39", "dest_ip": "134.19.55.199", "src_port": 50900, "dest_port": 28643}}'); INSERT INTO alerts VALUES(4812,1773086637.398817062,'{"timestamp": "2026-03-09T21:03:57.398817+0100", "flow_id": 1431434602778080, "event_type": "alert", "src_ip": "167.94.138.175", "src_port": 58172, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 290, "bytes_toclient": 0, "start": "2026-03-09T21:03:57.398817+0100", "src_ip": "167.94.138.175", "dest_ip": "134.19.55.199", "src_port": 58172, "dest_port": 5060}}'); INSERT INTO alerts VALUES(4813,1773086642.195230961,'{"timestamp": "2026-03-09T21:04:02.195231+0100", "flow_id": 838513137806022, "event_type": "alert", "src_ip": "205.210.31.255", "src_port": 56256, "dest_ip": "134.19.55.199", "dest_port": 50995, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:04:02.195231+0100", "src_ip": "205.210.31.255", "dest_ip": "134.19.55.199", "src_port": 56256, "dest_port": 50995}}'); INSERT INTO alerts VALUES(4814,1773086644.10397005,'{"timestamp": "2026-03-09T21:04:04.103970+0100", "flow_id": 1290975165707721, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57697, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40295, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:04:04.103970+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57697, "dest_port": 53}}'); INSERT INTO alerts VALUES(4815,1773086647.363158942,'{"timestamp": "2026-03-09T21:04:07.363159+0100", "flow_id": 2122706407502753, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64392, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29645, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:04:07.363159+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64392, "dest_port": 53}}'); INSERT INTO alerts VALUES(4816,1773086647.363159894,'{"timestamp": "2026-03-09T21:04:07.363160+0100", "flow_id": 2122713508805877, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14827, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:04:07.363160+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59318, "dest_port": 53}}'); INSERT INTO alerts VALUES(4817,1773086657.983202934,'{"timestamp": "2026-03-09T21:04:17.983203+0100", "flow_id": 282177265796466, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62755, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38631, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:04:17.983203+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62755, "dest_port": 53}}'); INSERT INTO alerts VALUES(4818,1773086657.983202934,'{"timestamp": "2026-03-09T21:04:17.983203+0100", "flow_id": 282175205533509, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56800, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50463, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:04:17.983203+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56800, "dest_port": 53}}'); INSERT INTO alerts VALUES(4819,1773086658.728281022,'{"timestamp": "2026-03-09T21:04:18.728281+0100", "flow_id": 594669275303417, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51948, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 322, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:04:18.728281+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51948, "dest_port": 53}}'); INSERT INTO alerts VALUES(4820,1773086658.728281974,'{"timestamp": "2026-03-09T21:04:18.728282+0100", "flow_id": 594675831922260, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60344, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27019, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:04:18.728282+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60344, "dest_port": 53}}'); INSERT INTO alerts VALUES(4821,1773086659.687061071,'{"timestamp": "2026-03-09T21:04:19.687061+0100", "flow_id": 980579714122963, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50290, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63913, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T21:04:19.687061+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50290, "dest_port": 53}}'); INSERT INTO alerts VALUES(4822,1773086668.866075039,'{"timestamp": "2026-03-09T21:04:28.866075+0100", "flow_id": 1186489838512690, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50683, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62921, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T21:04:28.866075+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50683, "dest_port": 53}}'); INSERT INTO alerts VALUES(4823,1773086680.58475399,'{"timestamp": "2026-03-09T21:04:40.584754+0100", "flow_id": 259700809133253, "event_type": "alert", "src_ip": "192.109.200.81", "src_port": 42629, "dest_ip": "134.19.55.199", "dest_port": 8000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400037, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 38", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T21:04:40.584754+0100", "src_ip": "192.109.200.81", "dest_ip": "134.19.55.199", "src_port": 42629, "dest_port": 8000}}'); INSERT INTO alerts VALUES(4824,1773086681.396518945,'{"timestamp": "2026-03-09T21:04:41.396519+0100", "flow_id": 295665318378287, "event_type": "alert", "src_ip": "198.235.24.197", "src_port": 51618, "dest_ip": "134.19.55.199", "dest_port": 50996, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:04:41.396519+0100", "src_ip": "198.235.24.197", "dest_ip": "134.19.55.199", "src_port": 51618, "dest_port": 50996}}'); INSERT INTO alerts VALUES(4825,1773086723.025748969,'{"timestamp": "2026-03-09T21:05:23.025749+0100", "flow_id": 955017827775344, "event_type": "alert", "src_ip": "176.65.148.4", "src_port": 54189, "dest_ip": "134.19.55.199", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:05:23.025749+0100", "src_ip": "176.65.148.4", "dest_ip": "134.19.55.199", "src_port": 54189, "dest_port": 25565}}'); INSERT INTO alerts VALUES(4826,1773086723.025748969,'{"timestamp": "2026-03-09T21:05:23.025749+0100", "flow_id": 955017827775344, "event_type": "alert", "src_ip": "176.65.148.4", "src_port": 54189, "dest_ip": "134.19.55.199", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:05:23.025749+0100", "src_ip": "176.65.148.4", "dest_ip": "134.19.55.199", "src_port": 54189, "dest_port": 25565}}'); INSERT INTO alerts VALUES(4827,1773086735.177954912,'{"timestamp": "2026-03-09T21:05:35.177955+0100", "flow_id": 2171686540643331, "event_type": "alert", "src_ip": "147.185.132.115", "src_port": 47176, "dest_ip": "134.19.55.199", "dest_port": 53413, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 42, "bytes_toclient": 0, "start": "2026-03-09T21:05:35.177955+0100", "src_ip": "147.185.132.115", "dest_ip": "134.19.55.199", "src_port": 47176, "dest_port": 53413}}'); INSERT INTO alerts VALUES(4828,1773086738.614944935,'{"timestamp": "2026-03-09T21:05:38.614945+0100", "flow_id": 670845888518073, "event_type": "alert", "src_ip": "167.94.146.40", "src_port": 11295, "dest_ip": "134.19.55.199", "dest_port": 1419, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:05:38.614945+0100", "src_ip": "167.94.146.40", "dest_ip": "134.19.55.199", "src_port": 11295, "dest_port": 1419}}'); INSERT INTO alerts VALUES(4829,1773086752.301321029,'{"timestamp": "2026-03-09T21:05:52.301321+0100", "flow_id": 67906779192509, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53234, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:05:52.277954+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 53234, "dest_port": 853}}'); INSERT INTO alerts VALUES(4830,1773086752.310971975,'{"timestamp": "2026-03-09T21:05:52.310972+0100", "flow_id": 114391361142233, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 57024, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:05:52.288777+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 57024, "dest_port": 853}}'); INSERT INTO alerts VALUES(4831,1773086752.327256917,'{"timestamp": "2026-03-09T21:05:52.327257+0100", "flow_id": 194356037024067, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53244, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:05:52.307396+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 53244, "dest_port": 853}}'); INSERT INTO alerts VALUES(4832,1773086754.622972965,'{"timestamp": "2026-03-09T21:05:54.622973+0100", "flow_id": 705324136913895, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:05:54.622973+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4833,1773086754.626070022,'{"timestamp": "2026-03-09T21:05:54.626070+0100", "flow_id": 718628519192145, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:05:54.626070+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4834,1773086785.574604989,'{"timestamp": "2026-03-09T21:06:25.574605+0100", "flow_id": 497588204789750, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56964, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49334, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:06:25.574605+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56964, "dest_port": 53}}'); INSERT INTO alerts VALUES(4835,1773086785.574604989,'{"timestamp": "2026-03-09T21:06:25.574605+0100", "flow_id": 497585642362148, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55968, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49387, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:06:25.574605+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55968, "dest_port": 53}}'); INSERT INTO alerts VALUES(4836,1773086795.250824929,'{"timestamp": "2026-03-09T21:06:35.250825+0100", "flow_id": 1077288587592018, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65140, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42838, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:06:35.250825+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65140, "dest_port": 53}}'); INSERT INTO alerts VALUES(4837,1773086795.250824929,'{"timestamp": "2026-03-09T21:06:35.250825+0100", "flow_id": 1077287897868727, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61447, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:06:35.250825+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61447, "dest_port": 53}}'); INSERT INTO alerts VALUES(4838,1773086831.211626052,'{"timestamp": "2026-03-09T21:07:11.211626+0100", "flow_id": 2034828383381469, "event_type": "alert", "src_ip": "91.196.152.223", "src_port": 20587, "dest_ip": "134.19.55.199", "dest_port": 20164, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:07:11.211626+0100", "src_ip": "91.196.152.223", "dest_ip": "134.19.55.199", "src_port": 20587, "dest_port": 20164}}'); INSERT INTO alerts VALUES(4839,1773086839.792126894,'{"timestamp": "2026-03-09T21:07:19.792127+0100", "flow_id": 1994784988322791, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:07:19.792127+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4840,1773086839.792128086,'{"timestamp": "2026-03-09T21:07:19.792128+0100", "flow_id": 1994792151852625, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:07:19.792128+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4841,1773086845.56774211,'{"timestamp": "2026-03-09T21:07:25.567742+0100", "flow_id": 1594011953022968, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55123, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38905, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:07:25.567742+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55123, "dest_port": 53}}'); INSERT INTO alerts VALUES(4842,1773086870.382169009,'{"timestamp": "2026-03-09T21:07:50.382169+0100", "flow_id": 1922878645853159, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:07:50.382169+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4843,1773086870.382169009,'{"timestamp": "2026-03-09T21:07:50.382169+0100", "flow_id": 1922881514415697, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:07:50.382169+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4844,1773086872.303215027,'{"timestamp": "2026-03-09T21:07:52.303215+0100", "flow_id": 87578696265968, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 36184, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:07:52.282535+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 36184, "dest_port": 853}}'); INSERT INTO alerts VALUES(4845,1773086872.314214944,'{"timestamp": "2026-03-09T21:07:52.314215+0100", "flow_id": 131891406381651, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 57066, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:07:52.292852+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 57066, "dest_port": 853}}'); INSERT INTO alerts VALUES(4846,1773086872.330692053,'{"timestamp": "2026-03-09T21:07:52.330692+0100", "flow_id": 206249867260734, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 57082, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:07:52.310165+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 57082, "dest_port": 853}}'); INSERT INTO alerts VALUES(4847,1773086873.646264076,'{"timestamp": "2026-03-09T21:07:53.646264+0100", "flow_id": 429149862878169, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 57088, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:07:53.624207+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 57088, "dest_port": 853}}'); INSERT INTO alerts VALUES(4848,1773086881.36939907,'{"timestamp": "2026-03-09T21:08:01.369399+0100", "flow_id": 460659346924371, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 42914, "dest_ip": "134.19.55.199", "dest_port": 64680, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:08:01.369399+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 42914, "dest_port": 64680}}'); INSERT INTO alerts VALUES(4849,1773086900.576232911,'{"timestamp": "2026-03-09T21:08:20.576233+0100", "flow_id": 1349002295630823, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:08:20.576233+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4850,1773086900.576232911,'{"timestamp": "2026-03-09T21:08:20.576233+0100", "flow_id": 1349005164193361, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:08:20.576233+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4851,1773086931.479737044,'{"timestamp": "2026-03-09T21:08:51.479737+0100", "flow_id": 934555131436007, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:08:51.479737+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4852,1773086931.479737044,'{"timestamp": "2026-03-09T21:08:51.479737+0100", "flow_id": 934557999998545, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:08:51.479737+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4853,1773086946.395617009,'{"timestamp": "2026-03-09T21:09:06.395617+0100", "flow_id": 573265402068213, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14827, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:09:06.395617+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59318, "dest_port": 53}}'); INSERT INTO alerts VALUES(4854,1773086946.395617962,'{"timestamp": "2026-03-09T21:09:06.395618+0100", "flow_id": 573270025455608, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55123, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38905, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:09:06.395618+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55123, "dest_port": 53}}'); INSERT INTO alerts VALUES(4855,1773086951.436443091,'{"timestamp": "2026-03-09T21:09:11.436443+0100", "flow_id": 2155985067245385, "event_type": "alert", "src_ip": "195.184.76.215", "src_port": 15493, "dest_ip": "134.19.55.199", "dest_port": 7024, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:09:11.436443+0100", "src_ip": "195.184.76.215", "dest_ip": "134.19.55.199", "src_port": 15493, "dest_port": 7024}}'); INSERT INTO alerts VALUES(4856,1773086962.73042488,'{"timestamp": "2026-03-09T21:09:22.730425+0100", "flow_id": 603877009382375, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:09:22.730425+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4857,1773086962.730426074,'{"timestamp": "2026-03-09T21:09:22.730426+0100", "flow_id": 603884172912209, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:09:22.730426+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4858,1773086987.689727067,'{"timestamp": "2026-03-09T21:09:47.689727+0100", "flow_id": 348930755680913, "event_type": "alert", "src_ip": "162.241.148.243", "src_port": 80, "dest_ip": "192.168.2.37", "dest_port": 51563, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2039070, "rev": 1, "signature": "ET INFO 404 Response with Javascript Variable in Page", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2022_09_30"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2022_09_30"]}}, "ts_progress": "request_complete", "tc_progress": "response_complete", "http": {"hostname": "www.gjesr.com", "url": "/favicon.ico", "http_user_agent": "Mozilla/5.0 (iPhone; CPU iPhone OS 16_7_14 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6.1 Mobile/15E148 Safari/604.1", "http_content_type": "text/html", "http_refer": "http://www.gjesr.com/Issues%20PDF/Archive-2016/August-2016/2.pdf", "http_method": "GET", "protocol": "HTTP/1.1", "status": 404, "length": 358}, "files": [{"filename": "/favicon.ico", "gaps": false, "state": "CLOSED", "stored": false, "size": 583, "tx_id": 0}], "app_proto": "http", "direction": "to_client", "flow": {"pkts_toserver": 3, "pkts_toclient": 3, "bytes_toserver": 549, "bytes_toclient": 768, "start": "2026-03-09T21:09:45.671065+0100", "src_ip": "192.168.2.37", "dest_ip": "162.241.148.243", "src_port": 51563, "dest_port": 80}}'); INSERT INTO alerts VALUES(4859,1773086992.310897112,'{"timestamp": "2026-03-09T21:09:52.310897+0100", "flow_id": 108795298160057, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 46240, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:09:52.287474+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 46240, "dest_port": 853}}'); INSERT INTO alerts VALUES(4860,1773086993.647300958,'{"timestamp": "2026-03-09T21:09:53.647301+0100", "flow_id": 441834786142275, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 35462, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:09:53.627160+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 35462, "dest_port": 853}}'); INSERT INTO alerts VALUES(4861,1773086993.830045939,'{"timestamp": "2026-03-09T21:09:53.830046+0100", "flow_id": 468795992955879, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:09:53.830046+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4862,1773086993.830045939,'{"timestamp": "2026-03-09T21:09:53.830046+0100", "flow_id": 468798861518417, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:09:53.830046+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4863,1773087006.033682108,'{"timestamp": "2026-03-09T21:10:06.033682+0100", "flow_id": 1833515738945815, "event_type": "alert", "src_ip": "91.196.152.215", "src_port": 45240, "dest_ip": "134.19.55.199", "dest_port": 2157, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:10:06.033682+0100", "src_ip": "91.196.152.215", "dest_ip": "134.19.55.199", "src_port": 45240, "dest_port": 2157}}'); INSERT INTO alerts VALUES(4864,1773087009.583702087,'{"timestamp": "2026-03-09T21:10:09.583702+0100", "flow_id": 536657605417748, "event_type": "alert", "src_ip": "195.184.76.71", "src_port": 61081, "dest_ip": "134.19.55.199", "dest_port": 6888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:10:09.583702+0100", "src_ip": "195.184.76.71", "dest_ip": "134.19.55.199", "src_port": 61081, "dest_port": 6888}}'); INSERT INTO alerts VALUES(4865,1773087022.280267954,'{"timestamp": "2026-03-09T21:10:22.280268+0100", "flow_id": 1766694022076867, "event_type": "alert", "src_ip": "176.65.139.28", "src_port": 48253, "dest_ip": "134.19.55.199", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 57, "bytes_toclient": 0, "start": "2026-03-09T21:10:22.280268+0100", "src_ip": "176.65.139.28", "dest_ip": "134.19.55.199", "src_port": 48253, "dest_port": 53}}'); INSERT INTO alerts VALUES(4866,1773087022.953871965,'{"timestamp": "2026-03-09T21:10:22.953872+0100", "flow_id": 1845053244423085, "event_type": "alert", "src_ip": "195.184.76.207", "src_port": 1257, "dest_ip": "134.19.55.199", "dest_port": 6146, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:10:22.953872+0100", "src_ip": "195.184.76.207", "dest_ip": "134.19.55.199", "src_port": 1257, "dest_port": 6146}}'); INSERT INTO alerts VALUES(4867,1773087024.497888088,'{"timestamp": "2026-03-09T21:10:24.497888+0100", "flow_id": 168088152693735, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:10:24.497888+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4868,1773087024.497889041,'{"timestamp": "2026-03-09T21:10:24.497889+0100", "flow_id": 168095316223569, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:10:24.497889+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4869,1773087031.423007011,'{"timestamp": "2026-03-09T21:10:31.423007+0100", "flow_id": 2098280243447482, "event_type": "alert", "src_ip": "195.184.76.23", "src_port": 51880, "dest_ip": "134.19.55.199", "dest_port": 6014, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:10:31.423007+0100", "src_ip": "195.184.76.23", "dest_ip": "134.19.55.199", "src_port": 51880, "dest_port": 6014}}'); INSERT INTO alerts VALUES(4870,1773087040.795877933,'{"timestamp": "2026-03-09T21:10:40.795878+0100", "flow_id": 40570375856206, "event_type": "alert", "src_ip": "91.196.152.127", "src_port": 35013, "dest_ip": "134.19.55.199", "dest_port": 20111, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:10:40.795878+0100", "src_ip": "91.196.152.127", "dest_ip": "134.19.55.199", "src_port": 35013, "dest_port": 20111}}'); INSERT INTO alerts VALUES(4871,1773087047.583316087,'{"timestamp": "2026-03-09T21:10:47.583316+0100", "flow_id": 2223851582095698, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65140, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42838, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:10:47.583316+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65140, "dest_port": 53}}'); INSERT INTO alerts VALUES(4872,1773087047.583317041,'{"timestamp": "2026-03-09T21:10:47.583317+0100", "flow_id": 2223855187339703, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61447, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:10:47.583317+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61447, "dest_port": 53}}'); INSERT INTO alerts VALUES(4873,1773087047.583317041,'{"timestamp": "2026-03-09T21:10:47.583317+0100", "flow_id": 2223852965541202, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63417, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52947, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:10:47.583317+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63417, "dest_port": 53}}'); INSERT INTO alerts VALUES(4874,1773087047.583317041,'{"timestamp": "2026-03-09T21:10:47.583317+0100", "flow_id": 2223855466952019, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57646, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40202, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:10:47.583317+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57646, "dest_port": 53}}'); INSERT INTO alerts VALUES(4875,1773087047.592339038,'{"timestamp": "2026-03-09T21:10:47.592339+0100", "flow_id": 1981130034008508, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64757, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:10:47.592339+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64757, "dest_port": 53}}'); INSERT INTO alerts VALUES(4876,1773087047.592339038,'{"timestamp": "2026-03-09T21:10:47.592339+0100", "flow_id": 1981128484793603, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56347, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14124, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:10:47.592339+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56347, "dest_port": 53}}'); INSERT INTO alerts VALUES(4877,1773087055.909471989,'{"timestamp": "2026-03-09T21:10:55.909472+0100", "flow_id": 2217302948961255, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:10:55.909472+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4878,1773087055.909471989,'{"timestamp": "2026-03-09T21:10:55.909472+0100", "flow_id": 2217305817523793, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:10:55.909472+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4879,1773087057.581711054,'{"timestamp": "2026-03-09T21:10:57.581711+0100", "flow_id": 528108746813196, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61183, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59912, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:10:57.581711+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61183, "dest_port": 53}}'); INSERT INTO alerts VALUES(4880,1773087086.24465394,'{"timestamp": "2026-03-09T21:11:26.244654+0100", "flow_id": 1895206171565031, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:11:26.244654+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4881,1773087086.24465394,'{"timestamp": "2026-03-09T21:11:26.244654+0100", "flow_id": 1895209040127569, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:11:26.244654+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4882,1773087086.902493953,'{"timestamp": "2026-03-09T21:11:26.902494+0100", "flow_id": 1905858223185990, "event_type": "alert", "src_ip": "147.185.132.137", "src_port": 57339, "dest_ip": "134.19.55.199", "dest_port": 30930, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:11:26.902494+0100", "src_ip": "147.185.132.137", "dest_ip": "134.19.55.199", "src_port": 57339, "dest_port": 30930}}'); INSERT INTO alerts VALUES(4883,1773087113.653280974,'{"timestamp": "2026-03-09T21:11:53.653281+0100", "flow_id": 458564129891572, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 54330, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:11:53.631055+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 54330, "dest_port": 853}}'); INSERT INTO alerts VALUES(4884,1773087117.475528956,'{"timestamp": "2026-03-09T21:11:57.475529+0100", "flow_id": 1479431862475751, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:11:57.475529+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4885,1773087117.475528956,'{"timestamp": "2026-03-09T21:11:57.475529+0100", "flow_id": 1479434731038289, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:11:57.475529+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4886,1773087144.228842974,'{"timestamp": "2026-03-09T21:12:24.228843+0100", "flow_id": 138450946297166, "event_type": "alert", "src_ip": "79.124.62.178", "src_port": 56324, "dest_ip": "134.19.55.199", "dest_port": 13390, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:12:24.228843+0100", "src_ip": "79.124.62.178", "dest_ip": "134.19.55.199", "src_port": 56324, "dest_port": 13390}}'); INSERT INTO alerts VALUES(4887,1773087147.673578023,'{"timestamp": "2026-03-09T21:12:27.673578+0100", "flow_id": 922670956927975, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:12:27.673578+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4888,1773087147.673578978,'{"timestamp": "2026-03-09T21:12:27.673579+0100", "flow_id": 922678120457809, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:12:27.673579+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4889,1773087148.36779499,'{"timestamp": "2026-03-09T21:12:28.367795+0100", "flow_id": 1298195715535263, "event_type": "alert", "src_ip": "195.184.76.247", "src_port": 44906, "dest_ip": "134.19.55.199", "dest_port": 7071, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:12:28.367795+0100", "src_ip": "195.184.76.247", "dest_ip": "134.19.55.199", "src_port": 44906, "dest_port": 7071}}'); INSERT INTO alerts VALUES(4890,1773087161.805850982,'{"timestamp": "2026-03-09T21:12:41.805851+0100", "flow_id": 364882809696012, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61183, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59912, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:12:41.805851+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61183, "dest_port": 53}}'); INSERT INTO alerts VALUES(4891,1773087161.805851936,'{"timestamp": "2026-03-09T21:12:41.805852+0100", "flow_id": 364883745650002, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63417, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52947, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:12:41.805852+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63417, "dest_port": 53}}'); INSERT INTO alerts VALUES(4892,1773087161.805851936,'{"timestamp": "2026-03-09T21:12:41.805852+0100", "flow_id": 364886595883452, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64757, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30366, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:12:41.805852+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64757, "dest_port": 53}}'); INSERT INTO alerts VALUES(4893,1773087161.805851936,'{"timestamp": "2026-03-09T21:12:41.805852+0100", "flow_id": 364885046668547, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56347, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14124, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:12:41.805852+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56347, "dest_port": 53}}'); INSERT INTO alerts VALUES(4894,1773087161.805852891,'{"timestamp": "2026-03-09T21:12:41.805853+0100", "flow_id": 364887972199623, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51444, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45258, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:12:41.805853+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51444, "dest_port": 53}}'); INSERT INTO alerts VALUES(4895,1773087161.805852891,'{"timestamp": "2026-03-09T21:12:41.805853+0100", "flow_id": 364889156168952, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55537, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60183, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:12:41.805853+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55537, "dest_port": 53}}'); INSERT INTO alerts VALUES(4896,1773087161.805852891,'{"timestamp": "2026-03-09T21:12:41.805853+0100", "flow_id": 364887701384143, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64592, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45478, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:12:41.805853+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64592, "dest_port": 53}}'); INSERT INTO alerts VALUES(4897,1773087161.806437016,'{"timestamp": "2026-03-09T21:12:41.806437+0100", "flow_id": 367395916497160, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63687, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:12:41.806437+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63687, "dest_port": 53}}'); INSERT INTO alerts VALUES(4898,1773087171.596748113,'{"timestamp": "2026-03-09T21:12:51.596748+0100", "flow_id": 874166515858677, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14827, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:12:51.596748+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59318, "dest_port": 53}}'); INSERT INTO alerts VALUES(4899,1773087177.766968966,'{"timestamp": "2026-03-09T21:12:57.766969+0100", "flow_id": 479357317536743, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:12:57.766969+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4900,1773087177.768311024,'{"timestamp": "2026-03-09T21:12:57.768311+0100", "flow_id": 485124032210513, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:12:57.768311+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4901,1773087202.754844904,'{"timestamp": "2026-03-09T21:13:22.754845+0100", "flow_id": 708763030322421, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14827, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:13:22.754845+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59318, "dest_port": 53}}'); INSERT INTO alerts VALUES(4902,1773087209.122536898,'{"timestamp": "2026-03-09T21:13:29.122537+0100", "flow_id": 526292720147431, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:13:29.122537+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4903,1773087209.122538089,'{"timestamp": "2026-03-09T21:13:29.122538+0100", "flow_id": 526299883677265, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:13:29.122538+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4904,1773087212.221117973,'{"timestamp": "2026-03-09T21:13:32.221118+0100", "flow_id": 1231170503924241, "event_type": "alert", "src_ip": "147.185.132.197", "src_port": 54697, "dest_ip": "134.19.55.199", "dest_port": 458, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:13:32.221118+0100", "src_ip": "147.185.132.197", "dest_ip": "134.19.55.199", "src_port": 54697, "dest_port": 458}}'); INSERT INTO alerts VALUES(4905,1773087224.692451953,'{"timestamp": "2026-03-09T21:13:44.692452+0100", "flow_id": 159310585658498, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65249, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:13:44.692452+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4906,1773087227.120682955,'{"timestamp": "2026-03-09T21:13:47.120683+0100", "flow_id": 1081282465516644, "event_type": "alert", "src_ip": "195.184.76.95", "src_port": 5758, "dest_ip": "134.19.55.199", "dest_port": 8066, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:13:47.120683+0100", "src_ip": "195.184.76.95", "dest_ip": "134.19.55.199", "src_port": 5758, "dest_port": 8066}}'); INSERT INTO alerts VALUES(4907,1773087233.655456066,'{"timestamp": "2026-03-09T21:13:53.655456+0100", "flow_id": 474228851694239, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 37282, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:13:53.634703+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 37282, "dest_port": 853}}'); INSERT INTO alerts VALUES(4908,1773087240.337450982,'{"timestamp": "2026-03-09T21:14:00.337451+0100", "flow_id": 41966438046695, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:14:00.337451+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4909,1773087240.337451935,'{"timestamp": "2026-03-09T21:14:00.337452+0100", "flow_id": 41973601576529, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:14:00.337452+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4910,1773087266.781095027,'{"timestamp": "2026-03-09T21:14:26.781095+0100", "flow_id": 821506185446460, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50067, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:14:26.781095+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50067, "dest_port": 53}}'); INSERT INTO alerts VALUES(4911,1773087271.77560997,'{"timestamp": "2026-03-09T21:14:31.775610+0100", "flow_id": 2205319990205415, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:14:31.775610+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4912,1773087271.775610923,'{"timestamp": "2026-03-09T21:14:31.775611+0100", "flow_id": 2205327153735249, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:14:31.775611+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4913,1773087278.153438092,'{"timestamp": "2026-03-09T21:14:38.153438+0100", "flow_id": 1784914416725902, "event_type": "alert", "src_ip": "198.235.24.37", "src_port": 52129, "dest_ip": "134.19.55.199", "dest_port": 8282, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:14:38.153438+0100", "src_ip": "198.235.24.37", "dest_ip": "134.19.55.199", "src_port": 52129, "dest_port": 8282}}'); INSERT INTO alerts VALUES(4914,1773087279.149604083,'{"timestamp": "2026-03-09T21:14:39.149604+0100", "flow_id": 2049919311448658, "event_type": "alert", "src_ip": "167.94.138.131", "src_port": 14038, "dest_ip": "134.19.55.199", "dest_port": 808, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:14:39.149604+0100", "src_ip": "167.94.138.131", "dest_ip": "134.19.55.199", "src_port": 14038, "dest_port": 808}}'); INSERT INTO alerts VALUES(4915,1773087279.839088916,'{"timestamp": "2026-03-09T21:14:39.839089+0100", "flow_id": 2196486183709084, "event_type": "alert", "src_ip": "167.94.146.38", "src_port": 58150, "dest_ip": "134.19.55.199", "dest_port": 3914, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:14:39.839089+0100", "src_ip": "167.94.146.38", "dest_ip": "134.19.55.199", "src_port": 58150, "dest_port": 3914}}'); INSERT INTO alerts VALUES(4916,1773087282.220086097,'{"timestamp": "2026-03-09T21:14:42.220086+0100", "flow_id": 663787631230151, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51444, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45258, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:14:42.220086+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51444, "dest_port": 53}}'); INSERT INTO alerts VALUES(4917,1773087282.220086097,'{"timestamp": "2026-03-09T21:14:42.220086+0100", "flow_id": 663789058901149, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53829, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41538, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:14:42.220086+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53829, "dest_port": 53}}'); INSERT INTO alerts VALUES(4918,1773087282.220571994,'{"timestamp": "2026-03-09T21:14:42.220572+0100", "flow_id": 665875409582635, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61962, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2626, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:14:42.220572+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61962, "dest_port": 53}}'); INSERT INTO alerts VALUES(4919,1773087282.220571994,'{"timestamp": "2026-03-09T21:14:42.220572+0100", "flow_id": 665876287479327, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62260, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25688, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:14:42.220572+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62260, "dest_port": 53}}'); INSERT INTO alerts VALUES(4920,1773087283.487458945,'{"timestamp": "2026-03-09T21:14:43.487459+0100", "flow_id": 967723292522962, "event_type": "alert", "src_ip": "178.20.210.151", "src_port": 43978, "dest_ip": "134.19.55.199", "dest_port": 2332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:14:43.487459+0100", "src_ip": "178.20.210.151", "dest_ip": "134.19.55.199", "src_port": 43978, "dest_port": 2332}}'); INSERT INTO alerts VALUES(4921,1773087285.640225887,'{"timestamp": "2026-03-09T21:14:45.640226+0100", "flow_id": 1623853057375477, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14827, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:14:45.640226+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59318, "dest_port": 53}}'); INSERT INTO alerts VALUES(4922,1773087288.038995981,'{"timestamp": "2026-03-09T21:14:48.038996+0100", "flow_id": 167488203390082, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65249, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:14:48.038996+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4923,1773087302.137761116,'{"timestamp": "2026-03-09T21:15:02.137761+0100", "flow_id": 1717579209104359, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:15:02.137761+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4924,1773087302.137761116,'{"timestamp": "2026-03-09T21:15:02.137761+0100", "flow_id": 1717582077666897, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:15:02.137761+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4925,1773087313.148684979,'{"timestamp": "2026-03-09T21:15:13.148685+0100", "flow_id": 357126050904002, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61193, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6367, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:15:13.148685+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61193, "dest_port": 53}}'); INSERT INTO alerts VALUES(4926,1773087315.916121007,'{"timestamp": "2026-03-09T21:15:15.916121+0100", "flow_id": 1119963199241461, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14827, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:15:15.916121+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59318, "dest_port": 53}}'); INSERT INTO alerts VALUES(4927,1773087318.333865881,'{"timestamp": "2026-03-09T21:15:18.333866+0100", "flow_id": 1715420186672258, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65249, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:15:18.333866+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4928,1773087333.131712914,'{"timestamp": "2026-03-09T21:15:33.131713+0100", "flow_id": 1410128270187495, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:15:33.131713+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4929,1773087333.131714105,'{"timestamp": "2026-03-09T21:15:33.131714+0100", "flow_id": 1410135433717329, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:15:33.131714+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4930,1773087347.038352966,'{"timestamp": "2026-03-09T21:15:47.038353+0100", "flow_id": 1009153043004661, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14827, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:15:47.038353+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59318, "dest_port": 53}}'); INSERT INTO alerts VALUES(4931,1773087349.125792981,'{"timestamp": "2026-03-09T21:15:49.125793+0100", "flow_id": 1666178386623618, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54632, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65249, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:15:49.125793+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54632, "dest_port": 53}}'); INSERT INTO alerts VALUES(4932,1773087353.662254095,'{"timestamp": "2026-03-09T21:15:53.662254+0100", "flow_id": 506052760303629, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 52130, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:15:53.642112+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 52130, "dest_port": 853}}'); INSERT INTO alerts VALUES(4933,1773087363.767525911,'{"timestamp": "2026-03-09T21:16:03.767526+0100", "flow_id": 1044699567741927, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:16:03.767526+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4934,1773087363.767525911,'{"timestamp": "2026-03-09T21:16:03.767526+0100", "flow_id": 1044702436304465, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:16:03.767526+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4935,1773087377.916196107,'{"timestamp": "2026-03-09T21:16:17.916196+0100", "flow_id": 557335368367349, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14827, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:16:17.916196+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59318, "dest_port": 53}}'); INSERT INTO alerts VALUES(4936,1773087384.528645039,'{"timestamp": "2026-03-09T21:16:24.528645+0100", "flow_id": 18714804317543, "event_type": "alert", "src_ip": "205.210.31.89", "src_port": 39325, "dest_ip": "134.19.55.199", "dest_port": 13446, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T21:16:24.528645+0100", "src_ip": "205.210.31.89", "dest_ip": "134.19.55.199", "src_port": 39325, "dest_port": 13446}}'); INSERT INTO alerts VALUES(4937,1773087394.770898104,'{"timestamp": "2026-03-09T21:16:34.770898+0100", "flow_id": 777707220753383, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:16:34.770898+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4938,1773087394.770898104,'{"timestamp": "2026-03-09T21:16:34.770898+0100", "flow_id": 777710089315921, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:16:34.770898+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4939,1773087425.947742939,'{"timestamp": "2026-03-09T21:17:05.947743+0100", "flow_id": 411350805371879, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:17:05.947743+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4940,1773087425.947742939,'{"timestamp": "2026-03-09T21:17:05.947743+0100", "flow_id": 411353673934417, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:17:05.947743+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4941,1773087430.569803954,'{"timestamp": "2026-03-09T21:17:10.569804+0100", "flow_id": 1884342351143665, "event_type": "alert", "src_ip": "193.163.125.193", "src_port": 47876, "dest_ip": "134.19.55.199", "dest_port": 2086, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:17:10.569804+0100", "src_ip": "193.163.125.193", "dest_ip": "134.19.55.199", "src_port": 47876, "dest_port": 2086}}'); INSERT INTO alerts VALUES(4942,1773087442.123939991,'{"timestamp": "2026-03-09T21:17:22.123940+0100", "flow_id": 813796455546101, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14827, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:17:22.123940+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59318, "dest_port": 53}}'); INSERT INTO alerts VALUES(4943,1773087456.888138055,'{"timestamp": "2026-03-09T21:17:36.888138+0100", "flow_id": 155349279693799, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:17:36.888138+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4944,1773087456.888138055,'{"timestamp": "2026-03-09T21:17:36.888138+0100", "flow_id": 155352148256337, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:17:36.888138+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4945,1773087467.700261117,'{"timestamp": "2026-03-09T21:17:47.700261+0100", "flow_id": 948171376600686, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53982, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:17:47.679515+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 53982, "dest_port": 853}}'); INSERT INTO alerts VALUES(4946,1773087470.294640065,'{"timestamp": "2026-03-09T21:17:50.294640+0100", "flow_id": 1828423084848809, "event_type": "alert", "src_ip": "205.210.31.83", "src_port": 50875, "dest_ip": "134.19.55.199", "dest_port": 987, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:17:50.294640+0100", "src_ip": "205.210.31.83", "dest_ip": "134.19.55.199", "src_port": 50875, "dest_port": 987}}'); INSERT INTO alerts VALUES(4947,1773087476.563272954,'{"timestamp": "2026-03-09T21:17:56.563273+0100", "flow_id": 1293339542923887, "event_type": "alert", "src_ip": "147.185.132.244", "src_port": 53119, "dest_ip": "134.19.55.199", "dest_port": 25366, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:17:56.563273+0100", "src_ip": "147.185.132.244", "dest_ip": "134.19.55.199", "src_port": 53119, "dest_port": 25366}}'); INSERT INTO alerts VALUES(4948,1773087480.65574789,'{"timestamp": "2026-03-09T21:18:00.655748+0100", "flow_id": 1670557045463, "event_type": "alert", "src_ip": "185.242.3.211", "src_port": 45749, "dest_ip": "134.19.55.199", "dest_port": 21234, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:18:00.655748+0100", "src_ip": "185.242.3.211", "dest_ip": "134.19.55.199", "src_port": 45749, "dest_port": 21234}}'); INSERT INTO alerts VALUES(4949,1773087504.584357024,'{"timestamp": "2026-03-09T21:18:24.584357+0100", "flow_id": 257996080534176, "event_type": "alert", "src_ip": "46.151.182.45", "src_port": 35599, "dest_ip": "134.19.55.199", "dest_port": 8443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T21:18:24.584357+0100", "src_ip": "46.151.182.45", "dest_ip": "134.19.55.199", "src_port": 35599, "dest_port": 8443}}'); INSERT INTO alerts VALUES(4950,1773087527.002274991,'{"timestamp": "2026-03-09T21:18:47.002275+0100", "flow_id": 1980096200170471, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:18:47.002275+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4951,1773087527.002275943,'{"timestamp": "2026-03-09T21:18:47.002276+0100", "flow_id": 1980103363700305, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:18:47.002276+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4952,1773087528.538943052,'{"timestamp": "2026-03-09T21:18:48.538943+0100", "flow_id": 62945745446481, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 38131, "dest_ip": "134.19.55.199", "dest_port": 47204, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:18:48.538943+0100", "src_ip": "167.94.146.37", "dest_ip": "134.19.55.199", "src_port": 38131, "dest_port": 47204}}'); INSERT INTO alerts VALUES(4953,1773087534.194663048,'{"timestamp": "2026-03-09T21:18:54.194663+0100", "flow_id": 1961972463836847, "event_type": "alert", "src_ip": "198.235.24.95", "src_port": 49606, "dest_ip": "134.19.55.199", "dest_port": 3493, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:18:54.194663+0100", "src_ip": "198.235.24.95", "dest_ip": "134.19.55.199", "src_port": 49606, "dest_port": 3493}}'); INSERT INTO alerts VALUES(4954,1773087541.446301938,'{"timestamp": "2026-03-09T21:19:01.446302+0100", "flow_id": 1635380906299938, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50487, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42382, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:19:01.446302+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50487, "dest_port": 53}}'); INSERT INTO alerts VALUES(4955,1773087542.090502977,'{"timestamp": "2026-03-09T21:19:02.090503+0100", "flow_id": 1713264349667227, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53474, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:19:02.071220+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 53474, "dest_port": 853}}'); INSERT INTO alerts VALUES(4956,1773087542.202445031,'{"timestamp": "2026-03-09T21:19:02.202445+0100", "flow_id": 1902172561829222, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53478, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:19:02.180740+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 53478, "dest_port": 853}}'); INSERT INTO alerts VALUES(4957,1773087548.453716993,'{"timestamp": "2026-03-09T21:19:08.453717+0100", "flow_id": 1289645456015990, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53494, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:19:08.431340+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 53494, "dest_port": 853}}'); INSERT INTO alerts VALUES(4958,1773087558.488241911,'{"timestamp": "2026-03-09T21:19:18.488242+0100", "flow_id": 1815508758420455, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:19:18.488242+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4959,1773087558.488243104,'{"timestamp": "2026-03-09T21:19:18.488243+0100", "flow_id": 1815515921950289, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:19:18.488243+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4960,1773087572.105494022,'{"timestamp": "2026-03-09T21:19:32.105494+0100", "flow_id": 1297518351553070, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53365, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22750, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:19:32.105494+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53365, "dest_port": 53}}'); INSERT INTO alerts VALUES(4961,1773087572.105494977,'{"timestamp": "2026-03-09T21:19:32.105495+0100", "flow_id": 1297525343377265, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62986, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50482, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:19:32.105495+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62986, "dest_port": 53}}'); INSERT INTO alerts VALUES(4962,1773087587.703830958,'{"timestamp": "2026-03-09T21:19:47.703831+0100", "flow_id": 961268762620162, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 57520, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:19:47.682564+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 57520, "dest_port": 853}}'); INSERT INTO alerts VALUES(4963,1773087589.834280967,'{"timestamp": "2026-03-09T21:19:49.834281+0100", "flow_id": 1612885086297063, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:19:49.834281+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4964,1773087589.835189104,'{"timestamp": "2026-03-09T21:19:49.835189+0100", "flow_id": 1616787785164369, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:19:49.835189+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4965,1773087619.991532087,'{"timestamp": "2026-03-09T21:20:19.991532+0100", "flow_id": 880898105007079, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:20:19.991532+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4966,1773087619.991532087,'{"timestamp": "2026-03-09T21:20:19.991532+0100", "flow_id": 880900973569617, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:20:19.991532+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4967,1773087646.650386096,'{"timestamp": "2026-03-09T21:20:46.650386+0100", "flow_id": 1948965444259622, "event_type": "alert", "src_ip": "147.185.132.181", "src_port": 52392, "dest_ip": "134.19.55.199", "dest_port": 16318, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:20:46.650386+0100", "src_ip": "147.185.132.181", "dest_ip": "134.19.55.199", "src_port": 52392, "dest_port": 16318}}'); INSERT INTO alerts VALUES(4968,1773087651.023082017,'{"timestamp": "2026-03-09T21:20:51.023082+0100", "flow_id": 943561677855719, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:20:51.023082+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4969,1773087651.023082017,'{"timestamp": "2026-03-09T21:20:51.023082+0100", "flow_id": 943564546418257, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:20:51.023082+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4970,1773087657.334224939,'{"timestamp": "2026-03-09T21:20:57.334225+0100", "flow_id": 309587363425203, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56263, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30948, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:20:57.334225+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56263, "dest_port": 53}}'); INSERT INTO alerts VALUES(4971,1773087657.334224939,'{"timestamp": "2026-03-09T21:20:57.334225+0100", "flow_id": 309588023127618, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55785, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60414, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:20:57.334225+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55785, "dest_port": 53}}'); INSERT INTO alerts VALUES(4972,1773087662.099767923,'{"timestamp": "2026-03-09T21:21:02.099768+0100", "flow_id": 1740938356322499, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 41680, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:21:02.077663+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 41680, "dest_port": 853}}'); INSERT INTO alerts VALUES(4973,1773087662.208813905,'{"timestamp": "2026-03-09T21:21:02.208814+0100", "flow_id": 1931454605947257, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 51202, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:21:02.187557+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 51202, "dest_port": 853}}'); INSERT INTO alerts VALUES(4974,1773087668.669261932,'{"timestamp": "2026-03-09T21:21:08.669262+0100", "flow_id": 1185608683688494, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53365, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22750, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:21:08.669262+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53365, "dest_port": 53}}'); INSERT INTO alerts VALUES(4975,1773087668.669261932,'{"timestamp": "2026-03-09T21:21:08.669262+0100", "flow_id": 1185611380545393, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62986, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50482, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:21:08.669262+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62986, "dest_port": 53}}'); INSERT INTO alerts VALUES(4976,1773087668.669262886,'{"timestamp": "2026-03-09T21:21:08.669263+0100", "flow_id": 1185616814020972, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59451, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13750, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:21:08.669263+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59451, "dest_port": 53}}'); INSERT INTO alerts VALUES(4977,1773087668.669262886,'{"timestamp": "2026-03-09T21:21:08.669263+0100", "flow_id": 1185615245362271, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50374, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32849, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:21:08.669263+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50374, "dest_port": 53}}'); INSERT INTO alerts VALUES(4978,1773087677.646083116,'{"timestamp": "2026-03-09T21:21:17.646083+0100", "flow_id": 1649008725943131, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49586, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43086, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:21:17.646083+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49586, "dest_port": 53}}'); INSERT INTO alerts VALUES(4979,1773087677.646343946,'{"timestamp": "2026-03-09T21:21:17.646344+0100", "flow_id": 1650128999646560, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62518, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59336, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:21:17.646344+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62518, "dest_port": 53}}'); INSERT INTO alerts VALUES(4980,1773087681.685750008,'{"timestamp": "2026-03-09T21:21:21.685750+0100", "flow_id": 411999345433575, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:21:21.685750+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4981,1773087681.685750008,'{"timestamp": "2026-03-09T21:21:21.685750+0100", "flow_id": 412002213996113, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:21:21.685750+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4982,1773087702.028217078,'{"timestamp": "2026-03-09T21:21:42.028217+0100", "flow_id": 1810041414731725, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56913, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41647, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "caldav.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T21:21:42.028217+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56913, "dest_port": 53}}'); INSERT INTO alerts VALUES(4983,1773087702.02929306,'{"timestamp": "2026-03-09T21:21:42.029293+0100", "flow_id": 1814664261121674, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58387, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24869, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "contacts.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T21:21:42.029293+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58387, "dest_port": 53}}'); INSERT INTO alerts VALUES(4984,1773087712.833621979,'{"timestamp": "2026-03-09T21:21:52.833622+0100", "flow_id": 202679819295719, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:21:52.833622+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4985,1773087712.833621979,'{"timestamp": "2026-03-09T21:21:52.833622+0100", "flow_id": 202682687858257, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:21:52.833622+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4986,1773087716.93740511,'{"timestamp": "2026-03-09T21:21:56.937405+0100", "flow_id": 1211378170989904, "event_type": "alert", "src_ip": "167.94.138.138", "src_port": 21358, "dest_ip": "134.19.55.199", "dest_port": 5094, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 41, "bytes_toclient": 0, "start": "2026-03-09T21:21:56.937405+0100", "src_ip": "167.94.138.138", "dest_ip": "134.19.55.199", "src_port": 21358, "dest_port": 5094}}'); INSERT INTO alerts VALUES(4987,1773087717.910698891,'{"timestamp": "2026-03-09T21:21:57.910699+0100", "flow_id": 1659624412957235, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61870, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17270, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "caldav.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T21:21:57.910699+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61870, "dest_port": 53}}'); INSERT INTO alerts VALUES(4988,1773087735.239619017,'{"timestamp": "2026-03-09T21:22:15.239619+0100", "flow_id": 2155056554900479, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58473, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57581, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:22:15.239619+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58473, "dest_port": 53}}'); INSERT INTO alerts VALUES(4989,1773087735.239619971,'{"timestamp": "2026-03-09T21:22:15.239620+0100", "flow_id": 2155064173911400, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52565, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36494, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:22:15.239620+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52565, "dest_port": 53}}'); INSERT INTO alerts VALUES(4990,1773087742.991514921,'{"timestamp": "2026-03-09T21:22:22.991515+0100", "flow_id": 1725250020695015, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:22:22.991515+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4991,1773087742.991516114,'{"timestamp": "2026-03-09T21:22:22.991516+0100", "flow_id": 1725257184224849, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:22:22.991516+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4992,1773087744.071368933,'{"timestamp": "2026-03-09T21:22:24.071369+0100", "flow_id": 25053883692188, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 13476, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:22:24.071369+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 13476}}'); INSERT INTO alerts VALUES(4993,1773087763.074187995,'{"timestamp": "2026-03-09T21:22:43.074188+0100", "flow_id": 881587496881205, "event_type": "alert", "src_ip": "45.156.87.238", "src_port": 47574, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:22:43.074188+0100", "src_ip": "45.156.87.238", "dest_ip": "134.19.55.199", "src_port": 47574, "dest_port": 27017}}'); INSERT INTO alerts VALUES(4994,1773087774.369643927,'{"timestamp": "2026-03-09T21:22:54.369644+0100", "flow_id": 1869084180470759, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:22:54.369644+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(4995,1773087774.369645118,'{"timestamp": "2026-03-09T21:22:54.369645+0100", "flow_id": 1869091344000593, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:22:54.369645+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(4996,1773087782.101635932,'{"timestamp": "2026-03-09T21:23:02.101636+0100", "flow_id": 1757007012608146, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 50504, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:23:02.081405+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 50504, "dest_port": 853}}'); INSERT INTO alerts VALUES(4997,1773087782.104839087,'{"timestamp": "2026-03-09T21:23:02.104839+0100", "flow_id": 1760398053613198, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 58804, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:23:02.082194+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 58804, "dest_port": 853}}'); INSERT INTO alerts VALUES(4998,1773087782.213371992,'{"timestamp": "2026-03-09T21:23:02.213372+0100", "flow_id": 1952660176545342, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 58812, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:23:02.192495+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 58812, "dest_port": 853}}'); INSERT INTO alerts VALUES(4999,1773087797.95194292,'{"timestamp": "2026-03-09T21:23:17.951943+0100", "flow_id": 1555291789016504, "event_type": "alert", "src_ip": "198.235.24.106", "src_port": 51422, "dest_ip": "134.19.55.199", "dest_port": 11553, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:23:17.951943+0100", "src_ip": "198.235.24.106", "dest_ip": "134.19.55.199", "src_port": 51422, "dest_port": 11553}}'); INSERT INTO alerts VALUES(5000,1773087805.76560092,'{"timestamp": "2026-03-09T21:23:25.765601+0100", "flow_id": 1599381709118439, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:23:25.765601+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(5001,1773087805.76560092,'{"timestamp": "2026-03-09T21:23:25.765601+0100", "flow_id": 1599384577680977, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:23:25.765601+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(5002,1773087808.762418985,'{"timestamp": "2026-03-09T21:23:28.762419+0100", "flow_id": 178343024531462, "event_type": "alert", "src_ip": "167.94.146.33", "src_port": 23449, "dest_ip": "134.19.55.199", "dest_port": 17523, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:23:28.762419+0100", "src_ip": "167.94.146.33", "dest_ip": "134.19.55.199", "src_port": 23449, "dest_port": 17523}}'); INSERT INTO alerts VALUES(5003,1773087814.419563055,'{"timestamp": "2026-03-09T21:23:34.419563+0100", "flow_id": 1802013340473708, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59451, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13750, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:23:34.419563+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59451, "dest_port": 53}}'); INSERT INTO alerts VALUES(5004,1773087814.419563055,'{"timestamp": "2026-03-09T21:23:34.419563+0100", "flow_id": 1802011771815007, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50374, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32849, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:23:34.419563+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50374, "dest_port": 53}}'); INSERT INTO alerts VALUES(5005,1773087836.931618928,'{"timestamp": "2026-03-09T21:23:56.931619+0100", "flow_id": 1186523682823143, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:23:56.931619+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(5006,1773087836.931619882,'{"timestamp": "2026-03-09T21:23:56.931620+0100", "flow_id": 1186530846352977, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:23:56.931620+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(5007,1773087845.532087087,'{"timestamp": "2026-03-09T21:24:05.532087+0100", "flow_id": 1440875310356844, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59451, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13750, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:24:05.532087+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59451, "dest_port": 53}}'); INSERT INTO alerts VALUES(5008,1773087845.532087087,'{"timestamp": "2026-03-09T21:24:05.532087+0100", "flow_id": 1440873741698143, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50374, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32849, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:24:05.532087+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50374, "dest_port": 53}}'); INSERT INTO alerts VALUES(5009,1773087867.541671991,'{"timestamp": "2026-03-09T21:24:27.541672+0100", "flow_id": 919090559298265, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55365, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21638, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:24:27.541672+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55365, "dest_port": 53}}'); INSERT INTO alerts VALUES(5010,1773087867.541671991,'{"timestamp": "2026-03-09T21:24:27.541672+0100", "flow_id": 919091959304270, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61836, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39888, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:24:27.541672+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61836, "dest_port": 53}}'); INSERT INTO alerts VALUES(5011,1773087867.860646963,'{"timestamp": "2026-03-09T21:24:27.860647+0100", "flow_id": 881701263891431, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:24:27.860647+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(5012,1773087867.860647917,'{"timestamp": "2026-03-09T21:24:27.860648+0100", "flow_id": 881708427421265, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:24:27.860648+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(5013,1773087876.376033067,'{"timestamp": "2026-03-09T21:24:36.376033+0100", "flow_id": 1333578437368172, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59451, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13750, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:24:36.376033+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59451, "dest_port": 53}}'); INSERT INTO alerts VALUES(5014,1773087876.376034022,'{"timestamp": "2026-03-09T21:24:36.376034+0100", "flow_id": 1333581163676767, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50374, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32849, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:24:36.376034+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50374, "dest_port": 53}}'); INSERT INTO alerts VALUES(5015,1773087878.378042936,'{"timestamp": "2026-03-09T21:24:38.378043+0100", "flow_id": 1905161113401282, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61193, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6367, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:24:38.378043+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61193, "dest_port": 53}}'); INSERT INTO alerts VALUES(5016,1773087878.378042936,'{"timestamp": "2026-03-09T21:24:38.378043+0100", "flow_id": 1905159981577140, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58507, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3544, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:24:38.378043+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58507, "dest_port": 53}}'); INSERT INTO alerts VALUES(5017,1773087878.379371881,'{"timestamp": "2026-03-09T21:24:38.379372+0100", "flow_id": 1910867575193889, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51393, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30500, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:24:38.379372+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51393, "dest_port": 53}}'); INSERT INTO alerts VALUES(5018,1773087878.379371881,'{"timestamp": "2026-03-09T21:24:38.379372+0100", "flow_id": 1910868421501495, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56838, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15893, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:24:38.379372+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56838, "dest_port": 53}}'); INSERT INTO alerts VALUES(5019,1773087887.004808903,'{"timestamp": "2026-03-09T21:24:47.004809+0100", "flow_id": 1990979857939655, "event_type": "alert", "src_ip": "185.242.226.58", "src_port": 49033, "dest_ip": "134.19.55.199", "dest_port": 20000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:24:47.004809+0100", "src_ip": "185.242.226.58", "dest_ip": "134.19.55.199", "src_port": 49033, "dest_port": 20000}}'); INSERT INTO alerts VALUES(5020,1773087890.251766921,'{"timestamp": "2026-03-09T21:24:50.251767+0100", "flow_id": 799856980446115, "event_type": "alert", "src_ip": "176.65.134.34", "src_port": 37174, "dest_ip": "134.19.55.199", "dest_port": 44000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:24:50.251767+0100", "src_ip": "176.65.134.34", "dest_ip": "134.19.55.199", "src_port": 37174, "dest_port": 44000}}'); INSERT INTO alerts VALUES(5021,1773087899.044233083,'{"timestamp": "2026-03-09T21:24:59.044233+0100", "flow_id": 1034404531133415, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:24:59.044233+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(5022,1773087899.044234037,'{"timestamp": "2026-03-09T21:24:59.044234+0100", "flow_id": 1034411694663249, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:24:59.044234+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(5023,1773087902.106363059,'{"timestamp": "2026-03-09T21:25:02.106363+0100", "flow_id": 1767511858248143, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39632, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:25:02.083850+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 39632, "dest_port": 853}}'); INSERT INTO alerts VALUES(5024,1773087902.218452931,'{"timestamp": "2026-03-09T21:25:02.218453+0100", "flow_id": 1965633468925264, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 39638, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:25:02.195515+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 39638, "dest_port": 853}}'); INSERT INTO alerts VALUES(5025,1773087929.526629924,'{"timestamp": "2026-03-09T21:25:29.526630+0100", "flow_id": 291534102715367, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:25:29.526630+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(5026,1773087929.526629924,'{"timestamp": "2026-03-09T21:25:29.526630+0100", "flow_id": 291536971277905, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:25:29.526630+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(5027,1773087937.953567028,'{"timestamp": "2026-03-09T21:25:37.953567+0100", "flow_id": 436368400050943, "event_type": "alert", "src_ip": "198.235.24.252", "src_port": 29778, "dest_ip": "134.19.55.199", "dest_port": 50000, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 48, "bytes_toclient": 0, "start": "2026-03-09T21:25:37.953567+0100", "src_ip": "198.235.24.252", "dest_ip": "134.19.55.199", "src_port": 29778, "dest_port": 50000}}'); INSERT INTO alerts VALUES(5028,1773087938.841396093,'{"timestamp": "2026-03-09T21:25:38.841396+0100", "flow_id": 799021028583131, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58284, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T21:25:38.841396+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58728, "dest_port": 53}}'); INSERT INTO alerts VALUES(5029,1773087951.674256087,'{"timestamp": "2026-03-09T21:25:51.674256+0100", "flow_id": 2051483953892181, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52105, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:25:51.674256+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52105, "dest_port": 53}}'); INSERT INTO alerts VALUES(5030,1773087951.674257041,'{"timestamp": "2026-03-09T21:25:51.674257+0100", "flow_id": 2051489761299374, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59481, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55171, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:25:51.674257+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59481, "dest_port": 53}}'); INSERT INTO alerts VALUES(5031,1773087960.682919979,'{"timestamp": "2026-03-09T21:26:00.682920+0100", "flow_id": 118369611275239, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:26:00.682920+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(5032,1773087960.682919979,'{"timestamp": "2026-03-09T21:26:00.682920+0100", "flow_id": 118372479837777, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:26:00.682920+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(5033,1773087967.693680048,'{"timestamp": "2026-03-09T21:26:07.693680+0100", "flow_id": 2134909038872877, "event_type": "alert", "src_ip": "198.235.24.227", "src_port": 52364, "dest_ip": "134.19.55.199", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:26:07.693680+0100", "src_ip": "198.235.24.227", "dest_ip": "134.19.55.199", "src_port": 52364, "dest_port": 8888}}'); INSERT INTO alerts VALUES(5034,1773087992.176806926,'{"timestamp": "2026-03-09T21:26:32.176807+0100", "flow_id": 196430641880039, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:26:32.176807+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(5035,1773087992.176806926,'{"timestamp": "2026-03-09T21:26:32.176807+0100", "flow_id": 196433510442577, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:26:32.176807+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(5036,1773087995.334059001,'{"timestamp": "2026-03-09T21:26:35.334059+0100", "flow_id": 871825209897908, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58507, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3544, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:26:35.334059+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58507, "dest_port": 53}}'); INSERT INTO alerts VALUES(5037,1773087995.334059001,'{"timestamp": "2026-03-09T21:26:35.334059+0100", "flow_id": 871823508946396, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53824, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50010, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:26:35.334059+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53824, "dest_port": 53}}'); INSERT INTO alerts VALUES(5038,1773087995.33468008,'{"timestamp": "2026-03-09T21:26:35.334680+0100", "flow_id": 874492003592554, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56778, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11260, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:26:35.334680+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56778, "dest_port": 53}}'); INSERT INTO alerts VALUES(5039,1773087995.33468008,'{"timestamp": "2026-03-09T21:26:35.334680+0100", "flow_id": 874491441526685, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55981, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10885, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:26:35.334680+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55981, "dest_port": 53}}'); INSERT INTO alerts VALUES(5040,1773088001.924190998,'{"timestamp": "2026-03-09T21:26:41.924191+0100", "flow_id": 310197607970301, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61301, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55010, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T21:26:41.924191+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61301, "dest_port": 53}}'); INSERT INTO alerts VALUES(5041,1773088016.861973047,'{"timestamp": "2026-03-09T21:26:56.861973+0100", "flow_id": 42974618459676, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57331, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54432, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:26:56.861973+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57331, "dest_port": 53}}'); INSERT INTO alerts VALUES(5042,1773088016.862591982,'{"timestamp": "2026-03-09T21:26:56.862592+0100", "flow_id": 45630615669206, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60726, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:26:56.862592+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60726, "dest_port": 53}}'); INSERT INTO alerts VALUES(5043,1773088022.107153893,'{"timestamp": "2026-03-09T21:27:02.107154+0100", "flow_id": 1777077941914388, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 46420, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:27:02.086078+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 46420, "dest_port": 853}}'); INSERT INTO alerts VALUES(5044,1773088022.42620492,'{"timestamp": "2026-03-09T21:27:02.426205+0100", "flow_id": 1830536848989159, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:27:02.426205+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(5045,1773088022.42620492,'{"timestamp": "2026-03-09T21:27:02.426205+0100", "flow_id": 1830539717551697, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:27:02.426205+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(5046,1773088033.496680974,'{"timestamp": "2026-03-09T21:27:13.496681+0100", "flow_id": 444379494303225, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54069, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:27:13.496681+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54069, "dest_port": 53}}'); INSERT INTO alerts VALUES(5047,1773088033.496681929,'{"timestamp": "2026-03-09T21:27:13.496682+0100", "flow_id": 444386023187380, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44549, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:27:13.496682+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53509, "dest_port": 53}}'); INSERT INTO alerts VALUES(5048,1773088087.908721923,'{"timestamp": "2026-03-09T21:28:07.908722+0100", "flow_id": 2214085204054170, "event_type": "alert", "src_ip": "205.210.31.245", "src_port": 50752, "dest_ip": "134.19.55.199", "dest_port": 2300, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:28:07.908722+0100", "src_ip": "205.210.31.245", "dest_ip": "134.19.55.199", "src_port": 50752, "dest_port": 2300}}'); INSERT INTO alerts VALUES(5049,1773088097.842600108,'{"timestamp": "2026-03-09T21:28:17.842600+0100", "flow_id": 522718676654444, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59451, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13750, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:28:17.842600+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59451, "dest_port": 53}}'); INSERT INTO alerts VALUES(5050,1773088097.842600108,'{"timestamp": "2026-03-09T21:28:17.842600+0100", "flow_id": 522717107995743, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50374, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32849, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:28:17.842600+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50374, "dest_port": 53}}'); INSERT INTO alerts VALUES(5051,1773088107.040859937,'{"timestamp": "2026-03-09T21:28:27.040860+0100", "flow_id": 1019919530133034, "event_type": "alert", "src_ip": "185.169.4.141", "src_port": 47230, "dest_ip": "134.19.55.199", "dest_port": 8728, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:28:27.040860+0100", "src_ip": "185.169.4.141", "dest_ip": "134.19.55.199", "src_port": 47230, "dest_port": 8728}}'); INSERT INTO alerts VALUES(5052,1773088123.683561086,'{"timestamp": "2026-03-09T21:28:43.683561+0100", "flow_id": 965549226827933, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60301, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12292, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:28:43.683561+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60301, "dest_port": 53}}'); INSERT INTO alerts VALUES(5053,1773088123.683561086,'{"timestamp": "2026-03-09T21:28:43.683561+0100", "flow_id": 965550676223596, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52742, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20583, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:28:43.683561+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52742, "dest_port": 53}}'); INSERT INTO alerts VALUES(5054,1773088129.476780891,'{"timestamp": "2026-03-09T21:28:49.476781+0100", "flow_id": 358909824421559, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:28:49.476781+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5055,1773088129.645633936,'{"timestamp": "2026-03-09T21:28:49.645634+0100", "flow_id": 521180420838459, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6692, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T21:28:49.645634+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5056,1773088130.827950001,'{"timestamp": "2026-03-09T21:28:50.827950+0100", "flow_id": 741272596896684, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:28:50.827950+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5057,1773088142.111617088,'{"timestamp": "2026-03-09T21:29:02.111617+0100", "flow_id": 1799557160820600, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 38336, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:29:02.091312+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 38336, "dest_port": 853}}'); INSERT INTO alerts VALUES(5058,1773088150.783221961,'{"timestamp": "2026-03-09T21:29:10.783222+0100", "flow_id": 1956538974387676, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53824, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50010, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:29:10.783222+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53824, "dest_port": 53}}'); INSERT INTO alerts VALUES(5059,1773088150.783221961,'{"timestamp": "2026-03-09T21:29:10.783222+0100", "flow_id": 1956540319919331, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51233, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8143, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:29:10.783222+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51233, "dest_port": 53}}'); INSERT INTO alerts VALUES(5060,1773088150.783221961,'{"timestamp": "2026-03-09T21:29:10.783222+0100", "flow_id": 1956538315922413, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61579, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52913, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:29:10.783222+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61579, "dest_port": 53}}'); INSERT INTO alerts VALUES(5061,1773088150.783222914,'{"timestamp": "2026-03-09T21:29:10.783223+0100", "flow_id": 1956542725018325, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53461, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61219, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:29:10.783223+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53461, "dest_port": 53}}'); INSERT INTO alerts VALUES(5062,1773088160.171928882,'{"timestamp": "2026-03-09T21:29:20.171929+0100", "flow_id": 175479890068287, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63140, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10784, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T21:29:20.171929+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63140, "dest_port": 53}}'); INSERT INTO alerts VALUES(5063,1773088168.349033118,'{"timestamp": "2026-03-09T21:29:28.349033+0100", "flow_id": 91711569367898, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61861, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63525, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:29:28.349033+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61861, "dest_port": 53}}'); INSERT INTO alerts VALUES(5064,1773088168.349502087,'{"timestamp": "2026-03-09T21:29:28.349502+0100", "flow_id": 93727320140446, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64427, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41856, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:29:28.349502+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64427, "dest_port": 53}}'); INSERT INTO alerts VALUES(5065,1773088174.71429801,'{"timestamp": "2026-03-09T21:29:34.714298+0100", "flow_id": 1941987073483658, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 56878, "dest_ip": "134.19.55.199", "dest_port": 63333, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:29:34.714298+0100", "src_ip": "79.124.40.82", "dest_ip": "134.19.55.199", "src_port": 56878, "dest_port": 63333}}'); INSERT INTO alerts VALUES(5066,1773088183.93762207,'{"timestamp": "2026-03-09T21:29:43.937622+0100", "flow_id": 2056735079226826, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 34642, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:29:43.937622+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 34642}}'); INSERT INTO alerts VALUES(5067,1773088183.93762207,'{"timestamp": "2026-03-09T21:29:43.937622+0100", "flow_id": 2056735079226826, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 34642, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:29:43.937622+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 34642}}'); INSERT INTO alerts VALUES(5068,1773088208.493383885,'{"timestamp": "2026-03-09T21:30:08.493384+0100", "flow_id": 148745576356345, "event_type": "alert", "src_ip": "205.210.31.55", "src_port": 51449, "dest_ip": "134.19.55.199", "dest_port": 9091, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:30:08.493384+0100", "src_ip": "205.210.31.55", "dest_ip": "134.19.55.199", "src_port": 51449, "dest_port": 9091}}'); INSERT INTO alerts VALUES(5069,1773088226.880207062,'{"timestamp": "2026-03-09T21:30:26.880207+0100", "flow_id": 684236757134183, "event_type": "alert", "src_ip": "198.235.24.36", "src_port": 54666, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:30:26.880207+0100", "src_ip": "198.235.24.36", "dest_ip": "134.19.55.199", "src_port": 54666, "dest_port": 80}}'); INSERT INTO alerts VALUES(5070,1773088230.86657095,'{"timestamp": "2026-03-09T21:30:30.866571+0100", "flow_id": 1751570150018743, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:30:30.866571+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5071,1773088230.86657095,'{"timestamp": "2026-03-09T21:30:30.866571+0100", "flow_id": 1751573458967468, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:30:30.866571+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5072,1773088233.598527909,'{"timestamp": "2026-03-09T21:30:33.598528+0100", "flow_id": 318859504751450, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61861, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63525, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:30:33.598528+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61861, "dest_port": 53}}'); INSERT INTO alerts VALUES(5073,1773088233.598527909,'{"timestamp": "2026-03-09T21:30:33.598528+0100", "flow_id": 318860915862174, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64427, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41856, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:30:33.598528+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64427, "dest_port": 53}}'); INSERT INTO alerts VALUES(5074,1773088234.69312191,'{"timestamp": "2026-03-09T21:30:34.693122+0100", "flow_id": 725136821050343, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64927, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:30:34.693122+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64927, "dest_port": 53}}'); INSERT INTO alerts VALUES(5075,1773088234.69312191,'{"timestamp": "2026-03-09T21:30:34.693122+0100", "flow_id": 725139689612881, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47401, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:30:34.693122+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63375, "dest_port": 53}}'); INSERT INTO alerts VALUES(5076,1773088234.693123102,'{"timestamp": "2026-03-09T21:30:34.693123+0100", "flow_id": 725143710242636, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51157, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60399, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:30:34.693123+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51157, "dest_port": 53}}'); INSERT INTO alerts VALUES(5077,1773088234.693123102,'{"timestamp": "2026-03-09T21:30:34.693123+0100", "flow_id": 725140914082726, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58025, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14830, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:30:34.693123+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58025, "dest_port": 53}}'); INSERT INTO alerts VALUES(5078,1773088235.471662045,'{"timestamp": "2026-03-09T21:30:35.471662+0100", "flow_id": 899877001274867, "event_type": "alert", "src_ip": "66.132.153.150", "src_port": 15829, "dest_ip": "134.19.55.199", "dest_port": 808, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:30:35.471662+0100", "src_ip": "66.132.153.150", "dest_ip": "134.19.55.199", "src_port": 15829, "dest_port": 808}}'); INSERT INTO alerts VALUES(5079,1773088260.499109983,'{"timestamp": "2026-03-09T21:31:00.499110+0100", "flow_id": 1299237121230916, "event_type": "alert", "src_ip": "147.185.132.10", "src_port": 50745, "dest_ip": "134.19.55.199", "dest_port": 995, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:31:00.499110+0100", "src_ip": "147.185.132.10", "dest_ip": "134.19.55.199", "src_port": 50745, "dest_port": 995}}'); INSERT INTO alerts VALUES(5080,1773088260.959469079,'{"timestamp": "2026-03-09T21:31:00.959469+0100", "flow_id": 1306139091750583, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:31:00.959469+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5081,1773088260.959470034,'{"timestamp": "2026-03-09T21:31:00.959470+0100", "flow_id": 1306146695666604, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:31:00.959470+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5082,1773088262.11706996,'{"timestamp": "2026-03-09T21:31:02.117070+0100", "flow_id": 1814828088013251, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 44892, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:31:02.094867+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 44892, "dest_port": 853}}'); INSERT INTO alerts VALUES(5083,1773088262.335853099,'{"timestamp": "2026-03-09T21:31:02.335853+0100", "flow_id": 1723953556341381, "event_type": "alert", "src_ip": "205.210.31.175", "src_port": 55238, "dest_ip": "134.19.55.199", "dest_port": 4026, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:31:02.335853+0100", "src_ip": "205.210.31.175", "dest_ip": "134.19.55.199", "src_port": 55238, "dest_port": 4026}}'); INSERT INTO alerts VALUES(5084,1773088263.601847887,'{"timestamp": "2026-03-09T21:31:03.601848+0100", "flow_id": 2021968656438106, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61861, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63525, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:31:03.601848+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61861, "dest_port": 53}}'); INSERT INTO alerts VALUES(5085,1773088263.60184908,'{"timestamp": "2026-03-09T21:31:03.601849+0100", "flow_id": 2021974362516126, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64427, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41856, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:31:03.601849+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64427, "dest_port": 53}}'); INSERT INTO alerts VALUES(5086,1773088279.290931941,'{"timestamp": "2026-03-09T21:31:19.290932+0100", "flow_id": 2093970895667315, "event_type": "alert", "src_ip": "147.185.132.25", "src_port": 50632, "dest_ip": "134.19.55.199", "dest_port": 47693, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:31:19.290932+0100", "src_ip": "147.185.132.25", "dest_ip": "134.19.55.199", "src_port": 50632, "dest_port": 47693}}'); INSERT INTO alerts VALUES(5087,1773088282.064135075,'{"timestamp": "2026-03-09T21:31:22.064135+0100", "flow_id": 838407909606653, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 52604, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:31:22.064135+0100", "src_ip": "45.153.34.32", "dest_ip": "134.19.55.199", "src_port": 52604, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5088,1773088282.064135075,'{"timestamp": "2026-03-09T21:31:22.064135+0100", "flow_id": 838407909606653, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 52604, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:31:22.064135+0100", "src_ip": "45.153.34.32", "dest_ip": "134.19.55.199", "src_port": 52604, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5089,1773088291.520129919,'{"timestamp": "2026-03-09T21:31:31.520130+0100", "flow_id": 1108042315157175, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:31:31.520130+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5090,1773088291.520129919,'{"timestamp": "2026-03-09T21:31:31.520130+0100", "flow_id": 1108045624105900, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:31:31.520130+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5091,1773088326.870078087,'{"timestamp": "2026-03-09T21:32:06.870078+0100", "flow_id": 1950535033434054, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53064, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:32:06.847360+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 53064, "dest_port": 853}}'); INSERT INTO alerts VALUES(5092,1773088333.69245696,'{"timestamp": "2026-03-09T21:32:13.692457+0100", "flow_id": 1566708192155468, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51157, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60399, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:32:13.692457+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51157, "dest_port": 53}}'); INSERT INTO alerts VALUES(5093,1773088333.692457915,'{"timestamp": "2026-03-09T21:32:13.692458+0100", "flow_id": 1566709690962854, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58025, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14830, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:32:13.692458+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58025, "dest_port": 53}}'); INSERT INTO alerts VALUES(5094,1773088333.692457915,'{"timestamp": "2026-03-09T21:32:13.692458+0100", "flow_id": 1566712756109974, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57752, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1841, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:32:13.692458+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57752, "dest_port": 53}}'); INSERT INTO alerts VALUES(5095,1773088333.692457915,'{"timestamp": "2026-03-09T21:32:13.692458+0100", "flow_id": 1566712993830368, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56347, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64204, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:32:13.692458+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56347, "dest_port": 53}}'); INSERT INTO alerts VALUES(5096,1773088342.078228951,'{"timestamp": "2026-03-09T21:32:22.078229+0100", "flow_id": 1743366350447257, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63050, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56317, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "escrowproxy.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-09T21:32:22.078229+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63050, "dest_port": 53}}'); INSERT INTO alerts VALUES(5097,1773088344.526518106,'{"timestamp": "2026-03-09T21:32:24.526518+0100", "flow_id": 9578078539422, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59299, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23736, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:32:24.526518+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59299, "dest_port": 53}}'); INSERT INTO alerts VALUES(5098,1773088344.527142048,'{"timestamp": "2026-03-09T21:32:24.527142+0100", "flow_id": 12258660977360, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65190, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35551, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:32:24.527142+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65190, "dest_port": 53}}'); INSERT INTO alerts VALUES(5099,1773088364.658978939,'{"timestamp": "2026-03-09T21:32:44.658979+0100", "flow_id": 1141445724308521, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51441, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38108, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:32:44.658979+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51441, "dest_port": 53}}'); INSERT INTO alerts VALUES(5100,1773088364.658978939,'{"timestamp": "2026-03-09T21:32:44.658979+0100", "flow_id": 1141443634745386, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52638, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35313, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:32:44.658979+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52638, "dest_port": 53}}'); INSERT INTO alerts VALUES(5101,1773088385.760227918,'{"timestamp": "2026-03-09T21:33:05.760228+0100", "flow_id": 450406752507276, "event_type": "alert", "src_ip": "167.94.146.42", "src_port": 36460, "dest_ip": "134.19.55.199", "dest_port": 23352, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:33:05.760228+0100", "src_ip": "167.94.146.42", "dest_ip": "134.19.55.199", "src_port": 36460, "dest_port": 23352}}'); INSERT INTO alerts VALUES(5102,1773088387.291806937,'{"timestamp": "2026-03-09T21:33:07.291807+0100", "flow_id": 971826921071735, "event_type": "alert", "src_ip": "195.184.76.223", "src_port": 17703, "dest_ip": "134.19.55.199", "dest_port": 5408, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:33:07.291807+0100", "src_ip": "195.184.76.223", "dest_ip": "134.19.55.199", "src_port": 17703, "dest_port": 5408}}'); INSERT INTO alerts VALUES(5103,1773088420.075936079,'{"timestamp": "2026-03-09T21:33:40.075936+0100", "flow_id": 1170569719509462, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65179, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54416, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:33:40.075936+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65179, "dest_port": 53}}'); INSERT INTO alerts VALUES(5104,1773088420.075937032,'{"timestamp": "2026-03-09T21:33:40.075937+0100", "flow_id": 1170574178022387, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49759, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24886, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:33:40.075937+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49759, "dest_port": 53}}'); INSERT INTO alerts VALUES(5105,1773088421.615770102,'{"timestamp": "2026-03-09T21:33:41.615770+0100", "flow_id": 1518813959195250, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:33:41.615770+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 8080}}'); INSERT INTO alerts VALUES(5106,1773088421.615770102,'{"timestamp": "2026-03-09T21:33:41.615770+0100", "flow_id": 1518813959195250, "event_type": "alert", "src_ip": "204.76.203.215", "src_port": 40000, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:33:41.615770+0100", "src_ip": "204.76.203.215", "dest_ip": "134.19.55.199", "src_port": 40000, "dest_port": 8080}}'); INSERT INTO alerts VALUES(5107,1773088423.684650898,'{"timestamp": "2026-03-09T21:33:43.684651+0100", "flow_id": 2096131899851414, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57752, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1841, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:33:43.684651+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57752, "dest_port": 53}}'); INSERT INTO alerts VALUES(5108,1773088423.68465209,'{"timestamp": "2026-03-09T21:33:43.684652+0100", "flow_id": 2096136432539104, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56347, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64204, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:33:43.684652+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56347, "dest_port": 53}}'); INSERT INTO alerts VALUES(5109,1773088423.68465209,'{"timestamp": "2026-03-09T21:33:43.684652+0100", "flow_id": 2096136793035070, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50865, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44123, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:33:43.684652+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50865, "dest_port": 53}}'); INSERT INTO alerts VALUES(5110,1773088423.684653044,'{"timestamp": "2026-03-09T21:33:43.684653+0100", "flow_id": 2096140059135379, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62520, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18759, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:33:43.684653+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62520, "dest_port": 53}}'); INSERT INTO alerts VALUES(5111,1773088446.871501922,'{"timestamp": "2026-03-09T21:34:06.871502+0100", "flow_id": 1964867537878703, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 52904, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:34:06.850697+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 52904, "dest_port": 853}}'); INSERT INTO alerts VALUES(5112,1773088507.230262995,'{"timestamp": "2026-03-09T21:35:07.230263+0100", "flow_id": 988972455455010, "event_type": "alert", "src_ip": "185.242.226.67", "src_port": 43662, "dest_ip": "134.19.55.199", "dest_port": 49155, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 166, "bytes_toclient": 0, "start": "2026-03-09T21:35:07.230263+0100", "src_ip": "185.242.226.67", "dest_ip": "134.19.55.199", "src_port": 43662, "dest_port": 49155}}'); INSERT INTO alerts VALUES(5113,1773088508.518667937,'{"timestamp": "2026-03-09T21:35:08.518668+0100", "flow_id": 1383238049681079, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:35:08.518668+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5114,1773088508.518668889,'{"timestamp": "2026-03-09T21:35:08.518669+0100", "flow_id": 1383245653597100, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:35:08.518669+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5115,1773088508.518668889,'{"timestamp": "2026-03-09T21:35:08.518669+0100", "flow_id": 1383243615105494, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65179, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54416, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:35:08.518669+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65179, "dest_port": 53}}'); INSERT INTO alerts VALUES(5116,1773088508.518668889,'{"timestamp": "2026-03-09T21:35:08.518669+0100", "flow_id": 1383243778651123, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49759, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24886, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:35:08.518669+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49759, "dest_port": 53}}'); INSERT INTO alerts VALUES(5117,1773088523.644078969,'{"timestamp": "2026-03-09T21:35:23.644079+0100", "flow_id": 1077449217848647, "event_type": "alert", "src_ip": "91.196.152.228", "src_port": 43542, "dest_ip": "134.19.55.199", "dest_port": 2443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:35:23.644079+0100", "src_ip": "91.196.152.228", "dest_ip": "134.19.55.199", "src_port": 43542, "dest_port": 2443}}'); INSERT INTO alerts VALUES(5118,1773088533.880212068,'{"timestamp": "2026-03-09T21:35:33.880212+0100", "flow_id": 1528685848379740, "event_type": "alert", "src_ip": "46.151.182.188", "src_port": 48509, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:35:33.880212+0100", "src_ip": "46.151.182.188", "dest_ip": "134.19.55.199", "src_port": 48509, "dest_port": 5432}}'); INSERT INTO alerts VALUES(5119,1773088533.880212068,'{"timestamp": "2026-03-09T21:35:33.880212+0100", "flow_id": 1528685848379740, "event_type": "alert", "src_ip": "46.151.182.188", "src_port": 48509, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:35:33.880212+0100", "src_ip": "46.151.182.188", "dest_ip": "134.19.55.199", "src_port": 48509, "dest_port": 5432}}'); INSERT INTO alerts VALUES(5120,1773088539.38418603,'{"timestamp": "2026-03-09T21:35:39.384186+0100", "flow_id": 1087117234491063, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:35:39.384186+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5121,1773088539.384485007,'{"timestamp": "2026-03-09T21:35:39.384485+0100", "flow_id": 1088404738661292, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:35:39.384485+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5122,1773088539.384485007,'{"timestamp": "2026-03-09T21:35:39.384485+0100", "flow_id": 1088402700169686, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65179, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54416, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:35:39.384485+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65179, "dest_port": 53}}'); INSERT INTO alerts VALUES(5123,1773088539.384485007,'{"timestamp": "2026-03-09T21:35:39.384485+0100", "flow_id": 1088402863715315, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49759, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24886, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:35:39.384485+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49759, "dest_port": 53}}'); INSERT INTO alerts VALUES(5124,1773088539.820215941,'{"timestamp": "2026-03-09T21:35:39.820216+0100", "flow_id": 989527532561395, "event_type": "alert", "src_ip": "66.132.153.158", "src_port": 35316, "dest_ip": "134.19.55.199", "dest_port": 20201, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:35:39.820216+0100", "src_ip": "66.132.153.158", "dest_ip": "134.19.55.199", "src_port": 35316, "dest_port": 20201}}'); INSERT INTO alerts VALUES(5125,1773088566.872920037,'{"timestamp": "2026-03-09T21:36:06.872920+0100", "flow_id": 1693838801164521, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 35026, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:36:06.853129+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 35026, "dest_port": 853}}'); INSERT INTO alerts VALUES(5126,1773088620.39201188,'{"timestamp": "2026-03-09T21:37:00.392012+0100", "flow_id": 1402207300978609, "event_type": "alert", "src_ip": "147.185.132.106", "src_port": 50895, "dest_ip": "134.19.55.199", "dest_port": 138, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:37:00.392012+0100", "src_ip": "147.185.132.106", "dest_ip": "134.19.55.199", "src_port": 50895, "dest_port": 138}}'); INSERT INTO alerts VALUES(5127,1773088622.749245883,'{"timestamp": "2026-03-09T21:37:02.749246+0100", "flow_id": 1810612189564624, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52984, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42993, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T21:37:02.749246+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52984, "dest_port": 53}}'); INSERT INTO alerts VALUES(5128,1773088622.749245883,'{"timestamp": "2026-03-09T21:37:02.749246+0100", "flow_id": 1810614642442020, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 62626, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57749, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T21:37:02.749246+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 62626, "dest_port": 53}}'); INSERT INTO alerts VALUES(5129,1773088630.066220045,'{"timestamp": "2026-03-09T21:37:10.066220+0100", "flow_id": 1691790942358497, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 4439, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:37:10.066220+0100", "src_ip": "185.156.73.86", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 4439}}'); INSERT INTO alerts VALUES(5130,1773088647.859147071,'{"timestamp": "2026-03-09T21:37:27.859147+0100", "flow_id": 2001158620531738, "event_type": "alert", "src_ip": "61.221.207.130", "src_port": 58531, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:37:27.859147+0100", "src_ip": "61.221.207.130", "dest_ip": "134.19.55.199", "src_port": 58531, "dest_port": 1433}}'); INSERT INTO alerts VALUES(5131,1773088668.681741,'{"timestamp": "2026-03-09T21:37:48.681741+0100", "flow_id": 1239208226359520, "event_type": "alert", "src_ip": "185.242.226.87", "src_port": 55119, "dest_ip": "134.19.55.199", "dest_port": 9004, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:37:48.681741+0100", "src_ip": "185.242.226.87", "dest_ip": "134.19.55.199", "src_port": 55119, "dest_port": 9004}}'); INSERT INTO alerts VALUES(5132,1773088681.683130026,'{"timestamp": "2026-03-09T21:38:01.683130+0100", "flow_id": 400749992546622, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50865, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44123, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:38:01.683130+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50865, "dest_port": 53}}'); INSERT INTO alerts VALUES(5133,1773088681.683130979,'{"timestamp": "2026-03-09T21:38:01.683131+0100", "flow_id": 400753258646931, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62520, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18759, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:38:01.683131+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62520, "dest_port": 53}}'); INSERT INTO alerts VALUES(5134,1773088681.683130979,'{"timestamp": "2026-03-09T21:38:01.683131+0100", "flow_id": 400752524020136, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53428, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41981, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:38:01.683131+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53428, "dest_port": 53}}'); INSERT INTO alerts VALUES(5135,1773088681.683130979,'{"timestamp": "2026-03-09T21:38:01.683131+0100", "flow_id": 400751242525839, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63384, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:38:01.683131+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5136,1773088686.877784014,'{"timestamp": "2026-03-09T21:38:06.877784+0100", "flow_id": 1701732209495924, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 36774, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:38:06.854967+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 36774, "dest_port": 853}}'); INSERT INTO alerts VALUES(5137,1773088695.393867015,'{"timestamp": "2026-03-09T21:38:15.393867+0100", "flow_id": 1973124445382511, "event_type": "alert", "src_ip": "176.65.148.176", "src_port": 52339, "dest_ip": "134.19.55.199", "dest_port": 53, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:38:15.393867+0100", "src_ip": "176.65.148.176", "dest_ip": "134.19.55.199", "src_port": 52339, "dest_port": 53}}'); INSERT INTO alerts VALUES(5138,1773088695.393867015,'{"timestamp": "2026-03-09T21:38:15.393867+0100", "flow_id": 1973124445382511, "event_type": "alert", "src_ip": "176.65.148.176", "src_port": 52339, "dest_ip": "134.19.55.199", "dest_port": 53, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:38:15.393867+0100", "src_ip": "176.65.148.176", "dest_ip": "134.19.55.199", "src_port": 52339, "dest_port": 53}}'); INSERT INTO alerts VALUES(5139,1773088695.401436091,'{"timestamp": "2026-03-09T21:38:15.401436+0100", "flow_id": 2005629931436047, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51160, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7224, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:38:15.401436+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51160, "dest_port": 53}}'); INSERT INTO alerts VALUES(5140,1773088695.401436091,'{"timestamp": "2026-03-09T21:38:15.401436+0100", "flow_id": 2005629599209597, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65470, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4848, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:38:15.401436+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65470, "dest_port": 53}}'); INSERT INTO alerts VALUES(5141,1773088697.888739109,'{"timestamp": "2026-03-09T21:38:17.888739+0100", "flow_id": 349436573970103, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 45450, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:38:17.867791+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 45450, "dest_port": 853}}'); INSERT INTO alerts VALUES(5142,1773088719.967396021,'{"timestamp": "2026-03-09T21:38:39.967396+0100", "flow_id": 2184610390044354, "event_type": "alert", "src_ip": "205.210.31.111", "src_port": 49668, "dest_ip": "134.19.55.199", "dest_port": 5903, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:38:39.967396+0100", "src_ip": "205.210.31.111", "dest_ip": "134.19.55.199", "src_port": 49668, "dest_port": 5903}}'); INSERT INTO alerts VALUES(5143,1773088724.240649939,'{"timestamp": "2026-03-09T21:38:44.240650+0100", "flow_id": 1315061184457955, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51233, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8143, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:38:44.240650+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51233, "dest_port": 53}}'); INSERT INTO alerts VALUES(5144,1773088724.240649939,'{"timestamp": "2026-03-09T21:38:44.240650+0100", "flow_id": 1315059180461037, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61579, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52913, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:38:44.240650+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61579, "dest_port": 53}}'); INSERT INTO alerts VALUES(5145,1773088724.240650893,'{"timestamp": "2026-03-09T21:38:44.240651+0100", "flow_id": 1315063589556949, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53461, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61219, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:38:44.240651+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53461, "dest_port": 53}}'); INSERT INTO alerts VALUES(5146,1773088724.240650893,'{"timestamp": "2026-03-09T21:38:44.240651+0100", "flow_id": 1315066905576031, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55988, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27512, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:38:44.240651+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55988, "dest_port": 53}}'); INSERT INTO alerts VALUES(5147,1773088724.486973047,'{"timestamp": "2026-03-09T21:38:44.486973+0100", "flow_id": 1247111303885684, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50225, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12809, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:38:44.486973+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50225, "dest_port": 53}}'); INSERT INTO alerts VALUES(5148,1773088724.487853051,'{"timestamp": "2026-03-09T21:38:44.487853+0100", "flow_id": 1250889101587284, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61289, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42802, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:38:44.487853+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61289, "dest_port": 53}}'); INSERT INTO alerts VALUES(5149,1773088725.259697915,'{"timestamp": "2026-03-09T21:38:45.259698+0100", "flow_id": 1678347254851226, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52346, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7276, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "escrowproxy.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-09T21:38:45.259698+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52346, "dest_port": 53}}'); INSERT INTO alerts VALUES(5150,1773088727.379340887,'{"timestamp": "2026-03-09T21:38:47.379341+0100", "flow_id": 2192210685614122, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51198, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46584, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:38:47.379341+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51198, "dest_port": 53}}'); INSERT INTO alerts VALUES(5151,1773088727.379340887,'{"timestamp": "2026-03-09T21:38:47.379341+0100", "flow_id": 2192207638821296, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49541, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52250, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:38:47.379341+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49541, "dest_port": 53}}'); INSERT INTO alerts VALUES(5152,1773088739.857604027,'{"timestamp": "2026-03-09T21:38:59.857604+0100", "flow_id": 868632306016857, "event_type": "alert", "src_ip": "45.142.154.10", "src_port": 58914, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:38:59.857604+0100", "src_ip": "45.142.154.10", "dest_ip": "134.19.55.199", "src_port": 58914, "dest_port": 27017}}'); INSERT INTO alerts VALUES(5153,1773088762.291930913,'{"timestamp": "2026-03-09T21:39:22.291931+0100", "flow_id": 690885026598583, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:39:22.291931+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5154,1773088762.291930913,'{"timestamp": "2026-03-09T21:39:22.291931+0100", "flow_id": 690888335547308, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:39:22.291931+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5155,1773088770.71493411,'{"timestamp": "2026-03-09T21:39:30.714934+0100", "flow_id": 818820375555784, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64570, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44028, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:39:30.714934+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64570, "dest_port": 53}}'); INSERT INTO alerts VALUES(5156,1773088792.627028943,'{"timestamp": "2026-03-09T21:39:52.627029+0100", "flow_id": 159795140578999, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:39:52.627029+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5157,1773088792.627028943,'{"timestamp": "2026-03-09T21:39:52.627029+0100", "flow_id": 159798449527724, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:39:52.627029+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5158,1773088794.17444706,'{"timestamp": "2026-03-09T21:39:54.174447+0100", "flow_id": 749245100707952, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62848, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60501, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmipmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 74, "bytes_toclient": 0, "start": "2026-03-09T21:39:54.174447+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62848, "dest_port": 53}}'); INSERT INTO alerts VALUES(5159,1773088794.187618971,'{"timestamp": "2026-03-09T21:39:54.187619+0100", "flow_id": 805819358209186, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50398, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60139, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-09T21:39:54.187619+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50398, "dest_port": 53}}'); INSERT INTO alerts VALUES(5160,1773088795.342859029,'{"timestamp": "2026-03-09T21:39:55.342859+0100", "flow_id": 909618702006287, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51160, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7224, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:39:55.342859+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51160, "dest_port": 53}}'); INSERT INTO alerts VALUES(5161,1773088795.342859029,'{"timestamp": "2026-03-09T21:39:55.342859+0100", "flow_id": 909618369779837, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65470, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4848, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:39:55.342859+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65470, "dest_port": 53}}'); INSERT INTO alerts VALUES(5162,1773088795.342859984,'{"timestamp": "2026-03-09T21:39:55.342860+0100", "flow_id": 909624667134683, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56385, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8033, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:39:55.342860+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56385, "dest_port": 53}}'); INSERT INTO alerts VALUES(5163,1773088795.342859984,'{"timestamp": "2026-03-09T21:39:55.342860+0100", "flow_id": 909624568755577, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58460, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57483, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:39:55.342860+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58460, "dest_port": 53}}'); INSERT INTO alerts VALUES(5164,1773088795.383935929,'{"timestamp": "2026-03-09T21:39:55.383936+0100", "flow_id": 1086045006291426, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60852, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12391, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmip.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-09T21:39:55.383936+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60852, "dest_port": 53}}'); INSERT INTO alerts VALUES(5165,1773088795.682868958,'{"timestamp": "2026-03-09T21:39:55.682869+0100", "flow_id": 962579440749730, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53466, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44060, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmip.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-09T21:39:55.682869+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53466, "dest_port": 53}}'); INSERT INTO alerts VALUES(5166,1773088795.744714021,'{"timestamp": "2026-03-09T21:39:55.744714+0100", "flow_id": 946725165373680, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58253, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53071, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmf.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-09T21:39:55.744714+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58253, "dest_port": 53}}'); INSERT INTO alerts VALUES(5167,1773088795.849797964,'{"timestamp": "2026-03-09T21:39:55.849798+0100", "flow_id": 1116580082394473, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64097, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44423, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmip.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-09T21:39:55.849798+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64097, "dest_port": 53}}'); INSERT INTO alerts VALUES(5168,1773088796.82993102,'{"timestamp": "2026-03-09T21:39:56.829931+0100", "flow_id": 1312727660546920, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62299, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8033, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:39:56.829931+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62299, "dest_port": 53}}'); INSERT INTO alerts VALUES(5169,1773088796.830565929,'{"timestamp": "2026-03-09T21:39:56.830566+0100", "flow_id": 1315454414098668, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50587, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57483, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:39:56.830566+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50587, "dest_port": 53}}'); INSERT INTO alerts VALUES(5170,1773088803.325913906,'{"timestamp": "2026-03-09T21:40:03.325914+0100", "flow_id": 1030541721300402, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 42496, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:40:03.305477+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 42496, "dest_port": 853}}'); INSERT INTO alerts VALUES(5171,1773088803.390686035,'{"timestamp": "2026-03-09T21:40:03.390686+0100", "flow_id": 1029484045360411, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 42502, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:40:03.370767+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 42502, "dest_port": 853}}'); INSERT INTO alerts VALUES(5172,1773088804.466830016,'{"timestamp": "2026-03-09T21:40:04.466830+0100", "flow_id": 1160597057218817, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52303, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60199, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:40:04.466830+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52303, "dest_port": 53}}'); INSERT INTO alerts VALUES(5173,1773088806.879796028,'{"timestamp": "2026-03-09T21:40:06.879796+0100", "flow_id": 1721285400937182, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 42510, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:40:06.859519+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 42510, "dest_port": 853}}'); INSERT INTO alerts VALUES(5174,1773088817.895632029,'{"timestamp": "2026-03-09T21:40:17.895632+0100", "flow_id": 377207265954255, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 40514, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:40:17.874257+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 40514, "dest_port": 853}}'); INSERT INTO alerts VALUES(5175,1773088858.858079911,'{"timestamp": "2026-03-09T21:40:58.858080+0100", "flow_id": 589201764830056, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62299, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8033, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:40:58.858080+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62299, "dest_port": 53}}'); INSERT INTO alerts VALUES(5176,1773088858.858081102,'{"timestamp": "2026-03-09T21:40:58.858081+0100", "flow_id": 589205509116140, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50587, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57483, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:40:58.858081+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50587, "dest_port": 53}}'); INSERT INTO alerts VALUES(5177,1773088889.267755031,'{"timestamp": "2026-03-09T21:41:29.267755+0100", "flow_id": 305575009504104, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62299, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8033, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:41:29.267755+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62299, "dest_port": 53}}'); INSERT INTO alerts VALUES(5178,1773088889.267755986,'{"timestamp": "2026-03-09T21:41:29.267756+0100", "flow_id": 305578753790188, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50587, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57483, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:41:29.267756+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50587, "dest_port": 53}}'); INSERT INTO alerts VALUES(5179,1773088899.733658076,'{"timestamp": "2026-03-09T21:41:39.733658+0100", "flow_id": 899238185094839, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:41:39.733658+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5180,1773088899.73365903,'{"timestamp": "2026-03-09T21:41:39.733659+0100", "flow_id": 899245789010860, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:41:39.733659+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5181,1773088912.026531934,'{"timestamp": "2026-03-09T21:41:52.026532+0100", "flow_id": 113955829341312, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54356, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:41:52.026532+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5182,1773088912.026531934,'{"timestamp": "2026-03-09T21:41:52.026532+0100", "flow_id": 113955404185798, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56956, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52253, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:41:52.026532+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56956, "dest_port": 53}}'); INSERT INTO alerts VALUES(5183,1773088916.438448905,'{"timestamp": "2026-03-09T21:41:56.438449+0100", "flow_id": 1320178121426984, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57261, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43299, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmip.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-09T21:41:56.438449+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57261, "dest_port": 53}}'); INSERT INTO alerts VALUES(5184,1773088919.269588948,'{"timestamp": "2026-03-09T21:41:59.269589+0100", "flow_id": 2002301839788904, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62299, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8033, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:41:59.269589+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62299, "dest_port": 53}}'); INSERT INTO alerts VALUES(5185,1773088919.269589901,'{"timestamp": "2026-03-09T21:41:59.269590+0100", "flow_id": 2002305584074988, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50587, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57483, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:41:59.269590+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50587, "dest_port": 53}}'); INSERT INTO alerts VALUES(5186,1773088923.33267808,'{"timestamp": "2026-03-09T21:42:03.332678+0100", "flow_id": 1059954930075920, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 57142, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:42:03.312325+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 57142, "dest_port": 853}}'); INSERT INTO alerts VALUES(5187,1773088930.561268091,'{"timestamp": "2026-03-09T21:42:10.561268+0100", "flow_id": 721778726358711, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:42:10.561268+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5188,1773088930.561268091,'{"timestamp": "2026-03-09T21:42:10.561268+0100", "flow_id": 721782035307436, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:42:10.561268+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5189,1773088932.210316896,'{"timestamp": "2026-03-09T21:42:12.210317+0100", "flow_id": 1184782018062593, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52303, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60199, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:42:12.210317+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52303, "dest_port": 53}}'); INSERT INTO alerts VALUES(5190,1773088943.049516916,'{"timestamp": "2026-03-09T21:42:23.049517+0100", "flow_id": 2075943448452804, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 38772, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:42:23.024591+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 38772, "dest_port": 853}}'); INSERT INTO alerts VALUES(5191,1773088960.582779885,'{"timestamp": "2026-03-09T21:42:40.582780+0100", "flow_id": 251222109408951, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:42:40.582780+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5192,1773088960.582779885,'{"timestamp": "2026-03-09T21:42:40.582780+0100", "flow_id": 251225418357676, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:42:40.582780+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5193,1773088973.445048093,'{"timestamp": "2026-03-09T21:42:53.445048+0100", "flow_id": 1629993126706917, "event_type": "alert", "src_ip": "176.65.148.52", "src_port": 35034, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:42:53.445048+0100", "src_ip": "176.65.148.52", "dest_ip": "134.19.55.199", "src_port": 35034, "dest_port": 8080}}'); INSERT INTO alerts VALUES(5194,1773088973.445048093,'{"timestamp": "2026-03-09T21:42:53.445048+0100", "flow_id": 1629993126706917, "event_type": "alert", "src_ip": "176.65.148.52", "src_port": 35034, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:42:53.445048+0100", "src_ip": "176.65.148.52", "dest_ip": "134.19.55.199", "src_port": 35034, "dest_port": 8080}}'); INSERT INTO alerts VALUES(5195,1773088976.188564062,'{"timestamp": "2026-03-09T21:42:56.188564+0100", "flow_id": 246928432277599, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59913, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18062, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:42:56.188564+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59913, "dest_port": 53}}'); INSERT INTO alerts VALUES(5196,1773088976.188564062,'{"timestamp": "2026-03-09T21:42:56.188564+0100", "flow_id": 246927352055409, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51090, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22997, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:42:56.188564+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51090, "dest_port": 53}}'); INSERT INTO alerts VALUES(5197,1773088987.857711077,'{"timestamp": "2026-03-09T21:43:07.857711+0100", "flow_id": 869091898608488, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62299, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8033, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:43:07.857711+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62299, "dest_port": 53}}'); INSERT INTO alerts VALUES(5198,1773088987.857711077,'{"timestamp": "2026-03-09T21:43:07.857711+0100", "flow_id": 869091347927276, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50587, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57483, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:43:07.857711+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50587, "dest_port": 53}}'); INSERT INTO alerts VALUES(5199,1773088987.857712031,'{"timestamp": "2026-03-09T21:43:07.857712+0100", "flow_id": 869096974324277, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52951, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5358, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:43:07.857712+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52951, "dest_port": 53}}'); INSERT INTO alerts VALUES(5200,1773088987.857712031,'{"timestamp": "2026-03-09T21:43:07.857712+0100", "flow_id": 869098506246416, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52705, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32762, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:43:07.857712+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52705, "dest_port": 53}}'); INSERT INTO alerts VALUES(5201,1773088991.738398075,'{"timestamp": "2026-03-09T21:43:11.738398+0100", "flow_id": 2045496236920503, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:43:11.738398+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5202,1773088991.738939047,'{"timestamp": "2026-03-09T21:43:11.738939+0100", "flow_id": 2047823123176364, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:43:11.738939+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5203,1773088992.142211914,'{"timestamp": "2026-03-09T21:43:12.142212+0100", "flow_id": 47847781346393, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56919, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64118, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:43:12.142212+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56919, "dest_port": 53}}'); INSERT INTO alerts VALUES(5204,1773088992.142213107,'{"timestamp": "2026-03-09T21:43:12.142213+0100", "flow_id": 47851350335444, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61070, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8496, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:43:12.142213+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61070, "dest_port": 53}}'); INSERT INTO alerts VALUES(5205,1773089002.404088021,'{"timestamp": "2026-03-09T21:43:22.404088+0100", "flow_id": 609645103998293, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51196, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32824, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:43:22.404088+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51196, "dest_port": 53}}'); INSERT INTO alerts VALUES(5206,1773089027.11386609,'{"timestamp": "2026-03-09T21:43:47.113866+0100", "flow_id": 1052003229381002, "event_type": "alert", "src_ip": "87.121.84.72", "src_port": 59189, "dest_ip": "134.19.55.199", "dest_port": 127, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:43:47.113866+0100", "src_ip": "87.121.84.72", "dest_ip": "134.19.55.199", "src_port": 59189, "dest_port": 127}}'); INSERT INTO alerts VALUES(5207,1773089039.188488006,'{"timestamp": "2026-03-09T21:43:59.188488+0100", "flow_id": 2216925640971699, "event_type": "alert", "src_ip": "185.242.226.62", "src_port": 36430, "dest_ip": "134.19.55.199", "dest_port": 30718, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 57, "bytes_toclient": 0, "start": "2026-03-09T21:43:59.188488+0100", "src_ip": "185.242.226.62", "dest_ip": "134.19.55.199", "src_port": 36430, "dest_port": 30718}}'); INSERT INTO alerts VALUES(5208,1773089055.356359004,'{"timestamp": "2026-03-09T21:44:15.356359+0100", "flow_id": 2093501086387895, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:44:15.356359+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5209,1773089055.356359958,'{"timestamp": "2026-03-09T21:44:15.356360+0100", "flow_id": 2093508690303916, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:44:15.356360+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5210,1773089063.053874969,'{"timestamp": "2026-03-09T21:44:23.053875+0100", "flow_id": 2114541470960120, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 37768, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:44:23.033578+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 37768, "dest_port": 853}}'); INSERT INTO alerts VALUES(5211,1773089067.46269989,'{"timestamp": "2026-03-09T21:44:27.462700+0100", "flow_id": 861381751629954, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59836, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35154, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T21:44:27.462700+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59836, "dest_port": 53}}'); INSERT INTO alerts VALUES(5212,1773089067.514046908,'{"timestamp": "2026-03-09T21:44:27.514047+0100", "flow_id": 1081916537228229, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57616, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T21:44:27.514047+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58367, "dest_port": 53}}'); INSERT INTO alerts VALUES(5213,1773089070.204267024,'{"timestamp": "2026-03-09T21:44:30.204267+0100", "flow_id": 1721748993225494, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57405, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8913, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:44:30.204267+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57405, "dest_port": 53}}'); INSERT INTO alerts VALUES(5214,1773089070.20522809,'{"timestamp": "2026-03-09T21:44:30.205228+0100", "flow_id": 1725874796176440, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52932, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9572, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:44:30.205228+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52932, "dest_port": 53}}'); INSERT INTO alerts VALUES(5215,1773089073.526113987,'{"timestamp": "2026-03-09T21:44:33.526114+0100", "flow_id": 289319815713264, "event_type": "alert", "src_ip": "167.94.146.36", "src_port": 48510, "dest_ip": "134.19.55.199", "dest_port": 36640, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:44:33.526114+0100", "src_ip": "167.94.146.36", "dest_ip": "134.19.55.199", "src_port": 48510, "dest_port": 36640}}'); INSERT INTO alerts VALUES(5216,1773089086.488831043,'{"timestamp": "2026-03-09T21:44:46.488831+0100", "flow_id": 1818039257087777, "event_type": "alert", "src_ip": "204.76.203.30", "src_port": 58659, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:44:46.488831+0100", "src_ip": "204.76.203.30", "dest_ip": "134.19.55.199", "src_port": 58659, "dest_port": 3000}}'); INSERT INTO alerts VALUES(5217,1773089086.488831043,'{"timestamp": "2026-03-09T21:44:46.488831+0100", "flow_id": 1818039257087777, "event_type": "alert", "src_ip": "204.76.203.30", "src_port": 58659, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:44:46.488831+0100", "src_ip": "204.76.203.30", "dest_ip": "134.19.55.199", "src_port": 58659, "dest_port": 3000}}'); INSERT INTO alerts VALUES(5218,1773089147.014760017,'{"timestamp": "2026-03-09T21:45:47.014760+0100", "flow_id": 907820399465013, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52951, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5358, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:45:47.014760+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52951, "dest_port": 53}}'); INSERT INTO alerts VALUES(5219,1773089147.014760017,'{"timestamp": "2026-03-09T21:45:47.014760+0100", "flow_id": 907821931387152, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52705, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32762, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:45:47.014760+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52705, "dest_port": 53}}'); INSERT INTO alerts VALUES(5220,1773089147.014760971,'{"timestamp": "2026-03-09T21:45:47.014761+0100", "flow_id": 907823327506691, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51410, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59372, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:45:47.014761+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51410, "dest_port": 53}}'); INSERT INTO alerts VALUES(5221,1773089147.014760971,'{"timestamp": "2026-03-09T21:45:47.014761+0100", "flow_id": 907826870603317, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65380, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32594, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:45:47.014761+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65380, "dest_port": 53}}'); INSERT INTO alerts VALUES(5222,1773089172.990392923,'{"timestamp": "2026-03-09T21:46:12.990393+0100", "flow_id": 1157484011074589, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62424, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55193, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:46:12.990393+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62424, "dest_port": 53}}'); INSERT INTO alerts VALUES(5223,1773089183.057595968,'{"timestamp": "2026-03-09T21:46:23.057596+0100", "flow_id": 2125177267717254, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 42532, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:46:23.036054+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 42532, "dest_port": 853}}'); INSERT INTO alerts VALUES(5224,1773089204.102905036,'{"timestamp": "2026-03-09T21:46:44.102905+0100", "flow_id": 1286400509600511, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50615, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12309, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:46:44.102905+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50615, "dest_port": 53}}'); INSERT INTO alerts VALUES(5225,1773089204.103509903,'{"timestamp": "2026-03-09T21:46:44.103510+0100", "flow_id": 1288999452374616, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55697, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27771, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:46:44.103510+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55697, "dest_port": 53}}'); INSERT INTO alerts VALUES(5226,1773089204.702668905,'{"timestamp": "2026-03-09T21:46:44.702669+0100", "flow_id": 1329090547759880, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64180, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4847, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:46:44.702669+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64180, "dest_port": 53}}'); INSERT INTO alerts VALUES(5227,1773089215.968878985,'{"timestamp": "2026-03-09T21:46:55.968879+0100", "flow_id": 2096657345207702, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 58106, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:46:55.946918+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 58106, "dest_port": 853}}'); INSERT INTO alerts VALUES(5228,1773089215.972116948,'{"timestamp": "2026-03-09T21:46:55.972117+0100", "flow_id": 2099384398055063, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 35438, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:46:55.947553+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 35438, "dest_port": 853}}'); INSERT INTO alerts VALUES(5229,1773089221.814724922,'{"timestamp": "2026-03-09T21:47:01.814725+0100", "flow_id": 1528892770208241, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52292, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25679, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:47:01.814725+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52292, "dest_port": 53}}'); INSERT INTO alerts VALUES(5230,1773089221.815664053,'{"timestamp": "2026-03-09T21:47:01.815664+0100", "flow_id": 1532928181924538, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60846, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45624, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:47:01.815664+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60846, "dest_port": 53}}'); INSERT INTO alerts VALUES(5231,1773089222.551078082,'{"timestamp": "2026-03-09T21:47:02.551078+0100", "flow_id": 1803914563256467, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52897, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2890, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T21:47:02.551078+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52897, "dest_port": 53}}'); INSERT INTO alerts VALUES(5232,1773089222.657875061,'{"timestamp": "2026-03-09T21:47:02.657875+0100", "flow_id": 1699655476893759, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55574, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37694, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T21:47:02.657875+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55574, "dest_port": 53}}'); INSERT INTO alerts VALUES(5233,1773089227.21018505,'{"timestamp": "2026-03-09T21:47:07.210185+0100", "flow_id": 902740693250609, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60969, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6762, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T21:47:07.210185+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60969, "dest_port": 53}}'); INSERT INTO alerts VALUES(5234,1773089234.315025092,'{"timestamp": "2026-03-09T21:47:14.315025+0100", "flow_id": 790072281972496, "event_type": "alert", "src_ip": "147.185.132.246", "src_port": 54243, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:47:14.315025+0100", "src_ip": "147.185.132.246", "dest_ip": "134.19.55.199", "src_port": 54243, "dest_port": 80}}'); INSERT INTO alerts VALUES(5235,1773089245.715569972,'{"timestamp": "2026-03-09T21:47:25.715570+0100", "flow_id": 1665976825563537, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 48883, "dest_ip": "134.19.55.199", "dest_port": 2234, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:47:25.715570+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 48883, "dest_port": 2234}}'); INSERT INTO alerts VALUES(5236,1773089245.715569972,'{"timestamp": "2026-03-09T21:47:25.715570+0100", "flow_id": 1665976825563537, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 48883, "dest_ip": "134.19.55.199", "dest_port": 2234, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:47:25.715570+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.55.199", "src_port": 48883, "dest_port": 2234}}'); INSERT INTO alerts VALUES(5237,1773089249.9374609,'{"timestamp": "2026-03-09T21:47:29.937461+0100", "flow_id": 367190143003236, "event_type": "alert", "src_ip": "167.94.146.44", "src_port": 57372, "dest_ip": "134.19.55.199", "dest_port": 9197, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:47:29.937461+0100", "src_ip": "167.94.146.44", "dest_ip": "134.19.55.199", "src_port": 57372, "dest_port": 9197}}'); INSERT INTO alerts VALUES(5238,1773089253.522448063,'{"timestamp": "2026-03-09T21:47:33.522448+0100", "flow_id": 1680948279892141, "event_type": "alert", "src_ip": "198.235.24.49", "src_port": 54522, "dest_ip": "134.19.55.199", "dest_port": 10001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:47:33.522448+0100", "src_ip": "198.235.24.49", "dest_ip": "134.19.55.199", "src_port": 54522, "dest_port": 10001}}'); INSERT INTO alerts VALUES(5239,1773089289.792073966,'{"timestamp": "2026-03-09T21:48:09.792074+0100", "flow_id": 305708324635605, "event_type": "alert", "src_ip": "167.94.146.60", "src_port": 16016, "dest_ip": "134.19.55.199", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:48:09.792074+0100", "src_ip": "167.94.146.60", "dest_ip": "134.19.55.199", "src_port": 16016, "dest_port": 443}}'); INSERT INTO alerts VALUES(5240,1773089335.971241951,'{"timestamp": "2026-03-09T21:48:55.971242+0100", "flow_id": 2107759380755718, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 50942, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:48:55.949502+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 50942, "dest_port": 853}}'); INSERT INTO alerts VALUES(5241,1773089394.647665977,'{"timestamp": "2026-03-09T21:49:54.647666+0100", "flow_id": 811380334087863, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:49:54.647666+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5242,1773089394.648097038,'{"timestamp": "2026-03-09T21:49:54.648097+0100", "flow_id": 813234773941164, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:49:54.648097+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5243,1773089401.965943098,'{"timestamp": "2026-03-09T21:50:01.965943+0100", "flow_id": 489519282680067, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51410, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59372, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:50:01.965943+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51410, "dest_port": 53}}'); INSERT INTO alerts VALUES(5244,1773089401.965944052,'{"timestamp": "2026-03-09T21:50:01.965944+0100", "flow_id": 489527120743989, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65380, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32594, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:50:01.965944+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65380, "dest_port": 53}}'); INSERT INTO alerts VALUES(5245,1773089401.965944052,'{"timestamp": "2026-03-09T21:50:01.965944+0100", "flow_id": 489523927259476, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59484, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10029, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:50:01.965944+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59484, "dest_port": 53}}'); INSERT INTO alerts VALUES(5246,1773089401.965944052,'{"timestamp": "2026-03-09T21:50:01.965944+0100", "flow_id": 489527071975910, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53327, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51084, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:50:01.965944+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53327, "dest_port": 53}}'); INSERT INTO alerts VALUES(5247,1773089403.991086959,'{"timestamp": "2026-03-09T21:50:03.991087+0100", "flow_id": 878989362461064, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 46715, "dest_ip": "134.19.55.199", "dest_port": 20975, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:50:03.991087+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 46715, "dest_port": 20975}}'); INSERT INTO alerts VALUES(5248,1773089438.545499087,'{"timestamp": "2026-03-09T21:50:38.545499+0100", "flow_id": 1779954100919920, "event_type": "alert", "src_ip": "167.94.138.109", "src_port": 16580, "dest_ip": "134.19.55.199", "dest_port": 34396, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:50:38.545499+0100", "src_ip": "167.94.138.109", "dest_ip": "134.19.55.199", "src_port": 16580, "dest_port": 34396}}'); INSERT INTO alerts VALUES(5249,1773089444.507883071,'{"timestamp": "2026-03-09T21:50:44.507883+0100", "flow_id": 1514213122397969, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50320, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 2, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 2, "id": 55887, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 1, "bytes_toserver": 153, "bytes_toclient": 116, "start": "2026-03-09T21:49:25.090411+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50320, "dest_port": 53}}'); INSERT INTO alerts VALUES(5250,1773089448.258658885,'{"timestamp": "2026-03-09T21:50:48.258659+0100", "flow_id": 266510436666502, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56975, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32932, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T21:50:48.258659+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56975, "dest_port": 53}}'); INSERT INTO alerts VALUES(5251,1773089451.598849058,'{"timestamp": "2026-03-09T21:50:51.598849+0100", "flow_id": 883190169388667, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 16157, "dest_ip": "134.19.55.199", "dest_port": 359, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:50:51.598849+0100", "src_ip": "167.94.146.32", "dest_ip": "134.19.55.199", "src_port": 16157, "dest_port": 359}}'); INSERT INTO alerts VALUES(5252,1773089455.975539923,'{"timestamp": "2026-03-09T21:50:55.975540+0100", "flow_id": 2131805788594012, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 52022, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:50:55.955101+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 52022, "dest_port": 853}}'); INSERT INTO alerts VALUES(5253,1773089455.978626013,'{"timestamp": "2026-03-09T21:50:55.978626+0100", "flow_id": 2135000037608389, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 42666, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T21:50:55.955845+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 42666, "dest_port": 853}}'); INSERT INTO alerts VALUES(5254,1773089493.015248061,'{"timestamp": "2026-03-09T21:51:33.015248+0100", "flow_id": 1472866327196911, "event_type": "alert", "src_ip": "205.210.31.84", "src_port": 56533, "dest_ip": "134.19.55.199", "dest_port": 8009, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:51:33.015248+0100", "src_ip": "205.210.31.84", "dest_ip": "134.19.55.199", "src_port": 56533, "dest_port": 8009}}'); INSERT INTO alerts VALUES(5255,1773089509.227853059,'{"timestamp": "2026-03-09T21:51:49.227853+0100", "flow_id": 1541574147654460, "event_type": "alert", "src_ip": "193.163.125.186", "src_port": 54481, "dest_ip": "134.19.55.199", "dest_port": 4901, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:51:49.227853+0100", "src_ip": "193.163.125.186", "dest_ip": "134.19.55.199", "src_port": 54481, "dest_port": 4901}}'); INSERT INTO alerts VALUES(5256,1773089541.303365945,'{"timestamp": "2026-03-09T21:52:21.303366+0100", "flow_id": 1584424817218261, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 46889, "dest_ip": "134.19.55.199", "dest_port": 52407, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:52:21.303366+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 46889, "dest_port": 52407}}'); INSERT INTO alerts VALUES(5257,1773089586.039561033,'{"timestamp": "2026-03-09T21:53:06.039561+0100", "flow_id": 732865770051237, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54957, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59882, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T21:53:06.039561+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54957, "dest_port": 53}}'); INSERT INTO alerts VALUES(5258,1773089586.853163004,'{"timestamp": "2026-03-09T21:53:06.853163+0100", "flow_id": 568084971210760, "event_type": "alert", "src_ip": "45.156.87.91", "src_port": 49723, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:53:06.853163+0100", "src_ip": "45.156.87.91", "dest_ip": "134.19.55.199", "src_port": 49723, "dest_port": 8080}}'); INSERT INTO alerts VALUES(5259,1773089648.685578107,'{"timestamp": "2026-03-09T21:54:08.685578+0100", "flow_id": 129789169063095, "event_type": "alert", "src_ip": "147.185.132.213", "src_port": 51874, "dest_ip": "134.19.55.199", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 59, "bytes_toclient": 0, "start": "2026-03-09T21:54:08.685578+0100", "src_ip": "147.185.132.213", "dest_ip": "134.19.55.199", "src_port": 51874, "dest_port": 53}}'); INSERT INTO alerts VALUES(5260,1773089648.685578107,'{"timestamp": "2026-03-09T21:54:08.685578+0100", "flow_id": 129789169063095, "event_type": "alert", "src_ip": "147.185.132.213", "src_port": 51874, "dest_ip": "134.19.55.199", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2101616, "rev": 9, "signature": "GPL DNS named version attempt", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_07_26"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 59, "bytes_toclient": 0, "start": "2026-03-09T21:54:08.685578+0100", "src_ip": "147.185.132.213", "dest_ip": "134.19.55.199", "src_port": 51874, "dest_port": 53}}'); INSERT INTO alerts VALUES(5261,1773089672.654748917,'{"timestamp": "2026-03-09T21:54:32.654749+0100", "flow_id": 278852700405194, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 13443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:54:32.654749+0100", "src_ip": "185.156.73.181", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 13443}}'); INSERT INTO alerts VALUES(5262,1773089684.903224945,'{"timestamp": "2026-03-09T21:54:44.903225+0100", "flow_id": 1346048249159558, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 54656, "dest_ip": "134.19.55.199", "dest_port": 9090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:54:44.903225+0100", "src_ip": "87.121.84.57", "dest_ip": "134.19.55.199", "src_port": 54656, "dest_port": 9090}}'); INSERT INTO alerts VALUES(5263,1773089691.066941976,'{"timestamp": "2026-03-09T21:54:51.066942+0100", "flow_id": 850464863056925, "event_type": "alert", "src_ip": "43.228.157.19", "src_port": 53265, "dest_ip": "134.19.55.199", "dest_port": 2016, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:54:51.066942+0100", "src_ip": "43.228.157.19", "dest_ip": "134.19.55.199", "src_port": 53265, "dest_port": 2016}}'); INSERT INTO alerts VALUES(5264,1773089708.060187102,'{"timestamp": "2026-03-09T21:55:08.060187+0100", "flow_id": 1384401985818295, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:55:08.060187+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5265,1773089708.060188056,'{"timestamp": "2026-03-09T21:55:08.060188+0100", "flow_id": 1384409589734316, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:55:08.060188+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5266,1773089746.665136099,'{"timestamp": "2026-03-09T21:55:46.665136+0100", "flow_id": 604938072570946, "event_type": "alert", "src_ip": "89.248.163.200", "src_port": 49735, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T21:55:46.665136+0100", "src_ip": "89.248.163.200", "dest_ip": "134.19.55.199", "src_port": 49735, "dest_port": 5432}}'); INSERT INTO alerts VALUES(5267,1773089798.652417898,'{"timestamp": "2026-03-09T21:56:38.652418+0100", "flow_id": 1957689988031769, "event_type": "alert", "src_ip": "162.217.98.180", "src_port": 38800, "dest_ip": "134.19.55.199", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 414, "bytes_toclient": 0, "start": "2026-03-09T21:56:38.652418+0100", "src_ip": "162.217.98.180", "dest_ip": "134.19.55.199", "src_port": 38800, "dest_port": 5060}}'); INSERT INTO alerts VALUES(5268,1773089812.403975009,'{"timestamp": "2026-03-09T21:56:52.403975+0100", "flow_id": 1172112036563814, "event_type": "alert", "src_ip": "205.210.31.240", "src_port": 55148, "dest_ip": "134.19.55.199", "dest_port": 9444, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:56:52.403975+0100", "src_ip": "205.210.31.240", "dest_ip": "134.19.55.199", "src_port": 55148, "dest_port": 9444}}'); INSERT INTO alerts VALUES(5269,1773089819.820422888,'{"timestamp": "2026-03-09T21:56:59.820423+0100", "flow_id": 990418329106963, "event_type": "alert", "src_ip": "147.185.132.105", "src_port": 55270, "dest_ip": "134.19.55.199", "dest_port": 123, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "ntp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T21:56:59.820423+0100", "src_ip": "147.185.132.105", "dest_ip": "134.19.55.199", "src_port": 55270, "dest_port": 123}}'); INSERT INTO alerts VALUES(5270,1773089823.003855943,'{"timestamp": "2026-03-09T21:57:03.003856+0100", "flow_id": 1986888010603594, "event_type": "alert", "src_ip": "193.163.125.201", "src_port": 58910, "dest_ip": "134.19.55.199", "dest_port": 20254, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:57:03.003856+0100", "src_ip": "193.163.125.201", "dest_ip": "134.19.55.199", "src_port": 58910, "dest_port": 20254}}'); INSERT INTO alerts VALUES(5271,1773089825.898294926,'{"timestamp": "2026-03-09T21:57:05.898295+0100", "flow_id": 480450043654064, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62932, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37186, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:57:05.898295+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62932, "dest_port": 53}}'); INSERT INTO alerts VALUES(5272,1773089825.898294926,'{"timestamp": "2026-03-09T21:57:05.898295+0100", "flow_id": 480451119792883, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51571, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14620, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:57:05.898295+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51571, "dest_port": 53}}'); INSERT INTO alerts VALUES(5273,1773089832.772905112,'{"timestamp": "2026-03-09T21:57:12.772905+0100", "flow_id": 223379368282020, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60385, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42784, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T21:57:12.772905+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60385, "dest_port": 53}}'); INSERT INTO alerts VALUES(5274,1773089832.77324295,'{"timestamp": "2026-03-09T21:57:12.773243+0100", "flow_id": 224831522900150, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56838, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62094, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T21:57:12.773243+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56838, "dest_port": 53}}'); INSERT INTO alerts VALUES(5275,1773089833.312222958,'{"timestamp": "2026-03-09T21:57:13.312223+0100", "flow_id": 496563611108560, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56169, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50754, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:57:13.312223+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56169, "dest_port": 53}}'); INSERT INTO alerts VALUES(5276,1773089833.312544107,'{"timestamp": "2026-03-09T21:57:13.312544+0100", "flow_id": 497943424511622, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61013, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25775, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T21:57:13.312544+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61013, "dest_port": 53}}'); INSERT INTO alerts VALUES(5277,1773089841.412508964,'{"timestamp": "2026-03-09T21:57:21.412509+0100", "flow_id": 364338281895859, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57423, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52116, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T21:57:21.412509+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57423, "dest_port": 53}}'); INSERT INTO alerts VALUES(5278,1773089907.685162067,'{"timestamp": "2026-03-09T21:58:27.685162+0100", "flow_id": 972427240099382, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65206, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30428, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-09T21:58:27.685162+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65206, "dest_port": 53}}'); INSERT INTO alerts VALUES(5279,1773089940.317640067,'{"timestamp": "2026-03-09T21:59:00.317640+0100", "flow_id": 1364254294232759, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57993, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38974, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:59:00.317640+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57993, "dest_port": 53}}'); INSERT INTO alerts VALUES(5280,1773089940.317640067,'{"timestamp": "2026-03-09T21:59:00.317640+0100", "flow_id": 1364257603181484, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60124, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8310, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T21:59:00.317640+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60124, "dest_port": 53}}'); INSERT INTO alerts VALUES(5281,1773089968.062616109,'{"timestamp": "2026-03-09T21:59:28.062616+0100", "flow_id": 268937252137919, "event_type": "alert", "src_ip": "193.163.125.192", "src_port": 53562, "dest_ip": "134.19.55.199", "dest_port": 8015, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T21:59:28.062616+0100", "src_ip": "193.163.125.192", "dest_ip": "134.19.55.199", "src_port": 53562, "dest_port": 8015}}'); INSERT INTO alerts VALUES(5282,1773089974.562113046,'{"timestamp": "2026-03-09T21:59:34.562113+0100", "flow_id": 1851307184390038, "event_type": "alert", "src_ip": "167.94.138.110", "src_port": 23966, "dest_ip": "134.19.55.199", "dest_port": 52975, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T21:59:34.562113+0100", "src_ip": "167.94.138.110", "dest_ip": "134.19.55.199", "src_port": 23966, "dest_port": 52975}}'); INSERT INTO alerts VALUES(5283,1773089991.998507022,'{"timestamp": "2026-03-09T21:59:51.998507+0100", "flow_id": 2036758973816199, "event_type": "alert", "src_ip": "205.210.31.196", "src_port": 44278, "dest_ip": "134.19.55.199", "dest_port": 13146, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-09T21:59:51.998507+0100", "src_ip": "205.210.31.196", "dest_ip": "134.19.55.199", "src_port": 44278, "dest_port": 13146}}'); INSERT INTO alerts VALUES(5284,1773090007.946175098,'{"timestamp": "2026-03-09T22:00:07.946175+0100", "flow_id": 2093466895395512, "event_type": "alert", "src_ip": "178.20.210.152", "src_port": 46077, "dest_ip": "134.19.55.199", "dest_port": 58222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:00:07.946175+0100", "src_ip": "178.20.210.152", "dest_ip": "134.19.55.199", "src_port": 46077, "dest_port": 58222}}'); INSERT INTO alerts VALUES(5285,1773090008.594554901,'{"timestamp": "2026-03-09T22:00:08.594555+0100", "flow_id": 20320225007956, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59484, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10029, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:00:08.594555+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59484, "dest_port": 53}}'); INSERT INTO alerts VALUES(5286,1773090008.594556094,'{"timestamp": "2026-03-09T22:00:08.594556+0100", "flow_id": 20327664691686, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53327, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51084, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:00:08.594556+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53327, "dest_port": 53}}'); INSERT INTO alerts VALUES(5287,1773090008.594556094,'{"timestamp": "2026-03-09T22:00:08.594556+0100", "flow_id": 20324447691373, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59835, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11937, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:00:08.594556+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59835, "dest_port": 53}}'); INSERT INTO alerts VALUES(5288,1773090008.594556094,'{"timestamp": "2026-03-09T22:00:08.594556+0100", "flow_id": 20326786239945, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51991, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57936, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:00:08.594556+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51991, "dest_port": 53}}'); INSERT INTO alerts VALUES(5289,1773090031.63259101,'{"timestamp": "2026-03-09T22:00:31.632591+0100", "flow_id": 2154008543774175, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56256, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27664, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T22:00:31.632591+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56256, "dest_port": 53}}'); INSERT INTO alerts VALUES(5290,1773090031.63259101,'{"timestamp": "2026-03-09T22:00:31.632591+0100", "flow_id": 2154010937222583, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64389, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59611, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-09T22:00:31.632591+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64389, "dest_port": 53}}'); INSERT INTO alerts VALUES(5291,1773090053.720166921,'{"timestamp": "2026-03-09T22:00:53.720167+0100", "flow_id": 1685722403045304, "event_type": "alert", "src_ip": "147.185.132.99", "src_port": 57314, "dest_ip": "134.19.55.199", "dest_port": 5050, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:00:53.720167+0100", "src_ip": "147.185.132.99", "dest_ip": "134.19.55.199", "src_port": 57314, "dest_port": 5050}}'); INSERT INTO alerts VALUES(5292,1773090076.534187078,'{"timestamp": "2026-03-09T22:01:16.534187+0100", "flow_id": 1168419243859824, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60847, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59230, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:01:16.534187+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60847, "dest_port": 53}}'); INSERT INTO alerts VALUES(5293,1773090083.384645938,'{"timestamp": "2026-03-09T22:01:23.384646+0100", "flow_id": 1089095967847481, "event_type": "alert", "src_ip": "198.235.24.66", "src_port": 49192, "dest_ip": "134.19.55.199", "dest_port": 69, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "tftp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 42, "bytes_toclient": 0, "start": "2026-03-09T22:01:23.384646+0100", "src_ip": "198.235.24.66", "dest_ip": "134.19.55.199", "src_port": 49192, "dest_port": 69}}'); INSERT INTO alerts VALUES(5294,1773090088.804280043,'{"timestamp": "2026-03-09T22:01:28.804280+0100", "flow_id": 76658987229190, "event_type": "alert", "src_ip": "130.12.180.52", "src_port": 59044, "dest_ip": "134.19.55.199", "dest_port": 10000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:01:28.804280+0100", "src_ip": "130.12.180.52", "dest_ip": "134.19.55.199", "src_port": 59044, "dest_port": 10000}}'); INSERT INTO alerts VALUES(5295,1773090088.804280043,'{"timestamp": "2026-03-09T22:01:28.804280+0100", "flow_id": 76658987229190, "event_type": "alert", "src_ip": "130.12.180.52", "src_port": 59044, "dest_ip": "134.19.55.199", "dest_port": 10000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:01:28.804280+0100", "src_ip": "130.12.180.52", "dest_ip": "134.19.55.199", "src_port": 59044, "dest_port": 10000}}'); INSERT INTO alerts VALUES(5296,1773090089.676909923,'{"timestamp": "2026-03-09T22:01:29.676910+0100", "flow_id": 374034206202071, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52542, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47016, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:01:29.676910+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52542, "dest_port": 53}}'); INSERT INTO alerts VALUES(5297,1773090095.663539887,'{"timestamp": "2026-03-09T22:01:35.663540+0100", "flow_id": 2005458331902573, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59835, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11937, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:01:35.663540+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59835, "dest_port": 53}}'); INSERT INTO alerts VALUES(5298,1773090095.663539887,'{"timestamp": "2026-03-09T22:01:35.663540+0100", "flow_id": 2005460670451145, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51991, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57936, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:01:35.663540+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51991, "dest_port": 53}}'); INSERT INTO alerts VALUES(5299,1773090095.663539887,'{"timestamp": "2026-03-09T22:01:35.663540+0100", "flow_id": 2005458490772910, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56392, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33874, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:01:35.663540+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56392, "dest_port": 53}}'); INSERT INTO alerts VALUES(5300,1773090095.663541078,'{"timestamp": "2026-03-09T22:01:35.663541+0100", "flow_id": 2005463585061397, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57108, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2625, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:01:35.663541+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57108, "dest_port": 53}}'); INSERT INTO alerts VALUES(5301,1773090098.926951886,'{"timestamp": "2026-03-09T22:01:38.926952+0100", "flow_id": 603529680642578, "event_type": "alert", "src_ip": "198.235.24.92", "src_port": 49678, "dest_ip": "134.19.55.199", "dest_port": 8081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:01:38.926952+0100", "src_ip": "198.235.24.92", "dest_ip": "134.19.55.199", "src_port": 49678, "dest_port": 8081}}'); INSERT INTO alerts VALUES(5302,1773090150.097768069,'{"timestamp": "2026-03-09T22:02:30.097768+0100", "flow_id": 1827288273768150, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52998, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39515, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:02:30.097768+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52998, "dest_port": 53}}'); INSERT INTO alerts VALUES(5303,1773090193.854485034,'{"timestamp": "2026-03-09T22:03:13.854485+0100", "flow_id": 292286632838992, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61845, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37396, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:03:13.854485+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61845, "dest_port": 53}}'); INSERT INTO alerts VALUES(5304,1773090193.854800939,'{"timestamp": "2026-03-09T22:03:13.854801+0100", "flow_id": 293644977777907, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61032, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31781, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:03:13.854801+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61032, "dest_port": 53}}'); INSERT INTO alerts VALUES(5305,1773090194.357815981,'{"timestamp": "2026-03-09T22:03:14.357816+0100", "flow_id": 692387355931040, "event_type": "alert", "src_ip": "66.132.153.156", "src_port": 25892, "dest_ip": "134.19.55.199", "dest_port": 22122, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:03:14.357816+0100", "src_ip": "66.132.153.156", "dest_ip": "134.19.55.199", "src_port": 25892, "dest_port": 22122}}'); INSERT INTO alerts VALUES(5306,1773090197.596067905,'{"timestamp": "2026-03-09T22:03:17.596068+0100", "flow_id": 1434194573275662, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49277, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59171, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:03:17.596068+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49277, "dest_port": 53}}'); INSERT INTO alerts VALUES(5307,1773090197.596067905,'{"timestamp": "2026-03-09T22:03:17.596068+0100", "flow_id": 1434196569619713, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59204, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36941, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:03:17.596068+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59204, "dest_port": 53}}'); INSERT INTO alerts VALUES(5308,1773090203.359195947,'{"timestamp": "2026-03-09T22:03:23.359196+0100", "flow_id": 979785940749742, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56392, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33874, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:03:23.359196+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56392, "dest_port": 53}}'); INSERT INTO alerts VALUES(5309,1773090203.359195947,'{"timestamp": "2026-03-09T22:03:23.359196+0100", "flow_id": 979786740070933, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57108, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2625, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:03:23.359196+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57108, "dest_port": 53}}'); INSERT INTO alerts VALUES(5310,1773090203.359195947,'{"timestamp": "2026-03-09T22:03:23.359196+0100", "flow_id": 979785818944318, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54169, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7813, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:03:23.359196+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54169, "dest_port": 53}}'); INSERT INTO alerts VALUES(5311,1773090203.359196902,'{"timestamp": "2026-03-09T22:03:23.359197+0100", "flow_id": 979791977628375, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57476, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59182, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:03:23.359197+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57476, "dest_port": 53}}'); INSERT INTO alerts VALUES(5312,1773090203.731808901,'{"timestamp": "2026-03-09T22:03:23.731809+0100", "flow_id": 891299785875251, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49880, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38720, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:03:23.731809+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49880, "dest_port": 53}}'); INSERT INTO alerts VALUES(5313,1773090203.732105971,'{"timestamp": "2026-03-09T22:03:23.732106+0100", "flow_id": 892572474561369, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53992, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17713, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:03:23.732106+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53992, "dest_port": 53}}'); INSERT INTO alerts VALUES(5314,1773090204.184272051,'{"timestamp": "2026-03-09T22:03:24.184272+0100", "flow_id": 1354394504424548, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58104, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58877, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:03:24.184272+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58104, "dest_port": 53}}'); INSERT INTO alerts VALUES(5315,1773090206.460578918,'{"timestamp": "2026-03-09T22:03:26.460579+0100", "flow_id": 1696697808335804, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49428, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7813, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:03:26.460579+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49428, "dest_port": 53}}'); INSERT INTO alerts VALUES(5316,1773090206.461874008,'{"timestamp": "2026-03-09T22:03:26.461874+0100", "flow_id": 1702262887908560, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49688, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59182, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:03:26.461874+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49688, "dest_port": 53}}'); INSERT INTO alerts VALUES(5317,1773090221.794187068,'{"timestamp": "2026-03-09T22:03:41.794187+0100", "flow_id": 1440686190769918, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54533, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41924, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:03:41.794187+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54533, "dest_port": 53}}'); INSERT INTO alerts VALUES(5318,1773090221.794188023,'{"timestamp": "2026-03-09T22:03:41.794188+0100", "flow_id": 1440686651768091, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54943, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36705, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:03:41.794188+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54943, "dest_port": 53}}'); INSERT INTO alerts VALUES(5319,1773090224.391908884,'{"timestamp": "2026-03-09T22:03:44.391909+0100", "flow_id": 275862935214331, "event_type": "alert", "src_ip": "167.94.146.46", "src_port": 34008, "dest_ip": "134.19.55.199", "dest_port": 46158, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:03:44.391909+0100", "src_ip": "167.94.146.46", "dest_ip": "134.19.55.199", "src_port": 34008, "dest_port": 46158}}'); INSERT INTO alerts VALUES(5320,1773090249.210253954,'{"timestamp": "2026-03-09T22:04:09.210254+0100", "flow_id": 340086613672502, "event_type": "alert", "src_ip": "147.185.132.48", "src_port": 53410, "dest_ip": "134.19.55.199", "dest_port": 8010, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:04:09.210254+0100", "src_ip": "147.185.132.48", "dest_ip": "134.19.55.199", "src_port": 53410, "dest_port": 8010}}'); INSERT INTO alerts VALUES(5321,1773090255.462187051,'{"timestamp": "2026-03-09T22:04:15.462187+0100", "flow_id": 1985080349839717, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58224, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6351, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:04:15.462187+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58224, "dest_port": 53}}'); INSERT INTO alerts VALUES(5322,1773090255.462188006,'{"timestamp": "2026-03-09T22:04:15.462188+0100", "flow_id": 1985085473483673, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65078, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40247, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:04:15.462188+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65078, "dest_port": 53}}'); INSERT INTO alerts VALUES(5323,1773090283.48025608,'{"timestamp": "2026-03-09T22:04:43.480256+0100", "flow_id": 936784223237286, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51641, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63662, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:04:43.480256+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51641, "dest_port": 53}}'); INSERT INTO alerts VALUES(5324,1773090283.48025608,'{"timestamp": "2026-03-09T22:04:43.480256+0100", "flow_id": 936788150215128, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 52620, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57364, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:04:43.480256+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 52620, "dest_port": 53}}'); INSERT INTO alerts VALUES(5325,1773090300.659949064,'{"timestamp": "2026-03-09T22:05:00.659949+0100", "flow_id": 1145610010572535, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63430, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34438, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:05:00.659949+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63430, "dest_port": 53}}'); INSERT INTO alerts VALUES(5326,1773090300.659949064,'{"timestamp": "2026-03-09T22:05:00.659949+0100", "flow_id": 1145612452120750, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51234, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42461, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:05:00.659949+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51234, "dest_port": 53}}'); INSERT INTO alerts VALUES(5327,1773090365.16129589,'{"timestamp": "2026-03-09T22:06:05.161296+0100", "flow_id": 1537189810943742, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54533, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41924, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:06:05.161296+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54533, "dest_port": 53}}'); INSERT INTO alerts VALUES(5328,1773090365.16129589,'{"timestamp": "2026-03-09T22:06:05.161296+0100", "flow_id": 1537185976974619, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54943, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36705, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:06:05.161296+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54943, "dest_port": 53}}'); INSERT INTO alerts VALUES(5329,1773090365.162143946,'{"timestamp": "2026-03-09T22:06:05.162144+0100", "flow_id": 1540830062247492, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58695, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21396, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:06:05.162144+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58695, "dest_port": 53}}'); INSERT INTO alerts VALUES(5330,1773090365.162143946,'{"timestamp": "2026-03-09T22:06:05.162144+0100", "flow_id": 1540828281064207, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49288, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52609, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:06:05.162144+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49288, "dest_port": 53}}'); INSERT INTO alerts VALUES(5331,1773090366.87421608,'{"timestamp": "2026-03-09T22:06:06.874216+0100", "flow_id": 1784406915751271, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48748, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:06:06.874216+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51367, "dest_port": 53}}'); INSERT INTO alerts VALUES(5332,1773090366.87421608,'{"timestamp": "2026-03-09T22:06:06.874216+0100", "flow_id": 1784406236000479, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57060, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17501, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:06:06.874216+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57060, "dest_port": 53}}'); INSERT INTO alerts VALUES(5333,1773090383.419435978,'{"timestamp": "2026-03-09T22:06:23.419436+0100", "flow_id": 2082939767158283, "event_type": "alert", "src_ip": "193.163.125.217", "src_port": 42035, "dest_ip": "134.19.55.199", "dest_port": 25, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:06:23.419436+0100", "src_ip": "193.163.125.217", "dest_ip": "134.19.55.199", "src_port": 42035, "dest_port": 25}}'); INSERT INTO alerts VALUES(5334,1773090413.265372038,'{"timestamp": "2026-03-09T22:06:53.265372+0100", "flow_id": 1421241141086945, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55122, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4560, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:06:53.265372+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55122, "dest_port": 53}}'); INSERT INTO alerts VALUES(5335,1773090413.265372991,'{"timestamp": "2026-03-09T22:06:53.265373+0100", "flow_id": 1421243805649737, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61054, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61100, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:06:53.265373+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61054, "dest_port": 53}}'); INSERT INTO alerts VALUES(5336,1773090416.797909976,'{"timestamp": "2026-03-09T22:06:56.797910+0100", "flow_id": 49299219977268, "event_type": "alert", "src_ip": "195.184.76.217", "src_port": 26720, "dest_ip": "134.19.55.199", "dest_port": 5412, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:06:56.797910+0100", "src_ip": "195.184.76.217", "dest_ip": "134.19.55.199", "src_port": 26720, "dest_port": 5412}}'); INSERT INTO alerts VALUES(5337,1773090426.110908031,'{"timestamp": "2026-03-09T22:07:06.110908+0100", "flow_id": 663777063442891, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 60004, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T22:07:06.089011+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 60004, "dest_port": 853}}'); INSERT INTO alerts VALUES(5338,1773090426.125607967,'{"timestamp": "2026-03-09T22:07:06.125608+0100", "flow_id": 719709222790875, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 42894, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T22:07:06.102034+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 42894, "dest_port": 853}}'); INSERT INTO alerts VALUES(5339,1773090431.892286062,'{"timestamp": "2026-03-09T22:07:11.892286+0100", "flow_id": 2143489584322459, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60291, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13898, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:07:11.892286+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60291, "dest_port": 53}}'); INSERT INTO alerts VALUES(5340,1773090431.892287015,'{"timestamp": "2026-03-09T22:07:11.892287+0100", "flow_id": 2143496726596088, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60982, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25375, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:07:11.892287+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60982, "dest_port": 53}}'); INSERT INTO alerts VALUES(5341,1773090433.230223894,'{"timestamp": "2026-03-09T22:07:13.230224+0100", "flow_id": 425858252782973, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60299, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45835, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:07:13.230224+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60299, "dest_port": 53}}'); INSERT INTO alerts VALUES(5342,1773090433.230223894,'{"timestamp": "2026-03-09T22:07:13.230224+0100", "flow_id": 425856031437183, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61544, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59124, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:07:13.230224+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61544, "dest_port": 53}}'); INSERT INTO alerts VALUES(5343,1773090467.145091057,'{"timestamp": "2026-03-09T22:07:47.145091+0100", "flow_id": 904638795439481, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64023, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35011, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T22:07:47.145091+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64023, "dest_port": 53}}'); INSERT INTO alerts VALUES(5344,1773090472.434804917,'{"timestamp": "2026-03-09T22:07:52.434805+0100", "flow_id": 178627167767462, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51783, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21118, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "ds-pn-final.ybp.gysm.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 79, "bytes_toclient": 0, "start": "2026-03-09T22:07:52.434805+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51783, "dest_port": 53}}'); INSERT INTO alerts VALUES(5345,1773090514.7832191,'{"timestamp": "2026-03-09T22:08:34.783219+0100", "flow_id": 830627689917519, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59189, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28094, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:08:34.783219+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59189, "dest_port": 53}}'); INSERT INTO alerts VALUES(5346,1773090514.783884048,'{"timestamp": "2026-03-09T22:08:34.783884+0100", "flow_id": 833481710124668, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63227, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64049, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:08:34.783884+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63227, "dest_port": 53}}'); INSERT INTO alerts VALUES(5347,1773090523.950438023,'{"timestamp": "2026-03-09T22:08:43.950438+0100", "flow_id": 985878504438200, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56372, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47152, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:08:43.950438+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56372, "dest_port": 53}}'); INSERT INTO alerts VALUES(5348,1773090523.950438023,'{"timestamp": "2026-03-09T22:08:43.950438+0100", "flow_id": 985876056739777, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60298, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1110, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:08:43.950438+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60298, "dest_port": 53}}'); INSERT INTO alerts VALUES(5349,1773090584.750133037,'{"timestamp": "2026-03-09T22:09:44.750133+0100", "flow_id": 125572552505829, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 48096, "dest_ip": "134.19.55.199", "dest_port": 59509, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:09:44.750133+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.55.199", "src_port": 48096, "dest_port": 59509}}'); INSERT INTO alerts VALUES(5350,1773090587.212312936,'{"timestamp": "2026-03-09T22:09:47.212313+0100", "flow_id": 911879641384960, "event_type": "alert", "src_ip": "198.235.24.99", "src_port": 52619, "dest_ip": "134.19.55.199", "dest_port": 41795, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:09:47.212313+0100", "src_ip": "198.235.24.99", "dest_ip": "134.19.55.199", "src_port": 52619, "dest_port": 41795}}'); INSERT INTO alerts VALUES(5351,1773090617.892977952,'{"timestamp": "2026-03-09T22:10:17.892978+0100", "flow_id": 457615315470411, "event_type": "alert", "src_ip": "147.185.132.13", "src_port": 49668, "dest_ip": "134.19.55.199", "dest_port": 4730, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:10:17.892978+0100", "src_ip": "147.185.132.13", "dest_ip": "134.19.55.199", "src_port": 49668, "dest_port": 4730}}'); INSERT INTO alerts VALUES(5352,1773090624.475457906,'{"timestamp": "2026-03-09T22:10:24.475458+0100", "flow_id": 71755422208456, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59543, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50287, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:10:24.475458+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59543, "dest_port": 53}}'); INSERT INTO alerts VALUES(5353,1773090624.475457906,'{"timestamp": "2026-03-09T22:10:24.475458+0100", "flow_id": 71753782245243, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57299, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36263, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:10:24.475458+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57299, "dest_port": 53}}'); INSERT INTO alerts VALUES(5354,1773090667.706119061,'{"timestamp": "2026-03-09T22:11:07.706119+0100", "flow_id": 1062434759685724, "event_type": "alert", "src_ip": "192.253.248.14", "src_port": 17044, "dest_ip": "134.19.55.199", "dest_port": 110, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:11:07.706119+0100", "src_ip": "192.253.248.14", "dest_ip": "134.19.55.199", "src_port": 17044, "dest_port": 110}}'); INSERT INTO alerts VALUES(5355,1773090697.618597984,'{"timestamp": "2026-03-09T22:11:37.618598+0100", "flow_id": 405062263730208, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57798, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43019, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "ds-pn-final.ybp.gysm.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 79, "bytes_toclient": 0, "start": "2026-03-09T22:11:37.618598+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57798, "dest_port": 53}}'); INSERT INTO alerts VALUES(5356,1773090770.056135893,'{"timestamp": "2026-03-09T22:12:50.056136+0100", "flow_id": 804054860635495, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48748, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:12:50.056136+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51367, "dest_port": 53}}'); INSERT INTO alerts VALUES(5357,1773090770.056135893,'{"timestamp": "2026-03-09T22:12:50.056136+0100", "flow_id": 804054180884703, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57060, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17501, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:12:50.056136+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57060, "dest_port": 53}}'); INSERT INTO alerts VALUES(5358,1773090770.056135893,'{"timestamp": "2026-03-09T22:12:50.056136+0100", "flow_id": 804054192422468, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58695, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21396, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:12:50.056136+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58695, "dest_port": 53}}'); INSERT INTO alerts VALUES(5359,1773090770.056137084,'{"timestamp": "2026-03-09T22:12:50.056137+0100", "flow_id": 804056706206479, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49288, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52609, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:12:50.056137+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49288, "dest_port": 53}}'); INSERT INTO alerts VALUES(5360,1773090770.056137084,'{"timestamp": "2026-03-09T22:12:50.056137+0100", "flow_id": 804059870645944, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57035, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39815, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:12:50.056137+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57035, "dest_port": 53}}'); INSERT INTO alerts VALUES(5361,1773090770.056137084,'{"timestamp": "2026-03-09T22:12:50.056137+0100", "flow_id": 804057846898492, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53251, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49287, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:12:50.056137+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53251, "dest_port": 53}}'); INSERT INTO alerts VALUES(5362,1773090770.287262917,'{"timestamp": "2026-03-09T22:12:50.287263+0100", "flow_id": 670837617730543, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58353, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38889, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:12:50.287263+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58353, "dest_port": 53}}'); INSERT INTO alerts VALUES(5363,1773090770.292939901,'{"timestamp": "2026-03-09T22:12:50.292940+0100", "flow_id": 695221292054791, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59715, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53570, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:12:50.292940+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59715, "dest_port": 53}}'); INSERT INTO alerts VALUES(5364,1773090778.021698952,'{"timestamp": "2026-03-09T22:12:58.021699+0100", "flow_id": 656147786733151, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58295, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "ds-pn-final.ybp.gysm.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 79, "bytes_toclient": 0, "start": "2026-03-09T22:12:58.021699+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57395, "dest_port": 53}}'); INSERT INTO alerts VALUES(5365,1773090778.732609033,'{"timestamp": "2026-03-09T22:12:58.732609+0100", "flow_id": 613259675123328, "event_type": "alert", "src_ip": "167.94.146.39", "src_port": 12681, "dest_ip": "134.19.55.199", "dest_port": 64485, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:12:58.732609+0100", "src_ip": "167.94.146.39", "dest_ip": "134.19.55.199", "src_port": 12681, "dest_port": 64485}}'); INSERT INTO alerts VALUES(5366,1773090827.160094022,'{"timestamp": "2026-03-09T22:13:47.160094+0100", "flow_id": 969076595245751, "event_type": "alert", "src_ip": "193.163.125.197", "src_port": 44605, "dest_ip": "134.19.55.199", "dest_port": 2105, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:13:47.160094+0100", "src_ip": "193.163.125.197", "dest_ip": "134.19.55.199", "src_port": 44605, "dest_port": 2105}}'); INSERT INTO alerts VALUES(5367,1773090842.39939499,'{"timestamp": "2026-03-09T22:14:02.399395+0100", "flow_id": 773040025730814, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 52954, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T22:14:02.376595+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 52954, "dest_port": 853}}'); INSERT INTO alerts VALUES(5368,1773090843.302898884,'{"timestamp": "2026-03-09T22:14:03.302899+0100", "flow_id": 924142277701551, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 42386, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T22:14:03.280704+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 42386, "dest_port": 853}}'); INSERT INTO alerts VALUES(5369,1773090855.029467106,'{"timestamp": "2026-03-09T22:14:15.029467+0100", "flow_id": 2096885269126303, "event_type": "alert", "src_ip": "91.196.152.217", "src_port": 8730, "dest_ip": "134.19.55.199", "dest_port": 20172, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:14:15.029467+0100", "src_ip": "91.196.152.217", "dest_ip": "134.19.55.199", "src_port": 8730, "dest_port": 20172}}'); INSERT INTO alerts VALUES(5370,1773090862.689268113,'{"timestamp": "2026-03-09T22:14:22.689268+0100", "flow_id": 1834486853484911, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59874, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36742, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:14:22.689268+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59874, "dest_port": 53}}'); INSERT INTO alerts VALUES(5371,1773090862.689268113,'{"timestamp": "2026-03-09T22:14:22.689268+0100", "flow_id": 1834485723919826, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56934, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26295, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:14:22.689268+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56934, "dest_port": 53}}'); INSERT INTO alerts VALUES(5372,1773090877.454386949,'{"timestamp": "2026-03-09T22:14:37.454387+0100", "flow_id": 1670106230221916, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56758, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61493, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:14:37.454387+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56758, "dest_port": 53}}'); INSERT INTO alerts VALUES(5373,1773090877.454806089,'{"timestamp": "2026-03-09T22:14:37.454806+0100", "flow_id": 1671905047673914, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52893, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:14:37.454806+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54176, "dest_port": 53}}'); INSERT INTO alerts VALUES(5374,1773090895.941608906,'{"timestamp": "2026-03-09T22:14:55.941609+0100", "flow_id": 2073859158301868, "event_type": "alert", "src_ip": "193.163.125.200", "src_port": 58875, "dest_ip": "134.19.55.199", "dest_port": 60015, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:14:55.941609+0100", "src_ip": "193.163.125.200", "dest_ip": "134.19.55.199", "src_port": 58875, "dest_port": 60015}}'); INSERT INTO alerts VALUES(5375,1773090900.621161938,'{"timestamp": "2026-03-09T22:15:00.621162+0100", "flow_id": 1260498930093752, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57035, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39815, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:15:00.621162+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57035, "dest_port": 53}}'); INSERT INTO alerts VALUES(5376,1773090900.621162892,'{"timestamp": "2026-03-09T22:15:00.621163+0100", "flow_id": 1260502267732975, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58353, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38889, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:15:00.621163+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58353, "dest_port": 53}}'); INSERT INTO alerts VALUES(5377,1773090900.621162892,'{"timestamp": "2026-03-09T22:15:00.621163+0100", "flow_id": 1260501201313596, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53251, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49287, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:15:00.621163+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53251, "dest_port": 53}}'); INSERT INTO alerts VALUES(5378,1773090900.621162892,'{"timestamp": "2026-03-09T22:15:00.621163+0100", "flow_id": 1260503412717831, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59715, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53570, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:15:00.621163+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59715, "dest_port": 53}}'); INSERT INTO alerts VALUES(5379,1773090900.621162892,'{"timestamp": "2026-03-09T22:15:00.621163+0100", "flow_id": 1260500484091865, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51960, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45455, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:15:00.621163+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51960, "dest_port": 53}}'); INSERT INTO alerts VALUES(5380,1773090900.621162892,'{"timestamp": "2026-03-09T22:15:00.621163+0100", "flow_id": 1260502341938817, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49987, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33327, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:15:00.621163+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49987, "dest_port": 53}}'); INSERT INTO alerts VALUES(5381,1773090900.98160696,'{"timestamp": "2026-03-09T22:15:00.981607+0100", "flow_id": 1401221875177064, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65159, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:15:00.981607+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64556, "dest_port": 53}}'); INSERT INTO alerts VALUES(5382,1773090900.98160696,'{"timestamp": "2026-03-09T22:15:00.981607+0100", "flow_id": 1401223149980873, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62044, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61483, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:15:00.981607+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62044, "dest_port": 53}}'); INSERT INTO alerts VALUES(5383,1773090903.72336793,'{"timestamp": "2026-03-09T22:15:03.723368+0100", "flow_id": 1980943434404829, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58745, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45455, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:15:03.723368+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58745, "dest_port": 53}}'); INSERT INTO alerts VALUES(5384,1773090903.723368884,'{"timestamp": "2026-03-09T22:15:03.723369+0100", "flow_id": 1980949169205521, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64822, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33327, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:15:03.723369+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64822, "dest_port": 53}}'); INSERT INTO alerts VALUES(5385,1773090953.648180962,'{"timestamp": "2026-03-09T22:15:53.648181+0100", "flow_id": 532118998062158, "event_type": "alert", "src_ip": "205.210.31.92", "src_port": 52525, "dest_ip": "134.19.55.199", "dest_port": 3905, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:15:53.648181+0100", "src_ip": "205.210.31.92", "dest_ip": "134.19.55.199", "src_port": 52525, "dest_port": 3905}}'); INSERT INTO alerts VALUES(5386,1773090963.305246115,'{"timestamp": "2026-03-09T22:16:03.305246+0100", "flow_id": 940297498834307, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 33082, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T22:16:03.284466+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 33082, "dest_port": 853}}'); INSERT INTO alerts VALUES(5387,1773090976.124254942,'{"timestamp": "2026-03-09T22:16:16.124255+0100", "flow_id": 252197253169676, "event_type": "alert", "src_ip": "195.184.76.209", "src_port": 23608, "dest_ip": "134.19.55.199", "dest_port": 7168, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:16:16.124255+0100", "src_ip": "195.184.76.209", "dest_ip": "134.19.55.199", "src_port": 23608, "dest_port": 7168}}'); INSERT INTO alerts VALUES(5388,1773091035.926619053,'{"timestamp": "2026-03-09T22:17:15.926619+0100", "flow_id": 883573968542973, "event_type": "alert", "src_ip": "195.184.76.201", "src_port": 37644, "dest_ip": "134.19.55.199", "dest_port": 6508, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:17:15.926619+0100", "src_ip": "195.184.76.201", "dest_ip": "134.19.55.199", "src_port": 37644, "dest_port": 6508}}'); INSERT INTO alerts VALUES(5389,1773091041.13676095,'{"timestamp": "2026-03-09T22:17:21.136761+0100", "flow_id": 305909971279299, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56070, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8795, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:17:21.136761+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56070, "dest_port": 53}}'); INSERT INTO alerts VALUES(5390,1773091041.13676095,'{"timestamp": "2026-03-09T22:17:21.136761+0100", "flow_id": 305911434990630, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62607, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36544, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:17:21.136761+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62607, "dest_port": 53}}'); INSERT INTO alerts VALUES(5391,1773091041.404145956,'{"timestamp": "2026-03-09T22:17:21.404146+0100", "flow_id": 328422272170869, "event_type": "alert", "src_ip": "195.184.76.65", "src_port": 43731, "dest_ip": "134.19.55.199", "dest_port": 7019, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:17:21.404146+0100", "src_ip": "195.184.76.65", "dest_ip": "134.19.55.199", "src_port": 43731, "dest_port": 7019}}'); INSERT INTO alerts VALUES(5392,1773091041.475630999,'{"timestamp": "2026-03-09T22:17:21.475631+0100", "flow_id": 751582016008036, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58260, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 2, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 2, "id": 2807, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 1, "bytes_toserver": 137, "bytes_toclient": 189, "start": "2026-03-09T22:14:58.568207+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58260, "dest_port": 53}}'); INSERT INTO alerts VALUES(5393,1773091049.849169969,'{"timestamp": "2026-03-09T22:17:29.849170+0100", "flow_id": 550933325165412, "event_type": "alert", "src_ip": "91.196.152.209", "src_port": 35599, "dest_ip": "134.19.55.199", "dest_port": 2162, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:17:29.849170+0100", "src_ip": "91.196.152.209", "dest_ip": "134.19.55.199", "src_port": 35599, "dest_port": 2162}}'); INSERT INTO alerts VALUES(5394,1773091070.937614917,'{"timestamp": "2026-03-09T22:17:50.937615+0100", "flow_id": 1775229897470730, "event_type": "alert", "src_ip": "195.184.76.17", "src_port": 37216, "dest_ip": "134.19.55.199", "dest_port": 62016, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:17:50.937615+0100", "src_ip": "195.184.76.17", "dest_ip": "134.19.55.199", "src_port": 37216, "dest_port": 62016}}'); INSERT INTO alerts VALUES(5395,1773091076.640219926,'{"timestamp": "2026-03-09T22:17:56.640220+0100", "flow_id": 1342351660546072, "event_type": "alert", "src_ip": "167.94.138.150", "src_port": 57650, "dest_ip": "134.19.55.199", "dest_port": 2082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:17:56.640220+0100", "src_ip": "167.94.138.150", "dest_ip": "134.19.55.199", "src_port": 57650, "dest_port": 2082}}'); INSERT INTO alerts VALUES(5396,1773091083.308074952,'{"timestamp": "2026-03-09T22:18:03.308075+0100", "flow_id": 951611929269761, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 53940, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T22:18:03.287100+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 53940, "dest_port": 853}}'); INSERT INTO alerts VALUES(5397,1773091089.318135977,'{"timestamp": "2026-03-09T22:18:09.318136+0100", "flow_id": 521962466299922, "event_type": "alert", "src_ip": "91.196.152.121", "src_port": 601, "dest_ip": "134.19.55.199", "dest_port": 20178, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:18:09.318136+0100", "src_ip": "91.196.152.121", "dest_ip": "134.19.55.199", "src_port": 601, "dest_port": 20178}}'); INSERT INTO alerts VALUES(5398,1773091100.405554057,'{"timestamp": "2026-03-09T22:18:20.405554+0100", "flow_id": 1178893879779829, "event_type": "alert", "src_ip": "193.163.125.215", "src_port": 47945, "dest_ip": "134.19.55.199", "dest_port": 9098, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:18:20.405554+0100", "src_ip": "193.163.125.215", "dest_ip": "134.19.55.199", "src_port": 47945, "dest_port": 9098}}'); INSERT INTO alerts VALUES(5399,1773091103.110111952,'{"timestamp": "2026-03-09T22:18:23.110112+0100", "flow_id": 2161780213833789, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 44396, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T22:18:23.110112+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 44396, "dest_port": 8545}}'); INSERT INTO alerts VALUES(5400,1773091103.110111952,'{"timestamp": "2026-03-09T22:18:23.110112+0100", "flow_id": 2161780213833789, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 44396, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T22:18:23.110112+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.55.199", "src_port": 44396, "dest_port": 8545}}'); INSERT INTO alerts VALUES(5401,1773091127.980390072,'{"timestamp": "2026-03-09T22:18:47.980390+0100", "flow_id": 2240421851944093, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 47855, "dest_ip": "134.19.55.199", "dest_port": 3480, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:18:47.980390+0100", "src_ip": "45.142.193.7", "dest_ip": "134.19.55.199", "src_port": 47855, "dest_port": 3480}}'); INSERT INTO alerts VALUES(5402,1773091161.291903973,'{"timestamp": "2026-03-09T22:19:21.291904+0100", "flow_id": 409297119121671, "event_type": "alert", "src_ip": "193.142.146.230", "src_port": 45580, "dest_ip": "134.19.55.199", "dest_port": 8090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400039, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 40", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:19:21.291904+0100", "src_ip": "193.142.146.230", "dest_ip": "134.19.55.199", "src_port": 45580, "dest_port": 8090}}'); INSERT INTO alerts VALUES(5403,1773091182.425008059,'{"timestamp": "2026-03-09T22:19:42.425008+0100", "flow_id": 1825398156193478, "event_type": "alert", "src_ip": "185.156.73.182", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 26443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:19:42.425008+0100", "src_ip": "185.156.73.182", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 26443}}'); INSERT INTO alerts VALUES(5404,1773091203.310954093,'{"timestamp": "2026-03-09T22:20:03.310954+0100", "flow_id": 967346095532049, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 41256, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T22:20:03.290763+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 41256, "dest_port": 853}}'); INSERT INTO alerts VALUES(5405,1773091205.934046983,'{"timestamp": "2026-03-09T22:20:05.934047+0100", "flow_id": 1478430510321671, "event_type": "alert", "src_ip": "195.184.76.241", "src_port": 14043, "dest_ip": "134.19.55.199", "dest_port": 7100, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:20:05.934047+0100", "src_ip": "195.184.76.241", "dest_ip": "134.19.55.199", "src_port": 14043, "dest_port": 7100}}'); INSERT INTO alerts VALUES(5406,1773091213.184627056,'{"timestamp": "2026-03-09T22:20:13.184627+0100", "flow_id": 1637393033920307, "event_type": "alert", "src_ip": "66.132.153.149", "src_port": 52310, "dest_ip": "134.19.55.199", "dest_port": 2361, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 42, "bytes_toclient": 0, "start": "2026-03-09T22:20:13.184627+0100", "src_ip": "66.132.153.149", "dest_ip": "134.19.55.199", "src_port": 52310, "dest_port": 2361}}'); INSERT INTO alerts VALUES(5407,1773091230.261593103,'{"timestamp": "2026-03-09T22:20:30.261593+0100", "flow_id": 1967962038726205, "event_type": "alert", "src_ip": "178.20.210.136", "src_port": 48381, "dest_ip": "134.19.55.199", "dest_port": 3398, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:20:30.261593+0100", "src_ip": "178.20.210.136", "dest_ip": "134.19.55.199", "src_port": 48381, "dest_port": 3398}}'); INSERT INTO alerts VALUES(5408,1773091239.159539938,'{"timestamp": "2026-03-09T22:20:39.159540+0100", "flow_id": 2092597897536159, "event_type": "alert", "src_ip": "185.241.208.163", "src_port": 50251, "dest_ip": "134.19.55.199", "dest_port": 4490, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:20:39.159540+0100", "src_ip": "185.241.208.163", "dest_ip": "134.19.55.199", "src_port": 50251, "dest_port": 4490}}'); INSERT INTO alerts VALUES(5409,1773091275.872087002,'{"timestamp": "2026-03-09T22:21:15.872087+0100", "flow_id": 930837464951898, "event_type": "alert", "src_ip": "195.184.76.89", "src_port": 58924, "dest_ip": "134.19.55.199", "dest_port": 8069, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:21:15.872087+0100", "src_ip": "195.184.76.89", "dest_ip": "134.19.55.199", "src_port": 58924, "dest_port": 8069}}'); INSERT INTO alerts VALUES(5410,1773091323.32354498,'{"timestamp": "2026-03-09T22:22:03.323545+0100", "flow_id": 1011988690459020, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 44650, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T22:22:03.301157+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 44650, "dest_port": 853}}'); INSERT INTO alerts VALUES(5411,1773091328.918298959,'{"timestamp": "2026-03-09T22:22:08.918299+0100", "flow_id": 3418452009442, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60872, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16038, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "caldav.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T22:22:08.918299+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60872, "dest_port": 53}}'); INSERT INTO alerts VALUES(5412,1773091328.918299913,'{"timestamp": "2026-03-09T22:22:08.918300+0100", "flow_id": 3419782436412, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 65380, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54491, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "caldav.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-09T22:22:08.918300+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 65380, "dest_port": 53}}'); INSERT INTO alerts VALUES(5413,1773091328.932146073,'{"timestamp": "2026-03-09T22:22:08.932146+0100", "flow_id": 62889754985352, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58916, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56677, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "contacts.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T22:22:08.932146+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58916, "dest_port": 53}}'); INSERT INTO alerts VALUES(5414,1773091328.9333601,'{"timestamp": "2026-03-09T22:22:08.933360+0100", "flow_id": 68102836090476, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64127, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25935, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "contacts.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-09T22:22:08.933360+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64127, "dest_port": 53}}'); INSERT INTO alerts VALUES(5415,1773091371.564121008,'{"timestamp": "2026-03-09T22:22:51.564121+0100", "flow_id": 1015507800708061, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58745, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45455, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:22:51.564121+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58745, "dest_port": 53}}'); INSERT INTO alerts VALUES(5416,1773091371.564121961,'{"timestamp": "2026-03-09T22:22:51.564122+0100", "flow_id": 1015513535508753, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64822, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33327, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:22:51.564122+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64822, "dest_port": 53}}'); INSERT INTO alerts VALUES(5417,1773091371.564121961,'{"timestamp": "2026-03-09T22:22:51.564122+0100", "flow_id": 1015512337159784, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65159, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:22:51.564122+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64556, "dest_port": 53}}'); INSERT INTO alerts VALUES(5418,1773091371.564121961,'{"timestamp": "2026-03-09T22:22:51.564122+0100", "flow_id": 1015513611963593, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62044, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61483, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T22:22:51.564122+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62044, "dest_port": 53}}'); INSERT INTO alerts VALUES(5419,1773091371.564122915,'{"timestamp": "2026-03-09T22:22:51.564123+0100", "flow_id": 1015519142635375, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50029, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6569, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:22:51.564123+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50029, "dest_port": 53}}'); INSERT INTO alerts VALUES(5420,1773091371.564122915,'{"timestamp": "2026-03-09T22:22:51.564123+0100", "flow_id": 1015519214127529, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52168, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44075, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:22:51.564123+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52168, "dest_port": 53}}'); INSERT INTO alerts VALUES(5421,1773091434.058695078,'{"timestamp": "2026-03-09T22:23:54.058695+0100", "flow_id": 815045136352585, "event_type": "alert", "src_ip": "147.185.132.69", "src_port": 50238, "dest_ip": "134.19.55.199", "dest_port": 10250, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:23:54.058695+0100", "src_ip": "147.185.132.69", "dest_ip": "134.19.55.199", "src_port": 50238, "dest_port": 10250}}'); INSERT INTO alerts VALUES(5422,1773091439.35258603,'{"timestamp": "2026-03-09T22:23:59.352586+0100", "flow_id": 2077298526167538, "event_type": "alert", "src_ip": "88.210.63.193", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 4430, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:23:59.352586+0100", "src_ip": "88.210.63.193", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 4430}}'); INSERT INTO alerts VALUES(5423,1773091443.326534986,'{"timestamp": "2026-03-09T22:24:03.326535+0100", "flow_id": 1028012222505018, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 45310, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T22:24:03.304888+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 45310, "dest_port": 853}}'); INSERT INTO alerts VALUES(5424,1773091462.850939036,'{"timestamp": "2026-03-09T22:24:22.850939+0100", "flow_id": 1965908240591457, "event_type": "alert", "src_ip": "198.235.24.84", "src_port": 52018, "dest_ip": "134.19.55.199", "dest_port": 8082, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:24:22.850939+0100", "src_ip": "198.235.24.84", "dest_ip": "134.19.55.199", "src_port": 52018, "dest_port": 8082}}'); INSERT INTO alerts VALUES(5425,1773091499.210210084,'{"timestamp": "2026-03-09T22:24:59.210210+0100", "flow_id": 902848655065143, "event_type": "alert", "src_ip": "147.185.132.90", "src_port": 57157, "dest_ip": "134.19.55.199", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:24:59.210210+0100", "src_ip": "147.185.132.90", "dest_ip": "134.19.55.199", "src_port": 57157, "dest_port": 3000}}'); INSERT INTO alerts VALUES(5426,1773091519.04924512,'{"timestamp": "2026-03-09T22:25:19.049245+0100", "flow_id": 2181831834366118, "event_type": "alert", "src_ip": "79.124.40.110", "src_port": 52537, "dest_ip": "134.19.55.199", "dest_port": 11492, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:25:19.049245+0100", "src_ip": "79.124.40.110", "dest_ip": "134.19.55.199", "src_port": 52537, "dest_port": 11492}}'); INSERT INTO alerts VALUES(5427,1773091563.337083102,'{"timestamp": "2026-03-09T22:26:03.337083+0100", "flow_id": 1073898159379979, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 42182, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T22:26:03.315572+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.42", "src_port": 42182, "dest_port": 853}}'); INSERT INTO alerts VALUES(5428,1773091590.085656881,'{"timestamp": "2026-03-09T22:26:30.085657+0100", "flow_id": 1775273087493999, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50029, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6569, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:26:30.085657+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50029, "dest_port": 53}}'); INSERT INTO alerts VALUES(5429,1773091590.085656881,'{"timestamp": "2026-03-09T22:26:30.085657+0100", "flow_id": 1775273158986153, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52168, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44075, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:26:30.085657+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52168, "dest_port": 53}}'); INSERT INTO alerts VALUES(5430,1773091590.085656881,'{"timestamp": "2026-03-09T22:26:30.085657+0100", "flow_id": 1775271486152560, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60810, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 963, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:26:30.085657+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60810, "dest_port": 53}}'); INSERT INTO alerts VALUES(5431,1773091590.085658074,'{"timestamp": "2026-03-09T22:26:30.085658+0100", "flow_id": 1775275815023542, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61491, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36226, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:26:30.085658+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61491, "dest_port": 53}}'); INSERT INTO alerts VALUES(5432,1773091590.573683977,'{"timestamp": "2026-03-09T22:26:30.573684+0100", "flow_id": 1901004928408556, "event_type": "alert", "src_ip": "198.235.24.244", "src_port": 54481, "dest_ip": "134.19.55.199", "dest_port": 8084, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:26:30.573684+0100", "src_ip": "198.235.24.244", "dest_ip": "134.19.55.199", "src_port": 54481, "dest_port": 8084}}'); INSERT INTO alerts VALUES(5433,1773091601.203208924,'{"timestamp": "2026-03-09T22:26:41.203209+0100", "flow_id": 309828980670475, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 51555, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:26:41.203209+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 51555, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5434,1773091601.203208924,'{"timestamp": "2026-03-09T22:26:41.203209+0100", "flow_id": 309828980670475, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 51555, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:26:41.203209+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 51555, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5435,1773091634.51898408,'{"timestamp": "2026-03-09T22:27:14.518984+0100", "flow_id": 821647012519792, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60810, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 963, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:27:14.518984+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60810, "dest_port": 53}}'); INSERT INTO alerts VALUES(5436,1773091634.518985033,'{"timestamp": "2026-03-09T22:27:14.518985+0100", "flow_id": 821651341390774, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61491, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36226, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:27:14.518985+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61491, "dest_port": 53}}'); INSERT INTO alerts VALUES(5437,1773091634.518985033,'{"timestamp": "2026-03-09T22:27:14.518985+0100", "flow_id": 821651283008639, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58659, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2132, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:27:14.518985+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58659, "dest_port": 53}}'); INSERT INTO alerts VALUES(5438,1773091634.518985033,'{"timestamp": "2026-03-09T22:27:14.518985+0100", "flow_id": 821651405188886, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51695, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55137, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:27:14.518985+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51695, "dest_port": 53}}'); INSERT INTO alerts VALUES(5439,1773091683.343063116,'{"timestamp": "2026-03-09T22:28:03.343063+0100", "flow_id": 1095444727864106, "event_type": "alert", "src_ip": "134.19.55.199", "src_port": 37656, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-09T22:28:03.320589+0100", "src_ip": "134.19.55.199", "dest_ip": "185.95.218.43", "src_port": 37656, "dest_port": 853}}'); INSERT INTO alerts VALUES(5440,1773091711.183903933,'{"timestamp": "2026-03-09T22:28:31.183904+0100", "flow_id": 2197236835531398, "event_type": "alert", "src_ip": "198.235.24.113", "src_port": 49430, "dest_ip": "134.19.55.199", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:28:31.183904+0100", "src_ip": "198.235.24.113", "dest_ip": "134.19.55.199", "src_port": 49430, "dest_port": 443}}'); INSERT INTO alerts VALUES(5441,1773091730.864938975,'{"timestamp": "2026-03-09T22:28:50.864939+0100", "flow_id": 618660088104016, "event_type": "alert", "src_ip": "130.12.180.95", "src_port": 52849, "dest_ip": "134.19.55.199", "dest_port": 20205, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T22:28:50.864939+0100", "src_ip": "130.12.180.95", "dest_ip": "134.19.55.199", "src_port": 52849, "dest_port": 20205}}'); INSERT INTO alerts VALUES(5442,1773091730.864938975,'{"timestamp": "2026-03-09T22:28:50.864939+0100", "flow_id": 618660088104016, "event_type": "alert", "src_ip": "130.12.180.95", "src_port": 52849, "dest_ip": "134.19.55.199", "dest_port": 20205, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T22:28:50.864939+0100", "src_ip": "130.12.180.95", "dest_ip": "134.19.55.199", "src_port": 52849, "dest_port": 20205}}'); INSERT INTO alerts VALUES(5443,1773091730.864938975,'{"timestamp": "2026-03-09T22:28:50.864939+0100", "flow_id": 618660088104016, "event_type": "alert", "src_ip": "130.12.180.95", "src_port": 52849, "dest_ip": "134.19.55.199", "dest_port": 20205, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500004, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 3", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T22:28:50.864939+0100", "src_ip": "130.12.180.95", "dest_ip": "134.19.55.199", "src_port": 52849, "dest_port": 20205}}'); INSERT INTO alerts VALUES(5444,1773091800.600594043,'{"timestamp": "2026-03-09T22:30:00.600594+0100", "flow_id": 46259362225279, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58659, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2132, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:30:00.600594+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58659, "dest_port": 53}}'); INSERT INTO alerts VALUES(5445,1773091800.600594997,'{"timestamp": "2026-03-09T22:30:00.600595+0100", "flow_id": 46263779372822, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51695, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55137, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:30:00.600595+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51695, "dest_port": 53}}'); INSERT INTO alerts VALUES(5446,1773091800.600594997,'{"timestamp": "2026-03-09T22:30:00.600595+0100", "flow_id": 46264638601129, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61668, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27130, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:30:00.600595+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61668, "dest_port": 53}}'); INSERT INTO alerts VALUES(5447,1773091800.600594997,'{"timestamp": "2026-03-09T22:30:00.600595+0100", "flow_id": 46261404064403, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63396, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:30:00.600595+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63396, "dest_port": 53}}'); INSERT INTO alerts VALUES(5448,1773091802.425797939,'{"timestamp": "2026-03-09T22:30:02.425798+0100", "flow_id": 702889629301232, "event_type": "alert", "src_ip": "167.94.146.45", "src_port": 21779, "dest_ip": "134.19.55.199", "dest_port": 42161, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:30:02.425798+0100", "src_ip": "167.94.146.45", "dest_ip": "134.19.55.199", "src_port": 21779, "dest_port": 42161}}'); INSERT INTO alerts VALUES(5449,1773091806.155522108,'{"timestamp": "2026-03-09T22:30:06.155522+0100", "flow_id": 1793863903615313, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56325, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27130, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:30:06.155522+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56325, "dest_port": 53}}'); INSERT INTO alerts VALUES(5450,1773091806.155522108,'{"timestamp": "2026-03-09T22:30:06.155522+0100", "flow_id": 1793863009927465, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63539, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:30:06.155522+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63539, "dest_port": 53}}'); INSERT INTO alerts VALUES(5451,1773091810.235276938,'{"timestamp": "2026-03-09T22:30:10.235277+0100", "flow_id": 729035765309846, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53932, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27130, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:30:10.235277+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53932, "dest_port": 53}}'); INSERT INTO alerts VALUES(5452,1773091810.235537053,'{"timestamp": "2026-03-09T22:30:10.235537+0100", "flow_id": 730151657788581, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53022, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:30:10.235537+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53022, "dest_port": 53}}'); INSERT INTO alerts VALUES(5453,1773091818.556111098,'{"timestamp": "2026-03-09T22:30:18.556111+0100", "flow_id": 699628704076745, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53333, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27130, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:30:18.556111+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53333, "dest_port": 53}}'); INSERT INTO alerts VALUES(5454,1773091818.556112052,'{"timestamp": "2026-03-09T22:30:18.556112+0100", "flow_id": 699633023365551, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63884, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:30:18.556112+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63884, "dest_port": 53}}'); INSERT INTO alerts VALUES(5455,1773091834.368555068,'{"timestamp": "2026-03-09T22:30:34.368555+0100", "flow_id": 738508608515741, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64148, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27130, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:30:34.368555+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64148, "dest_port": 53}}'); INSERT INTO alerts VALUES(5456,1773091834.369505882,'{"timestamp": "2026-03-09T22:30:34.369506+0100", "flow_id": 742593000627485, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55452, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:30:34.369506+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55452, "dest_port": 53}}'); INSERT INTO alerts VALUES(5457,1773091841.875715971,'{"timestamp": "2026-03-09T22:30:41.875716+0100", "flow_id": 383472368040503, "event_type": "alert", "src_ip": "130.12.180.95", "src_port": 54909, "dest_ip": "134.19.55.199", "dest_port": 20373, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500004, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 3", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T22:30:41.875716+0100", "src_ip": "130.12.180.95", "dest_ip": "134.19.55.199", "src_port": 54909, "dest_port": 20373}}'); INSERT INTO alerts VALUES(5458,1773091862.107846975,'{"timestamp": "2026-03-09T22:31:02.107847+0100", "flow_id": 1870576375924199, "event_type": "alert", "src_ip": "205.210.31.200", "src_port": 52694, "dest_ip": "134.19.55.199", "dest_port": 1434, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-09T22:31:02.107847+0100", "src_ip": "205.210.31.200", "dest_ip": "134.19.55.199", "src_port": 52694, "dest_port": 1434}}'); INSERT INTO alerts VALUES(5459,1773091865.659416913,'{"timestamp": "2026-03-09T22:31:05.659417+0100", "flow_id": 298903064640604, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56570, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27130, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:31:05.659417+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56570, "dest_port": 53}}'); INSERT INTO alerts VALUES(5460,1773091865.659418107,'{"timestamp": "2026-03-09T22:31:05.659418+0100", "flow_id": 298906974687793, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56294, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:31:05.659418+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56294, "dest_port": 53}}'); INSERT INTO alerts VALUES(5461,1773091905.271024942,'{"timestamp": "2026-03-09T22:31:45.271025+0100", "flow_id": 319619264169756, "event_type": "alert", "src_ip": "130.12.180.95", "src_port": 37934, "dest_ip": "134.19.55.199", "dest_port": 53080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500004, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 3", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T22:31:45.271025+0100", "src_ip": "130.12.180.95", "dest_ip": "134.19.55.199", "src_port": 37934, "dest_port": 53080}}'); INSERT INTO alerts VALUES(5462,1773091917.688769102,'{"timestamp": "2026-03-09T22:31:57.688769+0100", "flow_id": 1550866466762354, "event_type": "alert", "src_ip": "64.89.163.167", "src_port": 51838, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:31:57.688769+0100", "src_ip": "64.89.163.167", "dest_ip": "134.19.55.199", "src_port": 51838, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5463,1773091917.688769102,'{"timestamp": "2026-03-09T22:31:57.688769+0100", "flow_id": 1550866466762354, "event_type": "alert", "src_ip": "64.89.163.167", "src_port": 51838, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:31:57.688769+0100", "src_ip": "64.89.163.167", "dest_ip": "134.19.55.199", "src_port": 51838, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5464,1773091923.046339036,'{"timestamp": "2026-03-09T22:32:03.046339+0100", "flow_id": 1043452863296965, "event_type": "alert", "src_ip": "205.210.31.69", "src_port": 50592, "dest_ip": "134.19.55.199", "dest_port": 943, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:32:03.046339+0100", "src_ip": "205.210.31.69", "dest_ip": "134.19.55.199", "src_port": 50592, "dest_port": 943}}'); INSERT INTO alerts VALUES(5465,1773091996.303869962,'{"timestamp": "2026-03-09T22:33:16.303870+0100", "flow_id": 1305114954189420, "event_type": "alert", "src_ip": "130.12.180.95", "src_port": 59343, "dest_ip": "134.19.55.199", "dest_port": 51682, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500004, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 3", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T22:33:16.303870+0100", "src_ip": "130.12.180.95", "dest_ip": "134.19.55.199", "src_port": 59343, "dest_port": 51682}}'); INSERT INTO alerts VALUES(5466,1773092053.196331978,'{"timestamp": "2026-03-09T22:34:13.196332+0100", "flow_id": 1687665213052496, "event_type": "alert", "src_ip": "205.210.31.40", "src_port": 49648, "dest_ip": "134.19.55.199", "dest_port": 60443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:34:13.196332+0100", "src_ip": "205.210.31.40", "dest_ip": "134.19.55.199", "src_port": 49648, "dest_port": 60443}}'); INSERT INTO alerts VALUES(5467,1773092072.268829108,'{"timestamp": "2026-03-09T22:34:32.268829+0100", "flow_id": 28715938520733, "event_type": "alert", "src_ip": "195.178.110.162", "src_port": 47689, "dest_ip": "134.19.55.199", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400040, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 41", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:34:32.268829+0100", "src_ip": "195.178.110.162", "dest_ip": "134.19.55.199", "src_port": 47689, "dest_port": 80}}'); INSERT INTO alerts VALUES(5468,1773092109.21462202,'{"timestamp": "2026-03-09T22:35:09.214622+0100", "flow_id": 1484745098067829, "event_type": "alert", "src_ip": "147.185.132.79", "src_port": 55160, "dest_ip": "134.19.55.199", "dest_port": 6443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:35:09.214622+0100", "src_ip": "147.185.132.79", "dest_ip": "134.19.55.199", "src_port": 55160, "dest_port": 6443}}'); INSERT INTO alerts VALUES(5469,1773092122.932737112,'{"timestamp": "2026-03-09T22:35:22.932737+0100", "flow_id": 628376377171883, "event_type": "alert", "src_ip": "198.235.24.226", "src_port": 54376, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:35:22.932737+0100", "src_ip": "198.235.24.226", "dest_ip": "134.19.55.199", "src_port": 54376, "dest_port": 22}}'); INSERT INTO alerts VALUES(5470,1773092178.011624098,'{"timestamp": "2026-03-09T22:36:18.011624+0100", "flow_id": 612875560987707, "event_type": "alert", "src_ip": "205.210.31.109", "src_port": 50556, "dest_ip": "134.19.55.199", "dest_port": 118, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:36:18.011624+0100", "src_ip": "205.210.31.109", "dest_ip": "134.19.55.199", "src_port": 50556, "dest_port": 118}}'); INSERT INTO alerts VALUES(5471,1773092199.953892946,'{"timestamp": "2026-03-09T22:36:39.953893+0100", "flow_id": 2126618208738086, "event_type": "alert", "src_ip": "178.16.55.146", "src_port": 51000, "dest_ip": "134.19.55.199", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:36:39.953893+0100", "src_ip": "178.16.55.146", "dest_ip": "134.19.55.199", "src_port": 51000, "dest_port": 5900}}'); INSERT INTO alerts VALUES(5472,1773092207.000920058,'{"timestamp": "2026-03-09T22:36:47.000920+0100", "flow_id": 1974277638805908, "event_type": "alert", "src_ip": "205.210.31.37", "src_port": 54647, "dest_ip": "134.19.55.199", "dest_port": 9100, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:36:47.000920+0100", "src_ip": "205.210.31.37", "dest_ip": "134.19.55.199", "src_port": 54647, "dest_port": 9100}}'); INSERT INTO alerts VALUES(5473,1773092207.160981894,'{"timestamp": "2026-03-09T22:36:47.160982+0100", "flow_id": 2098787987274574, "event_type": "alert", "src_ip": "45.156.87.188", "src_port": 51221, "dest_ip": "134.19.55.199", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:36:47.160982+0100", "src_ip": "45.156.87.188", "dest_ip": "134.19.55.199", "src_port": 51221, "dest_port": 8080}}'); INSERT INTO alerts VALUES(5474,1773092222.907130003,'{"timestamp": "2026-03-09T22:37:02.907130+0100", "flow_id": 1925771637028800, "event_type": "alert", "src_ip": "20.118.32.235", "src_port": 60253, "dest_ip": "134.19.55.199", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T22:37:02.907130+0100", "src_ip": "20.118.32.235", "dest_ip": "134.19.55.199", "src_port": 60253, "dest_port": 5432}}'); INSERT INTO alerts VALUES(5475,1773092225.503194094,'{"timestamp": "2026-03-09T22:37:05.503194+0100", "flow_id": 472355414528607, "event_type": "alert", "src_ip": "193.163.125.210", "src_port": 34506, "dest_ip": "134.19.55.199", "dest_port": 2087, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:37:05.503194+0100", "src_ip": "193.163.125.210", "dest_ip": "134.19.55.199", "src_port": 34506, "dest_port": 2087}}'); INSERT INTO alerts VALUES(5476,1773092260.72819209,'{"timestamp": "2026-03-09T22:37:40.728192+0100", "flow_id": 1157239557180640, "event_type": "alert", "src_ip": "79.124.40.82", "src_port": 56878, "dest_ip": "134.19.55.199", "dest_port": 5858, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:37:40.728192+0100", "src_ip": "79.124.40.82", "dest_ip": "134.19.55.199", "src_port": 56878, "dest_port": 5858}}'); INSERT INTO alerts VALUES(5477,1773092262.258584977,'{"timestamp": "2026-03-09T22:37:42.258585+0100", "flow_id": 1955041362670717, "event_type": "alert", "src_ip": "198.235.24.96", "src_port": 54529, "dest_ip": "134.19.55.199", "dest_port": 44818, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T22:37:42.258585+0100", "src_ip": "198.235.24.96", "dest_ip": "134.19.55.199", "src_port": 54529, "dest_port": 44818}}'); INSERT INTO alerts VALUES(5478,1773092406.562755107,'{"timestamp": "2026-03-09T22:40:06.562755+0100", "flow_id": 1854067798294489, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 52382, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:40:06.562755+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.55.199", "src_port": 52382, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5479,1773092417.659043073,'{"timestamp": "2026-03-09T22:40:17.659043+0100", "flow_id": 297296798653873, "event_type": "alert", "src_ip": "167.94.146.38", "src_port": 57419, "dest_ip": "134.19.55.199", "dest_port": 51272, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:40:17.659043+0100", "src_ip": "167.94.146.38", "dest_ip": "134.19.55.199", "src_port": 57419, "dest_port": 51272}}'); INSERT INTO alerts VALUES(5480,1773092428.727632046,'{"timestamp": "2026-03-09T22:40:28.727632+0100", "flow_id": 1154833170571115, "event_type": "alert", "src_ip": "147.185.132.52", "src_port": 52228, "dest_ip": "134.19.55.199", "dest_port": 10250, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:40:28.727632+0100", "src_ip": "147.185.132.52", "dest_ip": "134.19.55.199", "src_port": 52228, "dest_port": 10250}}'); INSERT INTO alerts VALUES(5481,1773092457.816570044,'{"timestamp": "2026-03-09T22:40:57.816570+0100", "flow_id": 410919012962929, "event_type": "alert", "src_ip": "195.184.76.179", "src_port": 28289, "dest_ip": "134.19.55.199", "dest_port": 5415, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:40:57.816570+0100", "src_ip": "195.184.76.179", "dest_ip": "134.19.55.199", "src_port": 28289, "dest_port": 5415}}'); INSERT INTO alerts VALUES(5482,1773092467.402761937,'{"timestamp": "2026-03-09T22:41:07.402762+0100", "flow_id": 885426336139871, "event_type": "alert", "src_ip": "198.235.24.109", "src_port": 52330, "dest_ip": "134.19.55.199", "dest_port": 5353, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "mdns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 74, "bytes_toclient": 0, "start": "2026-03-09T22:41:07.402762+0100", "src_ip": "198.235.24.109", "dest_ip": "134.19.55.199", "src_port": 52330, "dest_port": 5353}}'); INSERT INTO alerts VALUES(5483,1773092498.109810114,'{"timestamp": "2026-03-09T22:41:38.109810+0100", "flow_id": 753106563806430, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 1000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:41:38.109810+0100", "src_ip": "185.156.73.86", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 1000}}'); INSERT INTO alerts VALUES(5484,1773092539.854229928,'{"timestamp": "2026-03-09T22:42:19.854230+0100", "flow_id": 854141755964657, "event_type": "alert", "src_ip": "64.89.161.53", "src_port": 47358, "dest_ip": "134.19.55.199", "dest_port": 30113, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T22:42:19.854230+0100", "src_ip": "64.89.161.53", "dest_ip": "134.19.55.199", "src_port": 47358, "dest_port": 30113}}'); INSERT INTO alerts VALUES(5485,1773092626.749044896,'{"timestamp": "2026-03-09T22:43:46.749045+0100", "flow_id": 683850679456048, "event_type": "alert", "src_ip": "85.217.140.37", "src_port": 45591, "dest_ip": "134.19.55.199", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101616, "rev": 9, "signature": "GPL DNS named version attempt", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_07_26"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 58, "bytes_toclient": 0, "start": "2026-03-09T22:43:46.749045+0100", "src_ip": "85.217.140.37", "dest_ip": "134.19.55.199", "src_port": 45591, "dest_port": 53}}'); INSERT INTO alerts VALUES(5486,1773092761.196909904,'{"timestamp": "2026-03-09T22:46:01.196910+0100", "flow_id": 282772365834915, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 51622, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:46:01.196910+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 51622}}'); INSERT INTO alerts VALUES(5487,1773092761.196909904,'{"timestamp": "2026-03-09T22:46:01.196910+0100", "flow_id": 282772365834915, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.55.199", "dest_port": 51622, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:46:01.196910+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.55.199", "src_port": 52302, "dest_port": 51622}}'); INSERT INTO alerts VALUES(5488,1773092827.807955026,'{"timestamp": "2026-03-09T22:47:07.807955+0100", "flow_id": 936865804812623, "event_type": "alert", "src_ip": "167.94.138.151", "src_port": 65404, "dest_ip": "134.19.55.199", "dest_port": 2004, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:47:07.807955+0100", "src_ip": "167.94.138.151", "dest_ip": "134.19.55.199", "src_port": 65404, "dest_port": 2004}}'); INSERT INTO alerts VALUES(5489,1773092838.063657999,'{"timestamp": "2026-03-09T22:47:18.063658+0100", "flow_id": 1962259081328970, "event_type": "alert", "src_ip": "167.94.146.64", "src_port": 41116, "dest_ip": "134.19.55.199", "dest_port": 16492, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:47:18.063658+0100", "src_ip": "167.94.146.64", "dest_ip": "134.19.55.199", "src_port": 41116, "dest_port": 16492}}'); INSERT INTO alerts VALUES(5490,1773092880.125659942,'{"timestamp": "2026-03-09T22:48:00.125660+0100", "flow_id": 258231174875708, "event_type": "alert", "src_ip": "46.151.182.164", "src_port": 52451, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:48:00.125660+0100", "src_ip": "46.151.182.164", "dest_ip": "134.19.55.199", "src_port": 52451, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5491,1773092880.125659942,'{"timestamp": "2026-03-09T22:48:00.125660+0100", "flow_id": 258231174875708, "event_type": "alert", "src_ip": "46.151.182.164", "src_port": 52451, "dest_ip": "134.19.55.199", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:48:00.125660+0100", "src_ip": "46.151.182.164", "dest_ip": "134.19.55.199", "src_port": 52451, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5492,1773092881.212562085,'{"timestamp": "2026-03-09T22:48:01.212562+0100", "flow_id": 350001048503252, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57716, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6001, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T22:48:01.212562+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57716, "dest_port": 53}}'); INSERT INTO alerts VALUES(5493,1773092929.026557923,'{"timestamp": "2026-03-09T22:48:49.026558+0100", "flow_id": 395544873040228, "event_type": "alert", "src_ip": "172.94.9.6", "src_port": 55804, "dest_ip": "134.19.55.199", "dest_port": 110, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400031, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 32", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:48:49.026558+0100", "src_ip": "172.94.9.6", "dest_ip": "134.19.55.199", "src_port": 55804, "dest_port": 110}}'); INSERT INTO alerts VALUES(5494,1773092967.109555006,'{"timestamp": "2026-03-09T22:49:27.109555+0100", "flow_id": 2159386313058313, "event_type": "alert", "src_ip": "205.210.31.221", "src_port": 54283, "dest_ip": "134.19.55.199", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:49:27.109555+0100", "src_ip": "205.210.31.221", "dest_ip": "134.19.55.199", "src_port": 54283, "dest_port": 8888}}'); INSERT INTO alerts VALUES(5495,1773093017.468852043,'{"timestamp": "2026-03-09T22:50:17.468852+0100", "flow_id": 324856049898792, "event_type": "alert", "src_ip": "193.163.125.198", "src_port": 34033, "dest_ip": "134.19.55.199", "dest_port": 20123, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:50:17.468852+0100", "src_ip": "193.163.125.198", "dest_ip": "134.19.55.199", "src_port": 34033, "dest_port": 20123}}'); INSERT INTO alerts VALUES(5496,1773093019.015104055,'{"timestamp": "2026-03-09T22:50:19.015104+0100", "flow_id": 909297591947764, "event_type": "alert", "src_ip": "193.163.125.195", "src_port": 34888, "dest_ip": "134.19.55.199", "dest_port": 20134, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:50:19.015104+0100", "src_ip": "193.163.125.195", "dest_ip": "134.19.55.199", "src_port": 34888, "dest_port": 20134}}'); INSERT INTO alerts VALUES(5497,1773093154.20135808,'{"timestamp": "2026-03-09T22:52:34.201358+0100", "flow_id": 583352815890959, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 52232, "dest_ip": "134.19.55.199", "dest_port": 56869, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:52:34.201358+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 52232, "dest_port": 56869}}'); INSERT INTO alerts VALUES(5498,1773093178.76124692,'{"timestamp": "2026-03-09T22:52:58.761247+0100", "flow_id": 736256943798631, "event_type": "alert", "src_ip": "193.163.125.187", "src_port": 51380, "dest_ip": "134.19.55.199", "dest_port": 5120, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:52:58.761247+0100", "src_ip": "193.163.125.187", "dest_ip": "134.19.55.199", "src_port": 51380, "dest_port": 5120}}'); INSERT INTO alerts VALUES(5499,1773093203.502629995,'{"timestamp": "2026-03-09T22:53:23.502630+0100", "flow_id": 1032881595741795, "event_type": "alert", "src_ip": "198.235.24.242", "src_port": 56132, "dest_ip": "134.19.55.199", "dest_port": 2160, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:53:23.502630+0100", "src_ip": "198.235.24.242", "dest_ip": "134.19.55.199", "src_port": 56132, "dest_port": 2160}}'); INSERT INTO alerts VALUES(5500,1773093208.909703969,'{"timestamp": "2026-03-09T22:53:28.909704+0100", "flow_id": 247974296214949, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 53149, "dest_ip": "134.19.55.199", "dest_port": 30007, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:53:28.909704+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.55.199", "src_port": 53149, "dest_port": 30007}}'); INSERT INTO alerts VALUES(5501,1773093208.909703969,'{"timestamp": "2026-03-09T22:53:28.909704+0100", "flow_id": 247974296214949, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 53149, "dest_ip": "134.19.55.199", "dest_port": 30007, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:53:28.909704+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.55.199", "src_port": 53149, "dest_port": 30007}}'); INSERT INTO alerts VALUES(5502,1773093239.9208529,'{"timestamp": "2026-03-09T22:53:59.920853+0100", "flow_id": 1984711246557988, "event_type": "alert", "src_ip": "185.242.3.253", "src_port": 42589, "dest_ip": "134.19.55.199", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:53:59.920853+0100", "src_ip": "185.242.3.253", "dest_ip": "134.19.55.199", "src_port": 42589, "dest_port": 5900}}'); INSERT INTO alerts VALUES(5503,1773093274.235901118,'{"timestamp": "2026-03-09T22:54:34.235901+0100", "flow_id": 731716039886794, "event_type": "alert", "src_ip": "167.94.138.134", "src_port": 23385, "dest_ip": "134.19.55.199", "dest_port": 6443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:54:34.235901+0100", "src_ip": "167.94.138.134", "dest_ip": "134.19.55.199", "src_port": 23385, "dest_port": 6443}}'); INSERT INTO alerts VALUES(5504,1773093332.655139923,'{"timestamp": "2026-03-09T22:55:32.655140+0100", "flow_id": 1406433859152505, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 46715, "dest_ip": "134.19.55.199", "dest_port": 37814, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:55:32.655140+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 46715, "dest_port": 37814}}'); INSERT INTO alerts VALUES(5505,1773093359.290215015,'{"timestamp": "2026-03-09T22:55:59.290215+0100", "flow_id": 2090889700944563, "event_type": "alert", "src_ip": "167.94.146.37", "src_port": 40686, "dest_ip": "134.19.55.199", "dest_port": 61997, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:55:59.290215+0100", "src_ip": "167.94.146.37", "dest_ip": "134.19.55.199", "src_port": 40686, "dest_port": 61997}}'); INSERT INTO alerts VALUES(5506,1773093457.646080971,'{"timestamp": "2026-03-09T22:57:37.646081+0100", "flow_id": 523099976893423, "event_type": "alert", "src_ip": "198.235.24.122", "src_port": 56982, "dest_ip": "134.19.55.199", "dest_port": 82, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:57:37.646081+0100", "src_ip": "198.235.24.122", "dest_ip": "134.19.55.199", "src_port": 56982, "dest_port": 82}}'); INSERT INTO alerts VALUES(5507,1773093458.864078999,'{"timestamp": "2026-03-09T22:57:38.864079+0100", "flow_id": 614968635292659, "event_type": "alert", "src_ip": "147.185.132.177", "src_port": 50303, "dest_ip": "134.19.55.199", "dest_port": 8999, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:57:38.864079+0100", "src_ip": "147.185.132.177", "dest_ip": "134.19.55.199", "src_port": 50303, "dest_port": 8999}}'); INSERT INTO alerts VALUES(5508,1773093486.901819944,'{"timestamp": "2026-03-09T22:58:06.901820+0100", "flow_id": 1902962832716231, "event_type": "alert", "src_ip": "167.94.146.41", "src_port": 22954, "dest_ip": "134.19.55.199", "dest_port": 22227, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:58:06.901820+0100", "src_ip": "167.94.146.41", "dest_ip": "134.19.55.199", "src_port": 22954, "dest_port": 22227}}'); INSERT INTO alerts VALUES(5509,1773093489.783752919,'{"timestamp": "2026-03-09T22:58:09.783753+0100", "flow_id": 551446265488994, "event_type": "alert", "src_ip": "167.94.146.36", "src_port": 38403, "dest_ip": "134.19.55.199", "dest_port": 33111, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T22:58:09.783753+0100", "src_ip": "167.94.146.36", "dest_ip": "134.19.55.199", "src_port": 38403, "dest_port": 33111}}'); INSERT INTO alerts VALUES(5510,1773093520.779475928,'{"timestamp": "2026-03-09T22:58:40.779476+0100", "flow_id": 251600653137654, "event_type": "alert", "src_ip": "87.121.84.72", "src_port": 59189, "dest_ip": "134.19.55.199", "dest_port": 124, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T22:58:40.779476+0100", "src_ip": "87.121.84.72", "dest_ip": "134.19.55.199", "src_port": 59189, "dest_port": 124}}'); INSERT INTO alerts VALUES(5511,1773093538.511183024,'{"timestamp": "2026-03-09T22:58:58.511183+0100", "flow_id": 788142674423350, "event_type": "alert", "src_ip": "205.210.31.107", "src_port": 56289, "dest_ip": "134.19.55.199", "dest_port": 587, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T22:58:58.511183+0100", "src_ip": "205.210.31.107", "dest_ip": "134.19.55.199", "src_port": 56289, "dest_port": 587}}'); INSERT INTO alerts VALUES(5512,1773093611.227401972,'{"timestamp": "2026-03-09T23:00:11.227402+0100", "flow_id": 976685512550145, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 55990, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:00:11.227402+0100", "src_ip": "130.12.180.174", "dest_ip": "134.19.55.199", "src_port": 55990, "dest_port": 23}}'); INSERT INTO alerts VALUES(5513,1773093611.227401972,'{"timestamp": "2026-03-09T23:00:11.227402+0100", "flow_id": 976685512550145, "event_type": "alert", "src_ip": "130.12.180.174", "src_port": 55990, "dest_ip": "134.19.55.199", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:00:11.227402+0100", "src_ip": "130.12.180.174", "dest_ip": "134.19.55.199", "src_port": 55990, "dest_port": 23}}'); INSERT INTO alerts VALUES(5514,1773093674.857574939,'{"timestamp": "2026-03-09T23:01:14.857575+0100", "flow_id": 587032421552702, "event_type": "alert", "src_ip": "43.228.157.18", "src_port": 55309, "dest_ip": "134.19.55.199", "dest_port": 38922, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400003, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:01:14.857575+0100", "src_ip": "43.228.157.18", "dest_ip": "134.19.55.199", "src_port": 55309, "dest_port": 38922}}'); INSERT INTO alerts VALUES(5515,1773093683.87532401,'{"timestamp": "2026-03-09T23:01:23.875324+0100", "flow_id": 944739633012656, "event_type": "alert", "src_ip": "147.185.132.18", "src_port": 55433, "dest_ip": "134.19.55.199", "dest_port": 5907, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:01:23.875324+0100", "src_ip": "147.185.132.18", "dest_ip": "134.19.55.199", "src_port": 55433, "dest_port": 5907}}'); INSERT INTO alerts VALUES(5516,1773093704.364797116,'{"timestamp": "2026-03-09T23:01:44.364797+0100", "flow_id": 159417227678905, "event_type": "alert", "src_ip": "204.76.203.233", "src_port": 39628, "dest_ip": "134.19.55.199", "dest_port": 10055, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400051, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 52", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T23:01:44.364797+0100", "src_ip": "204.76.203.233", "dest_ip": "134.19.55.199", "src_port": 39628, "dest_port": 10055}}'); INSERT INTO alerts VALUES(5517,1773093704.364797116,'{"timestamp": "2026-03-09T23:01:44.364797+0100", "flow_id": 159417227678905, "event_type": "alert", "src_ip": "204.76.203.233", "src_port": 39628, "dest_ip": "134.19.55.199", "dest_port": 10055, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T23:01:44.364797+0100", "src_ip": "204.76.203.233", "dest_ip": "134.19.55.199", "src_port": 39628, "dest_port": 10055}}'); INSERT INTO alerts VALUES(5518,1773093713.780432939,'{"timestamp": "2026-03-09T23:01:53.780433+0100", "flow_id": 537188533817788, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52113, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44417, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T23:01:53.780433+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52113, "dest_port": 53}}'); INSERT INTO alerts VALUES(5519,1773093713.780703067,'{"timestamp": "2026-03-09T23:01:53.780703+0100", "flow_id": 538347457021719, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59833, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10557, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T23:01:53.780703+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59833, "dest_port": 53}}'); INSERT INTO alerts VALUES(5520,1773093802.315742015,'{"timestamp": "2026-03-09T23:03:22.315742+0100", "flow_id": 793151849980802, "event_type": "alert", "src_ip": "205.210.31.180", "src_port": 50677, "dest_ip": "134.19.55.199", "dest_port": 30006, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:03:22.315742+0100", "src_ip": "205.210.31.180", "dest_ip": "134.19.55.199", "src_port": 50677, "dest_port": 30006}}'); INSERT INTO alerts VALUES(5521,1773093808.938941001,'{"timestamp": "2026-03-09T23:03:28.938941+0100", "flow_id": 92072277423288, "event_type": "alert", "src_ip": "88.210.63.191", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 23000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:03:28.938941+0100", "src_ip": "88.210.63.191", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 23000}}'); INSERT INTO alerts VALUES(5522,1773093830.431283951,'{"timestamp": "2026-03-09T23:03:50.431284+0100", "flow_id": 1852354764493244, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52113, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44417, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T23:03:50.431284+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52113, "dest_port": 53}}'); INSERT INTO alerts VALUES(5523,1773093830.431283951,'{"timestamp": "2026-03-09T23:03:50.431284+0100", "flow_id": 1852354046527255, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59833, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10557, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T23:03:50.431284+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59833, "dest_port": 53}}'); INSERT INTO alerts VALUES(5524,1773093910.056381941,'{"timestamp": "2026-03-09T23:05:10.056382+0100", "flow_id": 1931009492962480, "event_type": "alert", "src_ip": "88.210.63.192", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 1111, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:05:10.056382+0100", "src_ip": "88.210.63.192", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 1111}}'); INSERT INTO alerts VALUES(5525,1773093913.564553977,'{"timestamp": "2026-03-09T23:05:13.564554+0100", "flow_id": 454416669893283, "event_type": "alert", "src_ip": "64.89.163.132", "src_port": 53746, "dest_ip": "134.19.55.199", "dest_port": 27017, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:05:13.564554+0100", "src_ip": "64.89.163.132", "dest_ip": "134.19.55.199", "src_port": 53746, "dest_port": 27017}}'); INSERT INTO alerts VALUES(5526,1773093975.35869193,'{"timestamp": "2026-03-09T23:06:15.358692+0100", "flow_id": 2103523107509223, "event_type": "alert", "src_ip": "147.185.132.76", "src_port": 49919, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:06:15.358692+0100", "src_ip": "147.185.132.76", "dest_ip": "134.19.55.199", "src_port": 49919, "dest_port": 22}}'); INSERT INTO alerts VALUES(5527,1773093994.489137888,'{"timestamp": "2026-03-09T23:06:34.489138+0100", "flow_id": 693459184135156, "event_type": "alert", "src_ip": "167.94.146.35", "src_port": 52256, "dest_ip": "134.19.55.199", "dest_port": 39611, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T23:06:34.489138+0100", "src_ip": "167.94.146.35", "dest_ip": "134.19.55.199", "src_port": 52256, "dest_port": 39611}}'); INSERT INTO alerts VALUES(5528,1773094004.772185088,'{"timestamp": "2026-03-09T23:06:44.772185+0100", "flow_id": 1346186313916598, "event_type": "alert", "src_ip": "205.210.31.83", "src_port": 49743, "dest_ip": "134.19.55.199", "dest_port": 5289, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:06:44.772185+0100", "src_ip": "205.210.31.83", "dest_ip": "134.19.55.199", "src_port": 49743, "dest_port": 5289}}'); INSERT INTO alerts VALUES(5529,1773094025.338063002,'{"timestamp": "2026-03-09T23:07:05.338063+0100", "flow_id": 326072538016753, "event_type": "alert", "src_ip": "147.185.132.67", "src_port": 56126, "dest_ip": "134.19.55.199", "dest_port": 50070, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:07:05.338063+0100", "src_ip": "147.185.132.67", "dest_ip": "134.19.55.199", "src_port": 56126, "dest_port": 50070}}'); INSERT INTO alerts VALUES(5530,1773094052.224184037,'{"timestamp": "2026-03-09T23:07:32.224184+0100", "flow_id": 1244340590045279, "event_type": "alert", "src_ip": "77.89.220.210", "src_port": 33820, "dest_ip": "134.19.55.199", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:07:32.224184+0100", "src_ip": "77.89.220.210", "dest_ip": "134.19.55.199", "src_port": 33820, "dest_port": 1433}}'); INSERT INTO alerts VALUES(5531,1773094105.907685995,'{"timestamp": "2026-03-09T23:08:25.907686+0100", "flow_id": 520783467206431, "event_type": "alert", "src_ip": "167.94.146.33", "src_port": 51937, "dest_ip": "134.19.55.199", "dest_port": 48228, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T23:08:25.907686+0100", "src_ip": "167.94.146.33", "dest_ip": "134.19.55.199", "src_port": 51937, "dest_port": 48228}}'); INSERT INTO alerts VALUES(5532,1773094107.050165892,'{"timestamp": "2026-03-09T23:08:27.050166+0100", "flow_id": 1059889330591141, "event_type": "alert", "src_ip": "185.242.226.73", "src_port": 51803, "dest_ip": "134.19.55.199", "dest_port": 8429, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:08:27.050166+0100", "src_ip": "185.242.226.73", "dest_ip": "134.19.55.199", "src_port": 51803, "dest_port": 8429}}'); INSERT INTO alerts VALUES(5533,1773094129.182063103,'{"timestamp": "2026-03-09T23:08:49.182063+0100", "flow_id": 500481220185993, "event_type": "alert", "src_ip": "205.210.31.79", "src_port": 45618, "dest_ip": "134.19.55.199", "dest_port": 17, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-09T23:08:49.182063+0100", "src_ip": "205.210.31.79", "dest_ip": "134.19.55.199", "src_port": 45618, "dest_port": 17}}'); INSERT INTO alerts VALUES(5534,1773094139.577881097,'{"timestamp": "2026-03-09T23:08:59.577881+0100", "flow_id": 1074607016847178, "event_type": "alert", "src_ip": "176.65.148.95", "src_port": 59067, "dest_ip": "134.19.55.199", "dest_port": 14000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:08:59.577881+0100", "src_ip": "176.65.148.95", "dest_ip": "134.19.55.199", "src_port": 59067, "dest_port": 14000}}'); INSERT INTO alerts VALUES(5535,1773094139.577881097,'{"timestamp": "2026-03-09T23:08:59.577881+0100", "flow_id": 1074607016847178, "event_type": "alert", "src_ip": "176.65.148.95", "src_port": 59067, "dest_ip": "134.19.55.199", "dest_port": 14000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:08:59.577881+0100", "src_ip": "176.65.148.95", "dest_ip": "134.19.55.199", "src_port": 59067, "dest_port": 14000}}'); INSERT INTO alerts VALUES(5536,1773094249.293334961,'{"timestamp": "2026-03-09T23:10:49.293335+0100", "flow_id": 415443590361091, "event_type": "alert", "src_ip": "81.29.142.50", "src_port": 59492, "dest_ip": "134.19.55.199", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:10:49.293335+0100", "src_ip": "81.29.142.50", "dest_ip": "134.19.55.199", "src_port": 59492, "dest_port": 1521}}'); INSERT INTO alerts VALUES(5537,1773094249.701769114,'{"timestamp": "2026-03-09T23:10:49.701769+0100", "flow_id": 480801711894365, "event_type": "alert", "src_ip": "205.210.31.110", "src_port": 52182, "dest_ip": "134.19.55.199", "dest_port": 2121, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:10:49.701769+0100", "src_ip": "205.210.31.110", "dest_ip": "134.19.55.199", "src_port": 52182, "dest_port": 2121}}'); INSERT INTO alerts VALUES(5538,1773094268.381268024,'{"timestamp": "2026-03-09T23:11:08.381268+0100", "flow_id": 1356060364177320, "event_type": "alert", "src_ip": "167.94.138.102", "src_port": 51425, "dest_ip": "134.19.55.199", "dest_port": 3729, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T23:11:08.381268+0100", "src_ip": "167.94.138.102", "dest_ip": "134.19.55.199", "src_port": 51425, "dest_port": 3729}}'); INSERT INTO alerts VALUES(5539,1773094296.429960012,'{"timestamp": "2026-03-09T23:11:36.429960+0100", "flow_id": 157817371830370, "event_type": "alert", "src_ip": "176.65.148.96", "src_port": 41195, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T23:11:36.429960+0100", "src_ip": "176.65.148.96", "dest_ip": "134.19.55.199", "src_port": 41195, "dest_port": 8545}}'); INSERT INTO alerts VALUES(5540,1773094296.429960012,'{"timestamp": "2026-03-09T23:11:36.429960+0100", "flow_id": 157817371830370, "event_type": "alert", "src_ip": "176.65.148.96", "src_port": 41195, "dest_ip": "134.19.55.199", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-09T23:11:36.429960+0100", "src_ip": "176.65.148.96", "dest_ip": "134.19.55.199", "src_port": 41195, "dest_port": 8545}}'); INSERT INTO alerts VALUES(5541,1773094355.610255003,'{"timestamp": "2026-03-09T23:12:35.610255+0100", "flow_id": 932179522202310, "event_type": "alert", "src_ip": "167.94.146.32", "src_port": 64772, "dest_ip": "134.19.55.199", "dest_port": 12131, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T23:12:35.610255+0100", "src_ip": "167.94.146.32", "dest_ip": "134.19.55.199", "src_port": 64772, "dest_port": 12131}}'); INSERT INTO alerts VALUES(5542,1773094403.249512911,'{"timestamp": "2026-03-09T23:13:23.249513+0100", "flow_id": 1071653351926825, "event_type": "alert", "src_ip": "178.20.210.151", "src_port": 52584, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:13:23.249513+0100", "src_ip": "178.20.210.151", "dest_ip": "134.19.55.199", "src_port": 52584, "dest_port": 22}}'); INSERT INTO alerts VALUES(5543,1773094468.941740036,'{"timestamp": "2026-03-09T23:14:28.941740+0100", "flow_id": 1229995216759960, "event_type": "alert", "src_ip": "195.184.76.221", "src_port": 25043, "dest_ip": "134.19.55.199", "dest_port": 5418, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T23:14:28.941740+0100", "src_ip": "195.184.76.221", "dest_ip": "134.19.55.199", "src_port": 25043, "dest_port": 5418}}'); INSERT INTO alerts VALUES(5544,1773094496.020975112,'{"timestamp": "2026-03-09T23:14:56.020975+0100", "flow_id": 90087456242964, "event_type": "alert", "src_ip": "100.29.192.31", "src_port": 45457, "dest_ip": "134.19.55.199", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T23:14:56.020975+0100", "src_ip": "100.29.192.31", "dest_ip": "134.19.55.199", "src_port": 45457, "dest_port": 161}}'); INSERT INTO alerts VALUES(5545,1773094496.020976067,'{"timestamp": "2026-03-09T23:14:56.020976+0100", "flow_id": 90087456242964, "event_type": "alert", "src_ip": "100.29.192.31", "src_port": 45457, "dest_ip": "134.19.55.199", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 139, "bytes_toclient": 0, "start": "2026-03-09T23:14:56.020975+0100", "src_ip": "100.29.192.31", "dest_ip": "134.19.55.199", "src_port": 45457, "dest_port": 161}}'); INSERT INTO alerts VALUES(5546,1773094518.722065925,'{"timestamp": "2026-03-09T23:15:18.722066+0100", "flow_id": 1693876870746967, "event_type": "alert", "src_ip": "87.121.84.85", "src_port": 39112, "dest_ip": "134.19.55.199", "dest_port": 2011, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:15:18.722066+0100", "src_ip": "87.121.84.85", "dest_ip": "134.19.55.199", "src_port": 39112, "dest_port": 2011}}'); INSERT INTO alerts VALUES(5547,1773094552.794302941,'{"timestamp": "2026-03-09T23:15:52.794303+0100", "flow_id": 33807613227054, "event_type": "alert", "src_ip": "193.163.125.182", "src_port": 36519, "dest_ip": "134.19.55.199", "dest_port": 58222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:15:52.794303+0100", "src_ip": "193.163.125.182", "dest_ip": "134.19.55.199", "src_port": 36519, "dest_port": 58222}}'); INSERT INTO alerts VALUES(5548,1773094576.864480973,'{"timestamp": "2026-03-09T23:16:16.864481+0100", "flow_id": 53745750625063, "event_type": "alert", "src_ip": "176.65.149.215", "src_port": 54617, "dest_ip": "134.19.55.199", "dest_port": 3128, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4638, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:16:16.864481+0100", "src_ip": "176.65.149.215", "dest_ip": "134.19.55.199", "src_port": 54617, "dest_port": 3128}}'); INSERT INTO alerts VALUES(5549,1773094629.431633949,'{"timestamp": "2026-03-09T23:17:09.431634+0100", "flow_id": 1572380479007146, "event_type": "alert", "src_ip": "198.235.24.102", "src_port": 49828, "dest_ip": "134.19.55.199", "dest_port": 5061, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:17:09.431634+0100", "src_ip": "198.235.24.102", "dest_ip": "134.19.55.199", "src_port": 49828, "dest_port": 5061}}'); INSERT INTO alerts VALUES(5550,1773094631.525487899,'{"timestamp": "2026-03-09T23:17:11.525488+0100", "flow_id": 1975480517469139, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51171, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 959, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T23:17:11.525488+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51171, "dest_port": 53}}'); INSERT INTO alerts VALUES(5551,1773094636.757190942,'{"timestamp": "2026-03-09T23:17:16.757191+0100", "flow_id": 1281789603731927, "event_type": "alert", "src_ip": "193.163.125.194", "src_port": 57892, "dest_ip": "134.19.55.199", "dest_port": 5678, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:17:16.757191+0100", "src_ip": "193.163.125.194", "dest_ip": "134.19.55.199", "src_port": 57892, "dest_port": 5678}}'); INSERT INTO alerts VALUES(5552,1773094657.975028992,'{"timestamp": "2026-03-09T23:17:37.975029+0100", "flow_id": 528546816790794, "event_type": "alert", "src_ip": "103.49.62.60", "src_port": 48552, "dest_ip": "134.19.55.199", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2500000, "rev": 7553, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T23:17:37.975029+0100", "src_ip": "103.49.62.60", "dest_ip": "134.19.55.199", "src_port": 48552, "dest_port": 22}}'); INSERT INTO alerts VALUES(5553,1773094697.134834052,'{"timestamp": "2026-03-09T23:18:17.134834+0100", "flow_id": 297634526989108, "event_type": "alert", "src_ip": "205.210.31.163", "src_port": 51640, "dest_ip": "134.19.55.199", "dest_port": 9983, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:18:17.134834+0100", "src_ip": "205.210.31.163", "dest_ip": "134.19.55.199", "src_port": 51640, "dest_port": 9983}}'); INSERT INTO alerts VALUES(5554,1773094861.088820935,'{"timestamp": "2026-03-09T23:21:01.088821+0100", "flow_id": 1507384620975319, "event_type": "alert", "src_ip": "91.196.152.187", "src_port": 19504, "dest_ip": "134.19.55.199", "dest_port": 20198, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-09T23:21:01.088821+0100", "src_ip": "91.196.152.187", "dest_ip": "134.19.55.199", "src_port": 19504, "dest_port": 20198}}'); INSERT INTO alerts VALUES(5555,1773094878.963834048,'{"timestamp": "2026-03-09T23:21:18.963834+0100", "flow_id": 1887838454345280, "event_type": "alert", "src_ip": "205.210.31.255", "src_port": 51563, "dest_ip": "134.19.55.199", "dest_port": 30303, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7670, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_06"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:21:18.963834+0100", "src_ip": "205.210.31.255", "dest_ip": "134.19.55.199", "src_port": 51563, "dest_port": 30303}}'); INSERT INTO alerts VALUES(5556,1773094976.645899057,'{"timestamp": "2026-03-09T23:22:56.645899+0100", "flow_id": 240842192752597, "event_type": "alert", "src_ip": "193.163.125.187", "src_port": 33079, "dest_ip": "134.19.55.199", "dest_port": 3263, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:22:56.645899+0100", "src_ip": "193.163.125.187", "dest_ip": "134.19.55.199", "src_port": 33079, "dest_port": 3263}}'); INSERT INTO alerts VALUES(5557,1773094980.106167078,'{"timestamp": "2026-03-09T23:23:00.106167+0100", "flow_id": 1300409140390891, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 53424, "dest_ip": "134.19.55.199", "dest_port": 40243, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:23:00.106167+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.55.199", "src_port": 53424, "dest_port": 40243}}'); INSERT INTO alerts VALUES(5558,1773095102.61570406,'{"timestamp": "2026-03-09T23:25:02.615704+0100", "flow_id": 1800004670737284, "event_type": "alert", "src_ip": "198.235.24.201", "src_port": 56474, "dest_ip": "134.19.55.199", "dest_port": 5902, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:25:02.615704+0100", "src_ip": "198.235.24.201", "dest_ip": "134.19.55.199", "src_port": 56474, "dest_port": 5902}}'); INSERT INTO alerts VALUES(5559,1773095181.240556002,'{"timestamp": "2026-03-09T23:26:21.240556+0100", "flow_id": 1596132534141057, "event_type": "alert", "src_ip": "92.63.197.182", "src_port": 55676, "dest_ip": "134.19.55.199", "dest_port": 40443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400014, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 15", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:26:21.240556+0100", "src_ip": "92.63.197.182", "dest_ip": "134.19.55.199", "src_port": 55676, "dest_port": 40443}}'); INSERT INTO alerts VALUES(5560,1773095208.728509903,'{"timestamp": "2026-03-09T23:26:48.728510+0100", "flow_id": 32702249700776, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 47855, "dest_ip": "134.19.55.199", "dest_port": 3476, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:26:48.728510+0100", "src_ip": "45.142.193.7", "dest_ip": "134.19.55.199", "src_port": 47855, "dest_port": 3476}}'); INSERT INTO alerts VALUES(5561,1773095209.542438983,'{"timestamp": "2026-03-09T23:26:49.542439+0100", "flow_id": 359433433442286, "event_type": "alert", "src_ip": "198.235.24.83", "src_port": 53279, "dest_ip": "134.19.55.199", "dest_port": 5908, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:26:49.542439+0100", "src_ip": "198.235.24.83", "dest_ip": "134.19.55.199", "src_port": 53279, "dest_port": 5908}}'); INSERT INTO alerts VALUES(5562,1773095218.92732191,'{"timestamp": "2026-03-09T23:26:58.927322+0100", "flow_id": 605120080495839, "event_type": "alert", "src_ip": "79.124.62.53", "src_port": 43009, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:26:58.927322+0100", "src_ip": "79.124.62.53", "dest_ip": "134.19.55.199", "src_port": 43009, "dest_port": 3389}}'); INSERT INTO alerts VALUES(5563,1773095236.358472109,'{"timestamp": "2026-03-09T23:27:16.358472+0100", "flow_id": 1258151679072865, "event_type": "alert", "src_ip": "198.235.24.207", "src_port": 56963, "dest_ip": "134.19.55.199", "dest_port": 83, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:27:16.358472+0100", "src_ip": "198.235.24.207", "dest_ip": "134.19.55.199", "src_port": 56963, "dest_port": 83}}'); INSERT INTO alerts VALUES(5564,1773095312.824434041,'{"timestamp": "2026-03-09T23:28:32.824434+0100", "flow_id": 163219870487018, "event_type": "alert", "src_ip": "198.235.24.110", "src_port": 49618, "dest_ip": "134.19.55.199", "dest_port": 4022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:28:32.824434+0100", "src_ip": "198.235.24.110", "dest_ip": "134.19.55.199", "src_port": 49618, "dest_port": 4022}}'); INSERT INTO alerts VALUES(5565,1773095342.656476974,'{"timestamp": "2026-03-09T23:29:02.656477+0100", "flow_id": 1693650730269827, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61794, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8270, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T23:29:02.656477+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61794, "dest_port": 53}}'); INSERT INTO alerts VALUES(5566,1773095342.65674305,'{"timestamp": "2026-03-09T23:29:02.656743+0100", "flow_id": 1694790216254762, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49944, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13864, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-09T23:29:02.656743+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49944, "dest_port": 53}}'); INSERT INTO alerts VALUES(5567,1773095344.959640027,'{"timestamp": "2026-03-09T23:29:04.959640+0100", "flow_id": 180973543877367, "event_type": "alert", "src_ip": "145.90.8.9", "src_port": 51199, "dest_ip": "134.19.55.199", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T23:29:04.959640+0100", "src_ip": "145.90.8.9", "dest_ip": "134.19.55.199", "src_port": 51199, "dest_port": 161}}'); INSERT INTO alerts VALUES(5568,1773095352.923885107,'{"timestamp": "2026-03-09T23:29:12.923885+0100", "flow_id": 27406964576700, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64999, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44027, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-09T23:29:12.923885+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64999, "dest_port": 53}}'); INSERT INTO alerts VALUES(5569,1773095384.317898989,'{"timestamp": "2026-03-09T23:29:44.317899+0100", "flow_id": 239468779805423, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 52232, "dest_ip": "134.19.55.199", "dest_port": 31986, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-09T23:29:44.317899+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.55.199", "src_port": 52232, "dest_port": 31986}}'); INSERT INTO alerts VALUES(5570,1773095415.847285986,'{"timestamp": "2026-03-09T23:30:15.847286+0100", "flow_id": 2231693862248964, "event_type": "alert", "src_ip": "198.235.24.177", "src_port": 55090, "dest_ip": "134.19.55.199", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:30:15.847286+0100", "src_ip": "198.235.24.177", "dest_ip": "134.19.55.199", "src_port": 55090, "dest_port": 3389}}'); INSERT INTO alerts VALUES(5571,1773095418.134601117,'{"timestamp": "2026-03-09T23:30:18.134601+0100", "flow_id": 578107410990134, "event_type": "alert", "src_ip": "185.242.226.81", "src_port": 44811, "dest_ip": "134.19.55.199", "dest_port": 40845, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-09T23:30:18.134601+0100", "src_ip": "185.242.226.81", "dest_ip": "134.19.55.199", "src_port": 44811, "dest_port": 40845}}'); INSERT INTO alerts VALUES(5572,1773122582.834070921,'{"timestamp": "2026-03-10T07:03:02.834071+0100", "flow_id": 1801926319477374, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 56280, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:03:02.812759+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 56280, "dest_port": 853}}'); INSERT INTO alerts VALUES(5573,1773122588.040230036,'{"timestamp": "2026-03-10T07:03:08.040230+0100", "flow_id": 1298688580656346, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57233, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46724, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T07:03:08.040230+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57233, "dest_port": 53}}'); INSERT INTO alerts VALUES(5574,1773122589.639309883,'{"timestamp": "2026-03-10T07:03:09.639310+0100", "flow_id": 1619919042147201, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58110, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47743, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:03:09.639310+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58110, "dest_port": 53}}'); INSERT INTO alerts VALUES(5575,1773122589.728929997,'{"timestamp": "2026-03-10T07:03:09.728930+0100", "flow_id": 1441883632636994, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52531, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31057, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:03:09.728930+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52531, "dest_port": 53}}'); INSERT INTO alerts VALUES(5576,1773122614.587465047,'{"timestamp": "2026-03-10T07:03:34.587465+0100", "flow_id": 1873648388940600, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 54356, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:03:34.567314+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 54356, "dest_port": 853}}'); INSERT INTO alerts VALUES(5577,1773122627.931466102,'{"timestamp": "2026-03-10T07:03:47.931466+0100", "flow_id": 904393262357925, "event_type": "alert", "src_ip": "15.204.54.13", "src_port": 19681, "dest_ip": "134.19.61.215", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2008578, "rev": 4, "signature": "ET SCAN Sipvicious Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 441, "bytes_toclient": 0, "start": "2026-03-10T07:03:47.931466+0100", "src_ip": "15.204.54.13", "dest_ip": "134.19.61.215", "src_port": 19681, "dest_port": 5060}}'); INSERT INTO alerts VALUES(5578,1773122627.931466102,'{"timestamp": "2026-03-10T07:03:47.931466+0100", "flow_id": 904393262357925, "event_type": "alert", "src_ip": "15.204.54.13", "src_port": 19681, "dest_ip": "134.19.61.215", "dest_port": 5060, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2011716, "rev": 3, "signature": "ET SCAN Sipvicious User-Agent Detected (friendly-scanner)", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["High"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 441, "bytes_toclient": 0, "start": "2026-03-10T07:03:47.931466+0100", "src_ip": "15.204.54.13", "dest_ip": "134.19.61.215", "src_port": 19681, "dest_port": 5060}}'); INSERT INTO alerts VALUES(5579,1773122652.1513021,'{"timestamp": "2026-03-10T07:04:12.151302+0100", "flow_id": 1212787936591747, "event_type": "alert", "src_ip": "176.65.148.4", "src_port": 52023, "dest_ip": "134.19.61.215", "dest_port": 25565, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:04:12.151302+0100", "src_ip": "176.65.148.4", "dest_ip": "134.19.61.215", "src_port": 52023, "dest_port": 25565}}'); INSERT INTO alerts VALUES(5580,1773122671.281333924,'{"timestamp": "2026-03-10T07:04:31.281334+0100", "flow_id": 2052746826517871, "event_type": "alert", "src_ip": "64.62.197.140", "src_port": 52547, "dest_ip": "134.19.61.215", "dest_port": 4500, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 80, "bytes_toclient": 0, "start": "2026-03-10T07:04:31.281334+0100", "src_ip": "64.62.197.140", "dest_ip": "134.19.61.215", "src_port": 52547, "dest_port": 4500}}'); INSERT INTO alerts VALUES(5581,1773122675.473762036,'{"timestamp": "2026-03-10T07:04:35.473762+0100", "flow_id": 908896477869573, "event_type": "alert", "src_ip": "185.93.89.79", "src_port": 40179, "dest_ip": "134.19.61.215", "dest_port": 9001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:04:35.473762+0100", "src_ip": "185.93.89.79", "dest_ip": "134.19.61.215", "src_port": 40179, "dest_port": 9001}}'); INSERT INTO alerts VALUES(5582,1773122689.509306907,'{"timestamp": "2026-03-10T07:04:49.509307+0100", "flow_id": 498610625531322, "event_type": "alert", "src_ip": "204.76.203.233", "src_port": 46840, "dest_ip": "134.19.61.215", "dest_port": 10023, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T07:04:49.509307+0100", "src_ip": "204.76.203.233", "dest_ip": "134.19.61.215", "src_port": 46840, "dest_port": 10023}}'); INSERT INTO alerts VALUES(5583,1773122703.363070011,'{"timestamp": "2026-03-10T07:05:03.363070+0100", "flow_id": 2122325376431952, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61439, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43190, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:05:03.363070+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61439, "dest_port": 53}}'); INSERT INTO alerts VALUES(5584,1773122703.364835978,'{"timestamp": "2026-03-10T07:05:03.364836+0100", "flow_id": 2129910882370758, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57702, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17320, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:05:03.364836+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57702, "dest_port": 53}}'); INSERT INTO alerts VALUES(5585,1773122703.96930194,'{"timestamp": "2026-03-10T07:05:03.969302+0100", "flow_id": 2192797028945267, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52277, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9776, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:05:03.969302+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52277, "dest_port": 53}}'); INSERT INTO alerts VALUES(5586,1773122709.938117028,'{"timestamp": "2026-03-10T07:05:09.938117+0100", "flow_id": 1495907070903948, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57566, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55661, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:05:09.938117+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57566, "dest_port": 53}}'); INSERT INTO alerts VALUES(5587,1773122754.4149971,'{"timestamp": "2026-03-10T07:05:54.414997+0100", "flow_id": 656500731276499, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 57964, "dest_ip": "134.19.61.215", "dest_port": 6320, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:05:54.414997+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.61.215", "src_port": 57964, "dest_port": 6320}}'); INSERT INTO alerts VALUES(5588,1773122776.130522013,'{"timestamp": "2026-03-10T07:06:16.130522+0100", "flow_id": 279113379844149, "event_type": "alert", "src_ip": "87.121.84.88", "src_port": 60000, "dest_ip": "134.19.61.215", "dest_port": 22145, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:06:16.130522+0100", "src_ip": "87.121.84.88", "dest_ip": "134.19.61.215", "src_port": 60000, "dest_port": 22145}}'); INSERT INTO alerts VALUES(5589,1773122776.130522013,'{"timestamp": "2026-03-10T07:06:16.130522+0100", "flow_id": 279113379844149, "event_type": "alert", "src_ip": "87.121.84.88", "src_port": 60000, "dest_ip": "134.19.61.215", "dest_port": 22145, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:06:16.130522+0100", "src_ip": "87.121.84.88", "dest_ip": "134.19.61.215", "src_port": 60000, "dest_port": 22145}}'); INSERT INTO alerts VALUES(5590,1773122780.48920989,'{"timestamp": "2026-03-10T07:06:20.489210+0100", "flow_id": 1256717953827632, "event_type": "alert", "src_ip": "77.90.185.16", "src_port": 65105, "dest_ip": "134.19.61.215", "dest_port": 10001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:06:20.489210+0100", "src_ip": "77.90.185.16", "dest_ip": "134.19.61.215", "src_port": 65105, "dest_port": 10001}}'); INSERT INTO alerts VALUES(5591,1773122793.199769021,'{"timestamp": "2026-03-10T07:06:33.199769+0100", "flow_id": 295051932416128, "event_type": "alert", "src_ip": "147.185.132.90", "src_port": 51688, "dest_ip": "134.19.61.215", "dest_port": 5000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:06:33.199769+0100", "src_ip": "147.185.132.90", "dest_ip": "134.19.61.215", "src_port": 51688, "dest_port": 5000}}'); INSERT INTO alerts VALUES(5592,1773122822.837635994,'{"timestamp": "2026-03-10T07:07:02.837636+0100", "flow_id": 1908770831008209, "event_type": "alert", "src_ip": "205.210.31.66", "src_port": 50884, "dest_ip": "134.19.61.215", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 59, "bytes_toclient": 0, "start": "2026-03-10T07:07:02.837636+0100", "src_ip": "205.210.31.66", "dest_ip": "134.19.61.215", "src_port": 50884, "dest_port": 53}}'); INSERT INTO alerts VALUES(5593,1773122822.837635994,'{"timestamp": "2026-03-10T07:07:02.837636+0100", "flow_id": 1908770831008209, "event_type": "alert", "src_ip": "205.210.31.66", "src_port": 50884, "dest_ip": "134.19.61.215", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2101616, "rev": 9, "signature": "GPL DNS named version attempt", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_07_26"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 59, "bytes_toclient": 0, "start": "2026-03-10T07:07:02.837636+0100", "src_ip": "205.210.31.66", "dest_ip": "134.19.61.215", "src_port": 50884, "dest_port": 53}}'); INSERT INTO alerts VALUES(5594,1773122831.294430972,'{"timestamp": "2026-03-10T07:07:11.294431+0100", "flow_id": 2018623177164182, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 36422, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:07:11.273389+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 36422, "dest_port": 853}}'); INSERT INTO alerts VALUES(5595,1773122859.31656003,'{"timestamp": "2026-03-10T07:07:39.316560+0100", "flow_id": 1078140765772607, "event_type": "alert", "src_ip": "185.196.8.218", "src_port": 58261, "dest_ip": "134.19.61.215", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:07:39.316560+0100", "src_ip": "185.196.8.218", "dest_ip": "134.19.61.215", "src_port": 58261, "dest_port": 5900}}'); INSERT INTO alerts VALUES(5596,1773122859.337841987,'{"timestamp": "2026-03-10T07:07:39.337842+0100", "flow_id": 888073704487303, "event_type": "alert", "src_ip": "198.235.24.176", "src_port": 20557, "dest_ip": "134.19.61.215", "dest_port": 13946, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-10T07:07:39.337842+0100", "src_ip": "198.235.24.176", "dest_ip": "134.19.61.215", "src_port": 20557, "dest_port": 13946}}'); INSERT INTO alerts VALUES(5597,1773122863.513618946,'{"timestamp": "2026-03-10T07:07:43.513619+0100", "flow_id": 2205979657329098, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 57972, "dest_ip": "134.19.61.215", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:07:43.513619+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.61.215", "src_port": 57972, "dest_port": 3389}}'); INSERT INTO alerts VALUES(5598,1773122877.696842909,'{"timestamp": "2026-03-10T07:07:57.696843+0100", "flow_id": 1585543063261949, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 41135, "dest_ip": "134.19.61.215", "dest_port": 222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:07:57.696843+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.61.215", "src_port": 41135, "dest_port": 222}}'); INSERT INTO alerts VALUES(5599,1773122877.696842909,'{"timestamp": "2026-03-10T07:07:57.696843+0100", "flow_id": 1585543063261949, "event_type": "alert", "src_ip": "185.242.246.38", "src_port": 41135, "dest_ip": "134.19.61.215", "dest_port": 222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:07:57.696843+0100", "src_ip": "185.242.246.38", "dest_ip": "134.19.61.215", "src_port": 41135, "dest_port": 222}}'); INSERT INTO alerts VALUES(5600,1773122894.405576945,'{"timestamp": "2026-03-10T07:08:14.405577+0100", "flow_id": 1741943635172654, "event_type": "alert", "src_ip": "87.121.84.172", "src_port": 55952, "dest_ip": "134.19.61.215", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T07:08:14.405577+0100", "src_ip": "87.121.84.172", "dest_ip": "134.19.61.215", "src_port": 55952, "dest_port": 80}}'); INSERT INTO alerts VALUES(5601,1773122894.405576945,'{"timestamp": "2026-03-10T07:08:14.405577+0100", "flow_id": 1741943635172654, "event_type": "alert", "src_ip": "87.121.84.172", "src_port": 55952, "dest_ip": "134.19.61.215", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T07:08:14.405577+0100", "src_ip": "87.121.84.172", "dest_ip": "134.19.61.215", "src_port": 55952, "dest_port": 80}}'); INSERT INTO alerts VALUES(5602,1773122927.990832091,'{"timestamp": "2026-03-10T07:08:47.990832+0100", "flow_id": 2003792426853411, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 55305, "dest_ip": "134.19.61.215", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T07:08:47.990832+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.61.215", "src_port": 55305, "dest_port": 8545}}'); INSERT INTO alerts VALUES(5603,1773122981.118225098,'{"timestamp": "2026-03-10T07:09:41.118225+0100", "flow_id": 1633673348394212, "event_type": "alert", "src_ip": "185.36.81.23", "src_port": 52089, "dest_ip": "134.19.61.215", "dest_port": 445, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400033, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 34", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:09:41.118225+0100", "src_ip": "185.36.81.23", "dest_ip": "134.19.61.215", "src_port": 52089, "dest_port": 445}}'); INSERT INTO alerts VALUES(5604,1773122984.23259306,'{"timestamp": "2026-03-10T07:09:44.232593+0100", "flow_id": 154556145777925, "event_type": "alert", "src_ip": "64.62.156.72", "src_port": 43856, "dest_ip": "134.19.61.215", "dest_port": 123, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:09:44.232593+0100", "src_ip": "64.62.156.72", "dest_ip": "134.19.61.215", "src_port": 43856, "dest_port": 123}}'); INSERT INTO alerts VALUES(5605,1773122988.678272963,'{"timestamp": "2026-03-10T07:09:48.678273+0100", "flow_id": 1224310951532902, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.61.215", "dest_port": 18396, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:09:48.678273+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.61.215", "src_port": 52302, "dest_port": 18396}}'); INSERT INTO alerts VALUES(5606,1773122988.678272963,'{"timestamp": "2026-03-10T07:09:48.678273+0100", "flow_id": 1224310951532902, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.61.215", "dest_port": 18396, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:09:48.678273+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.61.215", "src_port": 52302, "dest_port": 18396}}'); INSERT INTO alerts VALUES(5607,1773122992.637959957,'{"timestamp": "2026-03-10T07:09:52.637960+0100", "flow_id": 206743661558488, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52327, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:09:52.637960+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52327, "dest_port": 53}}'); INSERT INTO alerts VALUES(5608,1773122995.8483181,'{"timestamp": "2026-03-10T07:09:55.848318+0100", "flow_id": 1110226659756590, "event_type": "alert", "src_ip": "198.235.24.124", "src_port": 56040, "dest_ip": "134.19.61.215", "dest_port": 68, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:09:55.848318+0100", "src_ip": "198.235.24.124", "dest_ip": "134.19.61.215", "src_port": 56040, "dest_port": 68}}'); INSERT INTO alerts VALUES(5609,1773123009.9517591,'{"timestamp": "2026-03-10T07:10:09.951759+0100", "flow_id": 428601065824643, "event_type": "alert", "src_ip": "51.158.205.203", "src_port": 61000, "dest_ip": "134.19.61.215", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101616, "rev": 9, "signature": "GPL DNS named version attempt", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_07_26"]}}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 59, "bytes_toclient": 0, "start": "2026-03-10T07:10:09.951759+0100", "src_ip": "51.158.205.203", "dest_ip": "134.19.61.215", "src_port": 61000, "dest_port": 53}}'); INSERT INTO alerts VALUES(5610,1773123017.284548998,'{"timestamp": "2026-03-10T07:10:17.284549+0100", "flow_id": 377705500382292, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58049, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31349, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:10:17.284549+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58049, "dest_port": 53}}'); INSERT INTO alerts VALUES(5611,1773123029.757980109,'{"timestamp": "2026-03-10T07:10:29.757980+0100", "flow_id": 1566649673781164, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 59549, "dest_ip": "134.19.61.215", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:10:29.757980+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.61.215", "src_port": 59549, "dest_port": 3389}}'); INSERT INTO alerts VALUES(5612,1773123029.949925899,'{"timestamp": "2026-03-10T07:10:29.949926+0100", "flow_id": 1546626817783862, "event_type": "alert", "src_ip": "65.49.1.100", "src_port": 52010, "dest_ip": "134.19.61.215", "dest_port": 143, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:10:29.949926+0100", "src_ip": "65.49.1.100", "dest_ip": "134.19.61.215", "src_port": 52010, "dest_port": 143}}'); INSERT INTO alerts VALUES(5613,1773123045.04214406,'{"timestamp": "2026-03-10T07:10:45.042144+0100", "flow_id": 1588382992684486, "event_type": "alert", "src_ip": "198.235.24.174", "src_port": 56491, "dest_ip": "134.19.61.215", "dest_port": 50995, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:10:45.042144+0100", "src_ip": "198.235.24.174", "dest_ip": "134.19.61.215", "src_port": 56491, "dest_port": 50995}}'); INSERT INTO alerts VALUES(5614,1773123085.997509003,'{"timestamp": "2026-03-10T07:11:25.997509+0100", "flow_id": 1469522547666847, "event_type": "alert", "src_ip": "198.235.24.233", "src_port": 32861, "dest_ip": "134.19.61.215", "dest_port": 12946, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-10T07:11:25.997509+0100", "src_ip": "198.235.24.233", "dest_ip": "134.19.61.215", "src_port": 32861, "dest_port": 12946}}'); INSERT INTO alerts VALUES(5615,1773123106.389859914,'{"timestamp": "2026-03-10T07:11:46.389860+0100", "flow_id": 830014615326032, "event_type": "alert", "src_ip": "198.235.24.112", "src_port": 56984, "dest_ip": "134.19.61.215", "dest_port": 1717, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:11:46.389860+0100", "src_ip": "198.235.24.112", "dest_ip": "134.19.61.215", "src_port": 56984, "dest_port": 1717}}'); INSERT INTO alerts VALUES(5616,1773123155.183248996,'{"timestamp": "2026-03-10T07:12:35.183249+0100", "flow_id": 1068523682017475, "event_type": "alert", "src_ip": "198.235.24.245", "src_port": 49871, "dest_ip": "134.19.61.215", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:12:35.183249+0100", "src_ip": "198.235.24.245", "dest_ip": "134.19.61.215", "src_port": 49871, "dest_port": 8088}}'); INSERT INTO alerts VALUES(5617,1773123190.14044094,'{"timestamp": "2026-03-10T07:13:10.140441+0100", "flow_id": 1729090407623970, "event_type": "alert", "src_ip": "45.142.193.7", "src_port": 47855, "dest_ip": "134.19.61.215", "dest_port": 3505, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:13:10.140441+0100", "src_ip": "45.142.193.7", "dest_ip": "134.19.61.215", "src_port": 47855, "dest_port": 3505}}'); INSERT INTO alerts VALUES(5618,1773123190.798247099,'{"timestamp": "2026-03-10T07:13:10.798247+0100", "flow_id": 1739596566324832, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52501, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41088, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-10T07:13:10.798247+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52501, "dest_port": 53}}'); INSERT INTO alerts VALUES(5619,1773123199.4523561,'{"timestamp": "2026-03-10T07:13:19.452356+0100", "flow_id": 2224331091141529, "event_type": "alert", "src_ip": "64.62.197.189", "src_port": 43052, "dest_ip": "134.19.61.215", "dest_port": 8030, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:13:19.452356+0100", "src_ip": "64.62.197.189", "dest_ip": "134.19.61.215", "src_port": 43052, "dest_port": 8030}}'); INSERT INTO alerts VALUES(5620,1773123216.979028941,'{"timestamp": "2026-03-10T07:13:36.979029+0100", "flow_id": 264251529572965, "event_type": "alert", "src_ip": "64.62.156.225", "src_port": 46743, "dest_ip": "134.19.61.215", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:13:36.979029+0100", "src_ip": "64.62.156.225", "dest_ip": "134.19.61.215", "src_port": 46743, "dest_port": 1521}}'); INSERT INTO alerts VALUES(5621,1773123216.979028941,'{"timestamp": "2026-03-10T07:13:36.979029+0100", "flow_id": 264251529572965, "event_type": "alert", "src_ip": "64.62.156.225", "src_port": 46743, "dest_ip": "134.19.61.215", "dest_port": 1521, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010936, "rev": 3, "signature": "ET SCAN Suspicious inbound to Oracle SQL port 1521", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:13:36.979029+0100", "src_ip": "64.62.156.225", "dest_ip": "134.19.61.215", "src_port": 46743, "dest_port": 1521}}'); INSERT INTO alerts VALUES(5622,1773123259.60291195,'{"timestamp": "2026-03-10T07:14:19.602912+0100", "flow_id": 1090465267468917, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 58632, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:19.581573+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 58632, "dest_port": 853}}'); INSERT INTO alerts VALUES(5623,1773123259.654757976,'{"timestamp": "2026-03-10T07:14:19.654758+0100", "flow_id": 1036370585324216, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 58636, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:19.634514+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 58636, "dest_port": 853}}'); INSERT INTO alerts VALUES(5624,1773123259.692209959,'{"timestamp": "2026-03-10T07:14:19.692210+0100", "flow_id": 895898324827651, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 57720, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:19.667344+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 57720, "dest_port": 853}}'); INSERT INTO alerts VALUES(5625,1773123262.603789091,'{"timestamp": "2026-03-10T07:14:22.603789+0100", "flow_id": 1942054609220984, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 57722, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:22.583241+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 57722, "dest_port": 853}}'); INSERT INTO alerts VALUES(5626,1773123262.660350085,'{"timestamp": "2026-03-10T07:14:22.660350+0100", "flow_id": 1900702458758411, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 57734, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:22.639149+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 57734, "dest_port": 853}}'); INSERT INTO alerts VALUES(5627,1773123262.69162798,'{"timestamp": "2026-03-10T07:14:22.691628+0100", "flow_id": 1751267267751594, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 58642, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:22.669892+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 58642, "dest_port": 853}}'); INSERT INTO alerts VALUES(5628,1773123265.606266022,'{"timestamp": "2026-03-10T07:14:25.606266+0100", "flow_id": 543124626796848, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 58648, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:25.585208+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 58648, "dest_port": 853}}'); INSERT INTO alerts VALUES(5629,1773123265.663526059,'{"timestamp": "2026-03-10T07:14:25.663526+0100", "flow_id": 500384520262594, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 58662, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:25.640792+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 58662, "dest_port": 853}}'); INSERT INTO alerts VALUES(5630,1773123265.692935943,'{"timestamp": "2026-03-10T07:14:25.692936+0100", "flow_id": 351976039657339, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 57740, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:25.671774+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 57740, "dest_port": 853}}'); INSERT INTO alerts VALUES(5631,1773123268.610934973,'{"timestamp": "2026-03-10T07:14:28.610935+0100", "flow_id": 1401521104355847, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 45192, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:28.588461+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 45192, "dest_port": 853}}'); INSERT INTO alerts VALUES(5632,1773123268.666006088,'{"timestamp": "2026-03-10T07:14:28.666006+0100", "flow_id": 1356237495570863, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 45198, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:28.643453+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 45198, "dest_port": 853}}'); INSERT INTO alerts VALUES(5633,1773123268.695734024,'{"timestamp": "2026-03-10T07:14:28.695734+0100", "flow_id": 1210708714977352, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 38962, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:28.675106+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 38962, "dest_port": 853}}'); INSERT INTO alerts VALUES(5634,1773123271.611876011,'{"timestamp": "2026-03-10T07:14:31.611876+0100", "flow_id": 1973932407187411, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 38968, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:31.590663+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 38968, "dest_port": 853}}'); INSERT INTO alerts VALUES(5635,1773123271.666523933,'{"timestamp": "2026-03-10T07:14:31.666524+0100", "flow_id": 2210783331868188, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 38974, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:31.645810+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 38974, "dest_port": 853}}'); INSERT INTO alerts VALUES(5636,1773123273.723537921,'{"timestamp": "2026-03-10T07:14:33.723538+0100", "flow_id": 486492815157245, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 45210, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:33.703094+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 45210, "dest_port": 853}}'); INSERT INTO alerts VALUES(5637,1773123276.637789011,'{"timestamp": "2026-03-10T07:14:36.637789+0100", "flow_id": 1244171106708468, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 45224, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:36.617361+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 45224, "dest_port": 853}}'); INSERT INTO alerts VALUES(5638,1773123276.693895102,'{"timestamp": "2026-03-10T07:14:36.693895+0100", "flow_id": 1195604539879120, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 45232, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:36.671589+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 45232, "dest_port": 853}}'); INSERT INTO alerts VALUES(5639,1773123279.521305085,'{"timestamp": "2026-03-10T07:14:39.521305+0100", "flow_id": 2151101044954855, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 56976, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:39.500842+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 56976, "dest_port": 853}}'); INSERT INTO alerts VALUES(5640,1773123282.43396306,'{"timestamp": "2026-03-10T07:14:42.433963+0100", "flow_id": 645539970858158, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 56980, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:42.412445+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 56980, "dest_port": 853}}'); INSERT INTO alerts VALUES(5641,1773123282.496774912,'{"timestamp": "2026-03-10T07:14:42.496775+0100", "flow_id": 629871961596686, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 56994, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:42.474333+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 56994, "dest_port": 853}}'); INSERT INTO alerts VALUES(5642,1773123289.5757761,'{"timestamp": "2026-03-10T07:14:49.575776+0100", "flow_id": 405843339481127, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 33344, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:49.553244+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 33344, "dest_port": 853}}'); INSERT INTO alerts VALUES(5643,1773123292.483277082,'{"timestamp": "2026-03-10T07:14:52.483277+0100", "flow_id": 1140783592593845, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 33352, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:52.462217+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 33352, "dest_port": 853}}'); INSERT INTO alerts VALUES(5644,1773123292.544553995,'{"timestamp": "2026-03-10T07:14:52.544554+0100", "flow_id": 1126367080017455, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 33368, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:14:52.524396+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 33368, "dest_port": 853}}'); INSERT INTO alerts VALUES(5645,1773123299.962851048,'{"timestamp": "2026-03-10T07:14:59.962851+0100", "flow_id": 1039189803000869, "event_type": "alert", "src_ip": "193.163.125.133", "src_port": 55856, "dest_ip": "134.19.61.215", "dest_port": 8502, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:14:59.962851+0100", "src_ip": "193.163.125.133", "dest_ip": "134.19.61.215", "src_port": 55856, "dest_port": 8502}}'); INSERT INTO alerts VALUES(5646,1773123301.160875082,'{"timestamp": "2026-03-10T07:15:01.160875+0100", "flow_id": 1443138020298640, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 57890, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:15:01.139398+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 57890, "dest_port": 853}}'); INSERT INTO alerts VALUES(5647,1773123304.069345952,'{"timestamp": "2026-03-10T07:15:04.069346+0100", "flow_id": 205874088024030, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 44098, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:15:04.047933+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 44098, "dest_port": 853}}'); INSERT INTO alerts VALUES(5648,1773123306.164727926,'{"timestamp": "2026-03-10T07:15:06.164728+0100", "flow_id": 707501751091568, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50701, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50824, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:15:06.164728+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50701, "dest_port": 53}}'); INSERT INTO alerts VALUES(5649,1773123311.124773026,'{"timestamp": "2026-03-10T07:15:11.124773+0100", "flow_id": 2224746456291961, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59763, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39167, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:15:11.124773+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59763, "dest_port": 53}}'); INSERT INTO alerts VALUES(5650,1773123311.125957013,'{"timestamp": "2026-03-10T07:15:11.125957+0100", "flow_id": 2229832708465678, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54725, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23742, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:15:11.125957+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54725, "dest_port": 53}}'); INSERT INTO alerts VALUES(5651,1773123311.328885078,'{"timestamp": "2026-03-10T07:15:11.328885+0100", "flow_id": 1975500550396172, "event_type": "alert", "src_ip": "198.235.24.119", "src_port": 51838, "dest_ip": "134.19.61.215", "dest_port": 88, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "krb5", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 166, "bytes_toclient": 0, "start": "2026-03-10T07:15:11.328885+0100", "src_ip": "198.235.24.119", "dest_ip": "134.19.61.215", "src_port": 51838, "dest_port": 88}}'); INSERT INTO alerts VALUES(5652,1773123327.239847899,'{"timestamp": "2026-03-10T07:15:27.239848+0100", "flow_id": 2064500636956915, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 44016, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:15:27.218535+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 44016, "dest_port": 853}}'); INSERT INTO alerts VALUES(5653,1773123372.600867034,'{"timestamp": "2026-03-10T07:16:12.600867+0100", "flow_id": 1369291722626649, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 41902, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:16:12.580957+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 41902, "dest_port": 853}}'); INSERT INTO alerts VALUES(5654,1773123372.602355958,'{"timestamp": "2026-03-10T07:16:12.602356+0100", "flow_id": 1367978919682685, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 46918, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:16:12.580651+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 46918, "dest_port": 853}}'); INSERT INTO alerts VALUES(5655,1773123372.904230118,'{"timestamp": "2026-03-10T07:16:12.904230+0100", "flow_id": 1350363916893461, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59951, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48552, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:16:12.904230+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59951, "dest_port": 53}}'); INSERT INTO alerts VALUES(5656,1773123375.629832983,'{"timestamp": "2026-03-10T07:16:15.629833+0100", "flow_id": 2221150032536678, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 46934, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:16:15.582687+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 46934, "dest_port": 853}}'); INSERT INTO alerts VALUES(5657,1773123375.634608031,'{"timestamp": "2026-03-10T07:16:15.634608+0100", "flow_id": 2223936337573427, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 46950, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:16:15.583336+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 46950, "dest_port": 853}}'); INSERT INTO alerts VALUES(5658,1773123378.604569911,'{"timestamp": "2026-03-10T07:16:18.604570+0100", "flow_id": 819830260162343, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35458, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:16:18.584097+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 35458, "dest_port": 853}}'); INSERT INTO alerts VALUES(5659,1773123378.604621887,'{"timestamp": "2026-03-10T07:16:18.604622+0100", "flow_id": 823314995815097, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35442, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:16:18.584908+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 35442, "dest_port": 853}}'); INSERT INTO alerts VALUES(5660,1773123380.843894959,'{"timestamp": "2026-03-10T07:16:20.843895+0100", "flow_id": 1276029570699724, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35468, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:16:20.821386+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 35468, "dest_port": 853}}'); INSERT INTO alerts VALUES(5661,1773123381.002203941,'{"timestamp": "2026-03-10T07:16:21.002204+0100", "flow_id": 1399172320712828, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35482, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:16:20.981130+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 35482, "dest_port": 853}}'); INSERT INTO alerts VALUES(5662,1773123384.830378055,'{"timestamp": "2026-03-10T07:16:24.830378+0100", "flow_id": 188749217741071, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54346, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65224, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "weather-edge.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T07:16:24.830378+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54346, "dest_port": 53}}'); INSERT INTO alerts VALUES(5663,1773123385.019777059,'{"timestamp": "2026-03-10T07:16:25.019777+0100", "flow_id": 366418931702428, "event_type": "alert", "src_ip": "205.210.31.253", "src_port": 56871, "dest_ip": "134.19.61.215", "dest_port": 118, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:16:25.019777+0100", "src_ip": "205.210.31.253", "dest_ip": "134.19.61.215", "src_port": 56871, "dest_port": 118}}'); INSERT INTO alerts VALUES(5664,1773123472.550853967,'{"timestamp": "2026-03-10T07:17:52.550854+0100", "flow_id": 114104372976694, "event_type": "alert", "src_ip": "193.163.125.137", "src_port": 48407, "dest_ip": "134.19.61.215", "dest_port": 32795, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:17:52.550854+0100", "src_ip": "193.163.125.137", "dest_ip": "134.19.61.215", "src_port": 48407, "dest_port": 32795}}'); INSERT INTO alerts VALUES(5665,1773123480.731179953,'{"timestamp": "2026-03-10T07:18:00.731180+0100", "flow_id": 44171616807296, "event_type": "alert", "src_ip": "65.49.1.176", "src_port": 56489, "dest_ip": "134.19.61.215", "dest_port": 5081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:18:00.731180+0100", "src_ip": "65.49.1.176", "dest_ip": "134.19.61.215", "src_port": 56489, "dest_port": 5081}}'); INSERT INTO alerts VALUES(5666,1773123481.867855073,'{"timestamp": "2026-03-10T07:18:01.867855+0100", "flow_id": 349712963236768, "event_type": "alert", "src_ip": "92.63.197.197", "src_port": 41770, "dest_ip": "134.19.61.215", "dest_port": 443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400014, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 15", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:18:01.867855+0100", "src_ip": "92.63.197.197", "dest_ip": "134.19.61.215", "src_port": 41770, "dest_port": 443}}'); INSERT INTO alerts VALUES(5667,1773123517.87270689,'{"timestamp": "2026-03-10T07:18:37.872707+0100", "flow_id": 1496449835270515, "event_type": "alert", "src_ip": "147.185.132.165", "src_port": 51522, "dest_ip": "134.19.61.215", "dest_port": 7777, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:18:37.872707+0100", "src_ip": "147.185.132.165", "dest_ip": "134.19.61.215", "src_port": 51522, "dest_port": 7777}}'); INSERT INTO alerts VALUES(5668,1773123522.322935104,'{"timestamp": "2026-03-10T07:18:42.322935+0100", "flow_id": 824046734838436, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60806, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23481, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "acsegateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-10T07:18:42.322935+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60806, "dest_port": 53}}'); INSERT INTO alerts VALUES(5669,1773123524.223171949,'{"timestamp": "2026-03-10T07:18:44.223172+0100", "flow_id": 1239991779939116, "event_type": "alert", "src_ip": "87.121.84.67", "src_port": 52359, "dest_ip": "134.19.61.215", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:18:44.223172+0100", "src_ip": "87.121.84.67", "dest_ip": "134.19.61.215", "src_port": 52359, "dest_port": 5900}}'); INSERT INTO alerts VALUES(5670,1773123524.223171949,'{"timestamp": "2026-03-10T07:18:44.223172+0100", "flow_id": 1239991779939116, "event_type": "alert", "src_ip": "87.121.84.67", "src_port": 52359, "dest_ip": "134.19.61.215", "dest_port": 5900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:18:44.223172+0100", "src_ip": "87.121.84.67", "dest_ip": "134.19.61.215", "src_port": 52359, "dest_port": 5900}}'); INSERT INTO alerts VALUES(5671,1773123527.379770994,'{"timestamp": "2026-03-10T07:18:47.379771+0100", "flow_id": 2194058062525661, "event_type": "alert", "src_ip": "185.242.226.9", "src_port": 50336, "dest_ip": "134.19.61.215", "dest_port": 9611, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:18:47.379771+0100", "src_ip": "185.242.226.9", "dest_ip": "134.19.61.215", "src_port": 50336, "dest_port": 9611}}'); INSERT INTO alerts VALUES(5672,1773123528.209127903,'{"timestamp": "2026-03-10T07:18:48.209128+0100", "flow_id": 53775285773225, "event_type": "alert", "src_ip": "160.25.242.82", "src_port": 50025, "dest_ip": "134.19.61.215", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T07:18:48.209128+0100", "src_ip": "160.25.242.82", "dest_ip": "134.19.61.215", "src_port": 50025, "dest_port": 1433}}'); INSERT INTO alerts VALUES(5673,1773123531.213619948,'{"timestamp": "2026-03-10T07:18:51.213620+0100", "flow_id": 53775285773225, "event_type": "alert", "src_ip": "160.25.242.82", "src_port": 50025, "dest_ip": "134.19.61.215", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 104, "bytes_toclient": 0, "start": "2026-03-10T07:18:48.209128+0100", "src_ip": "160.25.242.82", "dest_ip": "134.19.61.215", "src_port": 50025, "dest_port": 1433}}'); INSERT INTO alerts VALUES(5674,1773123597.410510064,'{"timestamp": "2026-03-10T07:19:57.410510+0100", "flow_id": 1481653854640622, "event_type": "alert", "src_ip": "64.62.156.214", "src_port": 47381, "dest_ip": "134.19.61.215", "dest_port": 6080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:19:57.410510+0100", "src_ip": "64.62.156.214", "dest_ip": "134.19.61.215", "src_port": 47381, "dest_port": 6080}}'); INSERT INTO alerts VALUES(5675,1773123656.223392964,'{"timestamp": "2026-03-10T07:20:56.223393+0100", "flow_id": 24760577204077, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 50306, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:20:56.202373+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 50306, "dest_port": 853}}'); INSERT INTO alerts VALUES(5676,1773123657.485582113,'{"timestamp": "2026-03-10T07:20:57.485582+0100", "flow_id": 396710354651732, "event_type": "alert", "src_ip": "64.62.197.203", "src_port": 48944, "dest_ip": "134.19.61.215", "dest_port": 6081, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:20:57.485582+0100", "src_ip": "64.62.197.203", "dest_ip": "134.19.61.215", "src_port": 48944, "dest_port": 6081}}'); INSERT INTO alerts VALUES(5677,1773123659.223896981,'{"timestamp": "2026-03-10T07:20:59.223897+0100", "flow_id": 873452848310008, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 59912, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:20:59.203366+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 59912, "dest_port": 853}}'); INSERT INTO alerts VALUES(5678,1773123661.62819004,'{"timestamp": "2026-03-10T07:21:01.628190+0100", "flow_id": 1572159573084509, "event_type": "alert", "src_ip": "45.156.87.24", "src_port": 39656, "dest_ip": "134.19.61.215", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:21:01.628190+0100", "src_ip": "45.156.87.24", "dest_ip": "134.19.61.215", "src_port": 39656, "dest_port": 80}}'); INSERT INTO alerts VALUES(5679,1773123661.62819004,'{"timestamp": "2026-03-10T07:21:01.628190+0100", "flow_id": 1572159573084509, "event_type": "alert", "src_ip": "45.156.87.24", "src_port": 39656, "dest_ip": "134.19.61.215", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:21:01.628190+0100", "src_ip": "45.156.87.24", "dest_ip": "134.19.61.215", "src_port": 39656, "dest_port": 80}}'); INSERT INTO alerts VALUES(5680,1773123662.227108955,'{"timestamp": "2026-03-10T07:21:02.227109+0100", "flow_id": 1727838801950125, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 53028, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:21:02.205685+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 53028, "dest_port": 853}}'); INSERT INTO alerts VALUES(5681,1773123665.241764069,'{"timestamp": "2026-03-10T07:21:05.241764+0100", "flow_id": 385371942475260, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 59924, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:21:05.220798+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 59924, "dest_port": 853}}'); INSERT INTO alerts VALUES(5682,1773123668.252351045,'{"timestamp": "2026-03-10T07:21:08.252351+0100", "flow_id": 1269086165907221, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 57414, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:21:08.229946+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 57414, "dest_port": 853}}'); INSERT INTO alerts VALUES(5683,1773123674.269340039,'{"timestamp": "2026-03-10T07:21:14.269340+0100", "flow_id": 782000688599876, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 38552, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:21:14.247609+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 38552, "dest_port": 853}}'); INSERT INTO alerts VALUES(5684,1773123680.287189006,'{"timestamp": "2026-03-10T07:21:20.287189+0100", "flow_id": 11757341141565, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 42570, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:21:20.264881+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 42570, "dest_port": 853}}'); INSERT INTO alerts VALUES(5685,1773123692.318418979,'{"timestamp": "2026-03-10T07:21:32.318419+0100", "flow_id": 1279001887816793, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 41404, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:21:32.297790+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 41404, "dest_port": 853}}'); INSERT INTO alerts VALUES(5686,1773123704.352988004,'{"timestamp": "2026-03-10T07:21:44.352988+0100", "flow_id": 17473080881141, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 55870, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:21:44.331748+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 55870, "dest_port": 853}}'); INSERT INTO alerts VALUES(5687,1773123708.341547967,'{"timestamp": "2026-03-10T07:21:48.341548+0100", "flow_id": 1185464577105242, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:21:48.341548+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5688,1773123708.342020988,'{"timestamp": "2026-03-10T07:21:48.342021+0100", "flow_id": 1187494088950783, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:21:48.342021+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5689,1773123710.781416894,'{"timestamp": "2026-03-10T07:21:50.781417+0100", "flow_id": 1948786534556494, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53910, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "acsegateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-10T07:21:50.781417+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53910, "dest_port": 53}}'); INSERT INTO alerts VALUES(5690,1773123728.419188022,'{"timestamp": "2026-03-10T07:22:08.419188+0100", "flow_id": 21707190858511, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 55626, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:22:08.398270+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 55626, "dest_port": 853}}'); INSERT INTO alerts VALUES(5691,1773123754.741358042,'{"timestamp": "2026-03-10T07:22:34.741358+0100", "flow_id": 650836326325029, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 58728, "dest_ip": "134.19.61.215", "dest_port": 8000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:22:34.741358+0100", "src_ip": "87.121.84.57", "dest_ip": "134.19.61.215", "src_port": 58728, "dest_port": 8000}}'); INSERT INTO alerts VALUES(5692,1773123754.741358042,'{"timestamp": "2026-03-10T07:22:34.741358+0100", "flow_id": 650836326325029, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 58728, "dest_ip": "134.19.61.215", "dest_port": 8000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:22:34.741358+0100", "src_ip": "87.121.84.57", "dest_ip": "134.19.61.215", "src_port": 58728, "dest_port": 8000}}'); INSERT INTO alerts VALUES(5693,1773123772.005510092,'{"timestamp": "2026-03-10T07:22:52.005510+0100", "flow_id": 1149566135214926, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53910, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "acsegateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-10T07:22:52.005510+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53910, "dest_port": 53}}'); INSERT INTO alerts VALUES(5694,1773123773.360515117,'{"timestamp": "2026-03-10T07:22:53.360515+0100", "flow_id": 1548403984893146, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54086, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37670, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T07:22:53.360515+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54086, "dest_port": 53}}'); INSERT INTO alerts VALUES(5695,1773123807.866353035,'{"timestamp": "2026-03-10T07:23:27.866353+0100", "flow_id": 2032109723767918, "event_type": "alert", "src_ip": "64.62.156.113", "src_port": 52311, "dest_ip": "134.19.61.215", "dest_port": 389, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "ldap", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 80, "bytes_toclient": 0, "start": "2026-03-10T07:23:27.866353+0100", "src_ip": "64.62.156.113", "dest_ip": "134.19.61.215", "src_port": 52311, "dest_port": 389}}'); INSERT INTO alerts VALUES(5696,1773123832.069629908,'{"timestamp": "2026-03-10T07:23:52.069630+0100", "flow_id": 17586708854704, "event_type": "alert", "src_ip": "147.185.132.30", "src_port": 56205, "dest_ip": "134.19.61.215", "dest_port": 4002, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:23:52.069630+0100", "src_ip": "147.185.132.30", "dest_ip": "134.19.61.215", "src_port": 56205, "dest_port": 4002}}'); INSERT INTO alerts VALUES(5697,1773123837.011523962,'{"timestamp": "2026-03-10T07:23:57.011524+0100", "flow_id": 1456872150474074, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:23:57.011524+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5698,1773123837.015754939,'{"timestamp": "2026-03-10T07:23:57.015755+0100", "flow_id": 1475042149417983, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:23:57.015755+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5699,1773123844.410455943,'{"timestamp": "2026-03-10T07:24:04.410456+0100", "flow_id": 1199948785052587, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51444, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49979, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:24:04.410456+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51444, "dest_port": 53}}'); INSERT INTO alerts VALUES(5700,1773123844.41088295,'{"timestamp": "2026-03-10T07:24:04.410883+0100", "flow_id": 1201780878773841, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55768, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9042, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:24:04.410883+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55768, "dest_port": 53}}'); INSERT INTO alerts VALUES(5701,1773123868.259916067,'{"timestamp": "2026-03-10T07:24:28.259916+0100", "flow_id": 1397807760219482, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:24:28.259916+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5702,1773123868.259916067,'{"timestamp": "2026-03-10T07:24:28.259916+0100", "flow_id": 1397805752534015, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:24:28.259916+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5703,1773123875.806492091,'{"timestamp": "2026-03-10T07:24:35.806492+0100", "flow_id": 930582332521319, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58090, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54436, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:24:35.806492+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58090, "dest_port": 53}}'); INSERT INTO alerts VALUES(5704,1773123875.806492091,'{"timestamp": "2026-03-10T07:24:35.806492+0100", "flow_id": 930582589737722, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52187, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33841, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:24:35.806492+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52187, "dest_port": 53}}'); INSERT INTO alerts VALUES(5705,1773123875.827506066,'{"timestamp": "2026-03-10T07:24:35.827506+0100", "flow_id": 1020838885638610, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55578, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12477, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:24:35.827506+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55578, "dest_port": 53}}'); INSERT INTO alerts VALUES(5706,1773123899.576447964,'{"timestamp": "2026-03-10T07:24:59.576448+0100", "flow_id": 1068452488093018, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:24:59.576448+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5707,1773123899.576447964,'{"timestamp": "2026-03-10T07:24:59.576448+0100", "flow_id": 1068450480407551, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:24:59.576448+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5708,1773123904.995513916,'{"timestamp": "2026-03-10T07:25:04.995514+0100", "flow_id": 53575836819530, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61451, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:25:04.995514+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61451, "dest_port": 53}}'); INSERT INTO alerts VALUES(5709,1773123904.995513916,'{"timestamp": "2026-03-10T07:25:04.995514+0100", "flow_id": 53576735906710, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49409, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50223, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:25:04.995514+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49409, "dest_port": 53}}'); INSERT INTO alerts VALUES(5710,1773123915.165093898,'{"timestamp": "2026-03-10T07:25:15.165094+0100", "flow_id": 990551234151746, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64508, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49119, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:25:15.165094+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64508, "dest_port": 53}}'); INSERT INTO alerts VALUES(5711,1773123930.679761887,'{"timestamp": "2026-03-10T07:25:30.679762+0100", "flow_id": 667757809179994, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:25:30.679762+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5712,1773123930.679763079,'{"timestamp": "2026-03-10T07:25:30.679763+0100", "flow_id": 667760096461823, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:25:30.679763+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5713,1773123954.060710907,'{"timestamp": "2026-03-10T07:25:54.060711+0100", "flow_id": 823704126983383, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55280, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21653, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:25:54.060711+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55280, "dest_port": 53}}'); INSERT INTO alerts VALUES(5714,1773123954.061567068,'{"timestamp": "2026-03-10T07:25:54.061567+0100", "flow_id": 827380338009919, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60301, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16852, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:25:54.061567+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60301, "dest_port": 53}}'); INSERT INTO alerts VALUES(5715,1773123962.709108115,'{"timestamp": "2026-03-10T07:26:02.709108+0100", "flow_id": 793797311786878, "event_type": "alert", "src_ip": "147.185.132.24", "src_port": 50036, "dest_ip": "134.19.61.215", "dest_port": 5985, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:26:02.709108+0100", "src_ip": "147.185.132.24", "dest_ip": "134.19.61.215", "src_port": 50036, "dest_port": 5985}}'); INSERT INTO alerts VALUES(5716,1773124015.459749937,'{"timestamp": "2026-03-10T07:26:55.459750+0100", "flow_id": 1974611558436465, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64650, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59663, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "dcs-ups.g03.yahoodns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-10T07:26:55.459750+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64650, "dest_port": 53}}'); INSERT INTO alerts VALUES(5717,1773124047.737023116,'{"timestamp": "2026-03-10T07:27:27.737023+0100", "flow_id": 2039592315172141, "event_type": "alert", "src_ip": "92.63.197.5", "src_port": 49021, "dest_ip": "134.19.61.215", "dest_port": 7813, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400014, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 15", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:27:27.737023+0100", "src_ip": "92.63.197.5", "dest_ip": "134.19.61.215", "src_port": 49021, "dest_port": 7813}}'); INSERT INTO alerts VALUES(5718,1773124094.681293965,'{"timestamp": "2026-03-10T07:28:14.681294+0100", "flow_id": 1800237605920090, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:28:14.681294+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5719,1773124094.681294918,'{"timestamp": "2026-03-10T07:28:14.681295+0100", "flow_id": 1800239893201919, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:28:14.681295+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5720,1773124094.681294918,'{"timestamp": "2026-03-10T07:28:14.681295+0100", "flow_id": 1800242251140311, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55280, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21653, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:28:14.681295+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55280, "dest_port": 53}}'); INSERT INTO alerts VALUES(5721,1773124094.681294918,'{"timestamp": "2026-03-10T07:28:14.681295+0100", "flow_id": 1800241970161471, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60301, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16852, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:28:14.681295+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60301, "dest_port": 53}}'); INSERT INTO alerts VALUES(5722,1773124096.724323988,'{"timestamp": "2026-03-10T07:28:16.724324+0100", "flow_id": 14726867793486, "event_type": "alert", "src_ip": "147.185.132.25", "src_port": 55093, "dest_ip": "134.19.61.215", "dest_port": 30303, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:28:16.724324+0100", "src_ip": "147.185.132.25", "dest_ip": "134.19.61.215", "src_port": 55093, "dest_port": 30303}}'); INSERT INTO alerts VALUES(5723,1773124147.485066891,'{"timestamp": "2026-03-10T07:29:07.485067+0100", "flow_id": 957447349179117, "event_type": "alert", "src_ip": "147.185.132.55", "src_port": 55086, "dest_ip": "134.19.61.215", "dest_port": 23656, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:29:07.485067+0100", "src_ip": "147.185.132.55", "dest_ip": "134.19.61.215", "src_port": 55086, "dest_port": 23656}}'); INSERT INTO alerts VALUES(5724,1773124150.935457945,'{"timestamp": "2026-03-10T07:29:10.935458+0100", "flow_id": 1765965733779327, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56924, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47444, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:29:10.935458+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56924, "dest_port": 53}}'); INSERT INTO alerts VALUES(5725,1773124150.935818911,'{"timestamp": "2026-03-10T07:29:10.935819+0100", "flow_id": 1767514582896047, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54263, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65236, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:29:10.935819+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54263, "dest_port": 53}}'); INSERT INTO alerts VALUES(5726,1773124153.585493087,'{"timestamp": "2026-03-10T07:29:13.585493+0100", "flow_id": 544349437327334, "event_type": "alert", "src_ip": "176.65.148.68", "src_port": 51402, "dest_ip": "134.19.61.215", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:29:13.585493+0100", "src_ip": "176.65.148.68", "dest_ip": "134.19.61.215", "src_port": 51402, "dest_port": 80}}'); INSERT INTO alerts VALUES(5727,1773124158.744988919,'{"timestamp": "2026-03-10T07:29:18.744989+0100", "flow_id": 1963088328524210, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 60758, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:29:18.719211+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 60758, "dest_port": 853}}'); INSERT INTO alerts VALUES(5728,1773124162.909447909,'{"timestamp": "2026-03-10T07:29:22.909448+0100", "flow_id": 713672080960289, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 51554, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:29:22.887060+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 51554, "dest_port": 853}}'); INSERT INTO alerts VALUES(5729,1773124206.869828939,'{"timestamp": "2026-03-10T07:30:06.869829+0100", "flow_id": 1959264491502983, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 45800, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:30:06.849392+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 45800, "dest_port": 853}}'); INSERT INTO alerts VALUES(5730,1773124211.037017107,'{"timestamp": "2026-03-10T07:30:11.037017+0100", "flow_id": 915422677810815, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 36804, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:30:11.016530+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 36804, "dest_port": 853}}'); INSERT INTO alerts VALUES(5731,1773124216.586391925,'{"timestamp": "2026-03-10T07:30:16.586392+0100", "flow_id": 266738327019749, "event_type": "alert", "src_ip": "198.235.24.122", "src_port": 56336, "dest_ip": "134.19.61.215", "dest_port": 10010, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:30:16.586392+0100", "src_ip": "198.235.24.122", "dest_ip": "134.19.61.215", "src_port": 56336, "dest_port": 10010}}'); INSERT INTO alerts VALUES(5732,1773124228.922105074,'{"timestamp": "2026-03-10T07:30:28.922105+0100", "flow_id": 1145663468550464, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49613, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46371, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:30:28.922105+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49613, "dest_port": 53}}'); INSERT INTO alerts VALUES(5733,1773124228.92246008,'{"timestamp": "2026-03-10T07:30:28.922460+0100", "flow_id": 1147190029040878, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59686, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24640, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:30:28.922460+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59686, "dest_port": 53}}'); INSERT INTO alerts VALUES(5734,1773124252.219110965,'{"timestamp": "2026-03-10T07:30:52.219111+0100", "flow_id": 1222553544427468, "event_type": "alert", "src_ip": "185.156.73.181", "src_port": 44082, "dest_ip": "134.19.61.215", "dest_port": 8071, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:30:52.219111+0100", "src_ip": "185.156.73.181", "dest_ip": "134.19.61.215", "src_port": 44082, "dest_port": 8071}}'); INSERT INTO alerts VALUES(5735,1773124265.745670081,'{"timestamp": "2026-03-10T07:31:05.745670+0100", "flow_id": 387879003639554, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54409, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33936, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:31:05.745670+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54409, "dest_port": 53}}'); INSERT INTO alerts VALUES(5736,1773124265.745946884,'{"timestamp": "2026-03-10T07:31:05.745947+0100", "flow_id": 389070809487934, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51073, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11364, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:31:05.745947+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51073, "dest_port": 53}}'); INSERT INTO alerts VALUES(5737,1773124272.94885707,'{"timestamp": "2026-03-10T07:31:12.948857+0100", "flow_id": 134660179942225, "event_type": "alert", "src_ip": "46.151.182.158", "src_port": 44154, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:31:12.948857+0100", "src_ip": "46.151.182.158", "dest_ip": "134.19.61.215", "src_port": 44154, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5738,1773124272.94885707,'{"timestamp": "2026-03-10T07:31:12.948857+0100", "flow_id": 134660179942225, "event_type": "alert", "src_ip": "46.151.182.158", "src_port": 44154, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:31:12.948857+0100", "src_ip": "46.151.182.158", "dest_ip": "134.19.61.215", "src_port": 44154, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5739,1773124281.335504056,'{"timestamp": "2026-03-10T07:31:21.335504+0100", "flow_id": 501943045870403, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 52318, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:31:21.313475+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 52318, "dest_port": 853}}'); INSERT INTO alerts VALUES(5740,1773124283.029774904,'{"timestamp": "2026-03-10T07:31:23.029775+0100", "flow_id": 880101187713392, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 52334, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:31:23.008306+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 52334, "dest_port": 853}}'); INSERT INTO alerts VALUES(5741,1773124284.339250088,'{"timestamp": "2026-03-10T07:31:24.339250+0100", "flow_id": 1361751477049523, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 52348, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:31:24.317057+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 52348, "dest_port": 853}}'); INSERT INTO alerts VALUES(5742,1773124287.340341091,'{"timestamp": "2026-03-10T07:31:27.340341+0100", "flow_id": 2212922418205469, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 60918, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:31:27.318628+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 60918, "dest_port": 853}}'); INSERT INTO alerts VALUES(5743,1773124287.99939704,'{"timestamp": "2026-03-10T07:31:27.999397+0100", "flow_id": 2235447934270337, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 60930, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:31:27.979232+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 60930, "dest_port": 853}}'); INSERT INTO alerts VALUES(5744,1773124288.206475974,'{"timestamp": "2026-03-10T07:31:28.206476+0100", "flow_id": 233225656847499, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 37580, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:31:28.185374+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 37580, "dest_port": 853}}'); INSERT INTO alerts VALUES(5745,1773124288.264339924,'{"timestamp": "2026-03-10T07:31:28.264340+0100", "flow_id": 9434057824152, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57882, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63871, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:31:28.264340+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57882, "dest_port": 53}}'); INSERT INTO alerts VALUES(5746,1773124288.264838933,'{"timestamp": "2026-03-10T07:31:28.264839+0100", "flow_id": 11576274334884, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54162, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7798, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:31:28.264839+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54162, "dest_port": 53}}'); INSERT INTO alerts VALUES(5747,1773124291.729830027,'{"timestamp": "2026-03-10T07:31:31.729830+0100", "flow_id": 882797657914790, "event_type": "alert", "src_ip": "147.185.132.66", "src_port": 56677, "dest_ip": "134.19.61.215", "dest_port": 389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:31:31.729830+0100", "src_ip": "147.185.132.66", "dest_ip": "134.19.61.215", "src_port": 56677, "dest_port": 389}}'); INSERT INTO alerts VALUES(5748,1773124291.848149061,'{"timestamp": "2026-03-10T07:31:31.848149+0100", "flow_id": 1109500416121973, "event_type": "alert", "src_ip": "176.65.148.96", "src_port": 57015, "dest_ip": "134.19.61.215", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T07:31:31.848149+0100", "src_ip": "176.65.148.96", "dest_ip": "134.19.61.215", "src_port": 57015, "dest_port": 8332}}'); INSERT INTO alerts VALUES(5749,1773124307.296093941,'{"timestamp": "2026-03-10T07:31:47.296094+0100", "flow_id": 894572156729947, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 34232, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:31:47.273819+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 34232, "dest_port": 853}}'); INSERT INTO alerts VALUES(5750,1773124310.299861908,'{"timestamp": "2026-03-10T07:31:50.299862+0100", "flow_id": 1755625748298067, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 45594, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:31:50.277691+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 45594, "dest_port": 853}}'); INSERT INTO alerts VALUES(5751,1773124313.301948071,'{"timestamp": "2026-03-10T07:31:53.301948+0100", "flow_id": 356806351975263, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 44972, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:31:53.279683+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 44972, "dest_port": 853}}'); INSERT INTO alerts VALUES(5752,1773124316.304586888,'{"timestamp": "2026-03-10T07:31:56.304587+0100", "flow_id": 1215678169222523, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 44988, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:31:56.283047+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 44988, "dest_port": 853}}'); INSERT INTO alerts VALUES(5753,1773124319.316020011,'{"timestamp": "2026-03-10T07:31:59.316020+0100", "flow_id": 2107727853420251, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35360, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:31:59.294135+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 35360, "dest_port": 853}}'); INSERT INTO alerts VALUES(5754,1773124322.325670957,'{"timestamp": "2026-03-10T07:32:02.325671+0100", "flow_id": 739066463411141, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35374, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:32:02.303149+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 35374, "dest_port": 853}}'); INSERT INTO alerts VALUES(5755,1773124328.344194889,'{"timestamp": "2026-03-10T07:32:08.344195+0100", "flow_id": 258749807287309, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 50980, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:32:08.322388+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 50980, "dest_port": 853}}'); INSERT INTO alerts VALUES(5756,1773124334.361537934,'{"timestamp": "2026-03-10T07:32:14.361538+0100", "flow_id": 1744398119972091, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 36488, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:32:14.340613+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 36488, "dest_port": 853}}'); INSERT INTO alerts VALUES(5757,1773124337.982835054,'{"timestamp": "2026-03-10T07:32:17.982835+0100", "flow_id": 562073762941785, "event_type": "alert", "src_ip": "64.62.197.21", "src_port": 58324, "dest_ip": "134.19.61.215", "dest_port": 12654, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:32:17.982835+0100", "src_ip": "64.62.197.21", "dest_ip": "134.19.61.215", "src_port": 58324, "dest_port": 12654}}'); INSERT INTO alerts VALUES(5758,1773124368.069123984,'{"timestamp": "2026-03-10T07:32:48.069124+0100", "flow_id": 15414366273021, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64939, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36197, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "sharedstreams.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T07:32:48.069124+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64939, "dest_port": 53}}'); INSERT INTO alerts VALUES(5759,1773124370.173532009,'{"timestamp": "2026-03-10T07:32:50.173532+0100", "flow_id": 745318022808596, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63578, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12356, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:32:50.173532+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63578, "dest_port": 53}}'); INSERT INTO alerts VALUES(5760,1773124370.173532009,'{"timestamp": "2026-03-10T07:32:50.173532+0100", "flow_id": 745316601860290, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63528, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:32:50.173532+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63528, "dest_port": 53}}'); INSERT INTO alerts VALUES(5761,1773124370.535232067,'{"timestamp": "2026-03-10T07:32:50.535232+0100", "flow_id": 609954801696664, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58299, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15368, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "sharedstreams.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T07:32:50.535232+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58299, "dest_port": 53}}'); INSERT INTO alerts VALUES(5762,1773124370.603213071,'{"timestamp": "2026-03-10T07:32:50.603213+0100", "flow_id": 620457235629872, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49588, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49579, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "sharedstreams.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T07:32:50.603213+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49588, "dest_port": 53}}'); INSERT INTO alerts VALUES(5763,1773124371.96359992,'{"timestamp": "2026-03-10T07:32:51.963600+0100", "flow_id": 1042406984855410, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49498, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cvws.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:32:51.963600+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49498, "dest_port": 53}}'); INSERT INTO alerts VALUES(5764,1773124379.99909401,'{"timestamp": "2026-03-10T07:32:59.999094+0100", "flow_id": 913380011922723, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62441, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58187, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:32:59.999094+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62441, "dest_port": 53}}'); INSERT INTO alerts VALUES(5765,1773124390.375098943,'{"timestamp": "2026-03-10T07:33:10.375099+0100", "flow_id": 1892515881396506, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55354, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18406, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T07:33:10.375099+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55354, "dest_port": 53}}'); INSERT INTO alerts VALUES(5766,1773124396.708338975,'{"timestamp": "2026-03-10T07:33:16.708339+0100", "flow_id": 1353447025573729, "event_type": "alert", "src_ip": "198.235.24.96", "src_port": 54947, "dest_ip": "134.19.61.215", "dest_port": 8444, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:33:16.708339+0100", "src_ip": "198.235.24.96", "dest_ip": "134.19.61.215", "src_port": 54947, "dest_port": 8444}}'); INSERT INTO alerts VALUES(5767,1773124408.96687293,'{"timestamp": "2026-03-10T07:33:28.966873+0100", "flow_id": 212042361635081, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54928, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5742, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "calendars.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T07:33:28.966873+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54928, "dest_port": 53}}'); INSERT INTO alerts VALUES(5768,1773124411.011132001,'{"timestamp": "2026-03-10T07:33:31.011132+0100", "flow_id": 892237712508581, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52856, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49367, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "sharedstreams.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T07:33:31.011132+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52856, "dest_port": 53}}'); INSERT INTO alerts VALUES(5769,1773124412.774971961,'{"timestamp": "2026-03-10T07:33:32.774972+0100", "flow_id": 1358158235161891, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62441, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58187, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:33:32.774972+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62441, "dest_port": 53}}'); INSERT INTO alerts VALUES(5770,1773124412.774971961,'{"timestamp": "2026-03-10T07:33:32.774972+0100", "flow_id": 1358158316340244, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63578, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12356, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:33:32.774972+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63578, "dest_port": 53}}'); INSERT INTO alerts VALUES(5771,1773124412.774971961,'{"timestamp": "2026-03-10T07:33:32.774972+0100", "flow_id": 1358156895391938, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63528, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42407, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:33:32.774972+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63528, "dest_port": 53}}'); INSERT INTO alerts VALUES(5772,1773124412.775361061,'{"timestamp": "2026-03-10T07:33:32.775361+0100", "flow_id": 1359827924265900, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53188, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42866, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:33:32.775361+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53188, "dest_port": 53}}'); INSERT INTO alerts VALUES(5773,1773124412.917498112,'{"timestamp": "2026-03-10T07:33:32.917498+0100", "flow_id": 1407352587084312, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54316, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32787, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "sharedstreams.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T07:33:32.917498+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54316, "dest_port": 53}}'); INSERT INTO alerts VALUES(5774,1773124412.983850956,'{"timestamp": "2026-03-10T07:33:32.983851+0100", "flow_id": 1129385568610144, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52388, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25316, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "sharedstreams.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T07:33:32.983851+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52388, "dest_port": 53}}'); INSERT INTO alerts VALUES(5775,1773124418.329950095,'{"timestamp": "2026-03-10T07:33:38.329950+0100", "flow_id": 572702534848170, "event_type": "alert", "src_ip": "147.185.132.10", "src_port": 56242, "dest_ip": "134.19.61.215", "dest_port": 8010, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:33:38.329950+0100", "src_ip": "147.185.132.10", "dest_ip": "134.19.61.215", "src_port": 56242, "dest_port": 8010}}'); INSERT INTO alerts VALUES(5776,1773124421.467118025,'{"timestamp": "2026-03-10T07:33:41.467118+0100", "flow_id": 1443310148118997, "event_type": "alert", "src_ip": "64.62.197.160", "src_port": 39435, "dest_ip": "134.19.61.215", "dest_port": 12654, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:33:41.467118+0100", "src_ip": "64.62.197.160", "dest_ip": "134.19.61.215", "src_port": 39435, "dest_port": 12654}}'); INSERT INTO alerts VALUES(5777,1773124444.913779973,'{"timestamp": "2026-03-10T07:34:04.913780+0100", "flow_id": 1391382345225752, "event_type": "alert", "src_ip": "198.235.24.224", "src_port": 50738, "dest_ip": "134.19.61.215", "dest_port": 7547, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:34:04.913780+0100", "src_ip": "198.235.24.224", "dest_ip": "134.19.61.215", "src_port": 50738, "dest_port": 7547}}'); INSERT INTO alerts VALUES(5778,1773124475.058275938,'{"timestamp": "2026-03-10T07:34:35.058276+0100", "flow_id": 1094721067920300, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53188, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42866, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:34:35.058276+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53188, "dest_port": 53}}'); INSERT INTO alerts VALUES(5779,1773124475.058276891,'{"timestamp": "2026-03-10T07:34:35.058277+0100", "flow_id": 1094725591778871, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49396, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43449, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:34:35.058277+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49396, "dest_port": 53}}'); INSERT INTO alerts VALUES(5780,1773124481.98308897,'{"timestamp": "2026-03-10T07:34:41.983089+0100", "flow_id": 281686742993983, "event_type": "alert", "src_ip": "205.210.31.104", "src_port": 57059, "dest_ip": "134.19.61.215", "dest_port": 20000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:34:41.983089+0100", "src_ip": "205.210.31.104", "dest_ip": "134.19.61.215", "src_port": 57059, "dest_port": 20000}}'); INSERT INTO alerts VALUES(5781,1773124495.860477925,'{"timestamp": "2026-03-10T07:34:55.860478+0100", "flow_id": 2006878200514546, "event_type": "alert", "src_ip": "64.89.160.111", "src_port": 47084, "dest_ip": "134.19.61.215", "dest_port": 8089, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:34:55.860478+0100", "src_ip": "64.89.160.111", "dest_ip": "134.19.61.215", "src_port": 47084, "dest_port": 8089}}'); INSERT INTO alerts VALUES(5782,1773124496.367799043,'{"timestamp": "2026-03-10T07:34:56.367799+0100", "flow_id": 172310203193717, "event_type": "alert", "src_ip": "65.49.1.161", "src_port": 49727, "dest_ip": "134.19.61.215", "dest_port": 5800, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:34:56.367799+0100", "src_ip": "65.49.1.161", "dest_ip": "134.19.61.215", "src_port": 49727, "dest_port": 5800}}'); INSERT INTO alerts VALUES(5783,1773124499.454581022,'{"timestamp": "2026-03-10T07:34:59.454581+0100", "flow_id": 1107988650712528, "event_type": "alert", "src_ip": "65.49.1.112", "src_port": 18776, "dest_ip": "134.19.61.215", "dest_port": 137, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 78, "bytes_toclient": 0, "start": "2026-03-10T07:34:59.454581+0100", "src_ip": "65.49.1.112", "dest_ip": "134.19.61.215", "src_port": 18776, "dest_port": 137}}'); INSERT INTO alerts VALUES(5784,1773124517.369008065,'{"timestamp": "2026-03-10T07:35:17.369008+0100", "flow_id": 1584880953009441, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60530, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19689, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:35:17.369008+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60530, "dest_port": 53}}'); INSERT INTO alerts VALUES(5785,1773124517.369009017,'{"timestamp": "2026-03-10T07:35:17.369009+0100", "flow_id": 1584882078577722, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63771, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14845, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:35:17.369009+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63771, "dest_port": 53}}'); INSERT INTO alerts VALUES(5786,1773124519.370887994,'{"timestamp": "2026-03-10T07:35:19.370888+0100", "flow_id": 2155904160072783, "event_type": "alert", "src_ip": "176.65.148.150", "src_port": 45864, "dest_ip": "134.19.61.215", "dest_port": 50880, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:35:19.370888+0100", "src_ip": "176.65.148.150", "dest_ip": "134.19.61.215", "src_port": 45864, "dest_port": 50880}}'); INSERT INTO alerts VALUES(5787,1773124525.15496397,'{"timestamp": "2026-03-10T07:35:25.154964+0100", "flow_id": 1509991459563042, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61198, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21089, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:35:25.154964+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61198, "dest_port": 53}}'); INSERT INTO alerts VALUES(5788,1773124525.15496397,'{"timestamp": "2026-03-10T07:35:25.154964+0100", "flow_id": 1509990699705476, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64756, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39973, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:35:25.154964+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64756, "dest_port": 53}}'); INSERT INTO alerts VALUES(5789,1773124569.021107913,'{"timestamp": "2026-03-10T07:36:09.021108+0100", "flow_id": 372135804487246, "event_type": "alert", "src_ip": "64.62.197.7", "src_port": 46938, "dest_ip": "134.19.61.215", "dest_port": 811, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:36:09.021108+0100", "src_ip": "64.62.197.7", "dest_ip": "134.19.61.215", "src_port": 46938, "dest_port": 811}}'); INSERT INTO alerts VALUES(5790,1773124586.83585,'{"timestamp": "2026-03-10T07:36:26.835850+0100", "flow_id": 775199864628770, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61198, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21089, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:36:26.835850+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61198, "dest_port": 53}}'); INSERT INTO alerts VALUES(5791,1773124586.83585,'{"timestamp": "2026-03-10T07:36:26.835850+0100", "flow_id": 775199104771204, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64756, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39973, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:36:26.835850+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64756, "dest_port": 53}}'); INSERT INTO alerts VALUES(5792,1773124593.538186073,'{"timestamp": "2026-03-10T07:36:33.538186+0100", "flow_id": 341168820208026, "event_type": "alert", "src_ip": "65.49.1.119", "src_port": 50940, "dest_ip": "134.19.61.215", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:36:33.538186+0100", "src_ip": "65.49.1.119", "dest_ip": "134.19.61.215", "src_port": 50940, "dest_port": 3000}}'); INSERT INTO alerts VALUES(5793,1773124599.282006025,'{"timestamp": "2026-03-10T07:36:39.282006+0100", "flow_id": 2055633306137990, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52338, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:36:39.282006+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52338, "dest_port": 53}}'); INSERT INTO alerts VALUES(5794,1773124599.282006979,'{"timestamp": "2026-03-10T07:36:39.282007+0100", "flow_id": 2055639038622902, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53352, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29682, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:36:39.282007+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53352, "dest_port": 53}}'); INSERT INTO alerts VALUES(5795,1773124603.463745117,'{"timestamp": "2026-03-10T07:36:43.463745+0100", "flow_id": 865870821400007, "event_type": "alert", "src_ip": "147.45.50.108", "src_port": 63469, "dest_ip": "134.19.61.215", "dest_port": 23, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2500010, "rev": 7556, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:36:43.463745+0100", "src_ip": "147.45.50.108", "dest_ip": "134.19.61.215", "src_port": 63469, "dest_port": 23}}'); INSERT INTO alerts VALUES(5796,1773124619.682136059,'{"timestamp": "2026-03-10T07:36:59.682136+0100", "flow_id": 959430712073066, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58213, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25231, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T07:36:59.682136+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58213, "dest_port": 53}}'); INSERT INTO alerts VALUES(5797,1773124655.478876114,'{"timestamp": "2026-03-10T07:37:35.478876+0100", "flow_id": 2056759714949146, "event_type": "alert", "src_ip": "64.62.197.219", "src_port": 36490, "dest_ip": "134.19.61.215", "dest_port": 9060, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:37:35.478876+0100", "src_ip": "64.62.197.219", "dest_ip": "134.19.61.215", "src_port": 36490, "dest_port": 9060}}'); INSERT INTO alerts VALUES(5798,1773124661.135313987,'{"timestamp": "2026-03-10T07:37:41.135314+0100", "flow_id": 1425595963553158, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52338, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:37:41.135314+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52338, "dest_port": 53}}'); INSERT INTO alerts VALUES(5799,1773124661.135314942,'{"timestamp": "2026-03-10T07:37:41.135315+0100", "flow_id": 1425601696038070, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53352, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29682, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:37:41.135315+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53352, "dest_port": 53}}'); INSERT INTO alerts VALUES(5800,1773124683.128848076,'{"timestamp": "2026-03-10T07:38:03.128848+0100", "flow_id": 1116349963378010, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:38:03.128848+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5801,1773124683.12884903,'{"timestamp": "2026-03-10T07:38:03.128849+0100", "flow_id": 1116352250659839, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:38:03.128849+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5802,1773124683.12884903,'{"timestamp": "2026-03-10T07:38:03.128849+0100", "flow_id": 1116355855590689, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60530, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19689, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:38:03.128849+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60530, "dest_port": 53}}'); INSERT INTO alerts VALUES(5803,1773124683.12884903,'{"timestamp": "2026-03-10T07:38:03.128849+0100", "flow_id": 1116352686191674, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63771, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14845, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:38:03.128849+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63771, "dest_port": 53}}'); INSERT INTO alerts VALUES(5804,1773124703.494179011,'{"timestamp": "2026-03-10T07:38:23.494179+0100", "flow_id": 2122483839387628, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55983, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37591, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:38:23.494179+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55983, "dest_port": 53}}'); INSERT INTO alerts VALUES(5805,1773124703.494179011,'{"timestamp": "2026-03-10T07:38:23.494179+0100", "flow_id": 2122484549038381, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60686, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30813, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:38:23.494179+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60686, "dest_port": 53}}'); INSERT INTO alerts VALUES(5806,1773124713.92623496,'{"timestamp": "2026-03-10T07:38:33.926235+0100", "flow_id": 318977515449193, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60714, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54976, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:38:33.926235+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60714, "dest_port": 53}}'); INSERT INTO alerts VALUES(5807,1773124713.926235914,'{"timestamp": "2026-03-10T07:38:33.926236+0100", "flow_id": 318979877032257, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51702, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54299, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:38:33.926236+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51702, "dest_port": 53}}'); INSERT INTO alerts VALUES(5808,1773124714.43453002,'{"timestamp": "2026-03-10T07:38:34.434530+0100", "flow_id": 740394296089946, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:38:34.434530+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5809,1773124714.434911012,'{"timestamp": "2026-03-10T07:38:34.434911+0100", "flow_id": 742028670944255, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:38:34.434911+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5810,1773124714.434911012,'{"timestamp": "2026-03-10T07:38:34.434911+0100", "flow_id": 742032275875105, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60530, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19689, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:38:34.434911+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60530, "dest_port": 53}}'); INSERT INTO alerts VALUES(5811,1773124714.435041904,'{"timestamp": "2026-03-10T07:38:34.435042+0100", "flow_id": 742591747191866, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63771, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14845, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:38:34.435042+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63771, "dest_port": 53}}'); INSERT INTO alerts VALUES(5812,1773124724.522996903,'{"timestamp": "2026-03-10T07:38:44.522997+0100", "flow_id": 1401830423700719, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53292, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21154, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:38:44.522997+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53292, "dest_port": 53}}'); INSERT INTO alerts VALUES(5813,1773124724.522996903,'{"timestamp": "2026-03-10T07:38:44.522997+0100", "flow_id": 1401831907699735, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57984, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42770, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:38:44.522997+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57984, "dest_port": 53}}'); INSERT INTO alerts VALUES(5814,1773124730.405920983,'{"timestamp": "2026-03-10T07:38:50.405921+0100", "flow_id": 617521603717765, "event_type": "alert", "src_ip": "64.62.197.45", "src_port": 57193, "dest_ip": "134.19.61.215", "dest_port": 7900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:38:50.405921+0100", "src_ip": "64.62.197.45", "dest_ip": "134.19.61.215", "src_port": 57193, "dest_port": 7900}}'); INSERT INTO alerts VALUES(5815,1773124731.923913956,'{"timestamp": "2026-03-10T07:38:51.923914+0100", "flow_id": 871959317188064, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59607, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17397, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:38:51.923914+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59607, "dest_port": 53}}'); INSERT INTO alerts VALUES(5816,1773124731.923913956,'{"timestamp": "2026-03-10T07:38:51.923914+0100", "flow_id": 871955970473277, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52509, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13150, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:38:51.923914+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52509, "dest_port": 53}}'); INSERT INTO alerts VALUES(5817,1773124738.968441963,'{"timestamp": "2026-03-10T07:38:58.968442+0100", "flow_id": 781730744792214, "event_type": "alert", "src_ip": "45.153.34.187", "src_port": 56410, "dest_ip": "134.19.61.215", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:38:58.968442+0100", "src_ip": "45.153.34.187", "dest_ip": "134.19.61.215", "src_port": 56410, "dest_port": 80}}'); INSERT INTO alerts VALUES(5818,1773124738.968441963,'{"timestamp": "2026-03-10T07:38:58.968442+0100", "flow_id": 781730744792214, "event_type": "alert", "src_ip": "45.153.34.187", "src_port": 56410, "dest_ip": "134.19.61.215", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:38:58.968442+0100", "src_ip": "45.153.34.187", "dest_ip": "134.19.61.215", "src_port": 56410, "dest_port": 80}}'); INSERT INTO alerts VALUES(5819,1773124745.645102025,'{"timestamp": "2026-03-10T07:39:05.645102+0100", "flow_id": 518892537447954, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49344, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55348, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:39:05.645102+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49344, "dest_port": 53}}'); INSERT INTO alerts VALUES(5820,1773124745.645102025,'{"timestamp": "2026-03-10T07:39:05.645102+0100", "flow_id": 518893847244287, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63841, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53940, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:39:05.645102+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63841, "dest_port": 53}}'); INSERT INTO alerts VALUES(5821,1773124745.709247113,'{"timestamp": "2026-03-10T07:39:05.709247+0100", "flow_id": 512919943191898, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:39:05.709247+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5822,1773124745.71010089,'{"timestamp": "2026-03-10T07:39:05.710101+0100", "flow_id": 516585837577215, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:39:05.710101+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5823,1773124745.710685014,'{"timestamp": "2026-03-10T07:39:05.710685+0100", "flow_id": 519097703408929, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60530, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19689, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:39:05.710685+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60530, "dest_port": 53}}'); INSERT INTO alerts VALUES(5824,1773124745.711262942,'{"timestamp": "2026-03-10T07:39:05.711263+0100", "flow_id": 521577025107002, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63771, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14845, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:39:05.711263+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63771, "dest_port": 53}}'); INSERT INTO alerts VALUES(5825,1773124752.818922042,'{"timestamp": "2026-03-10T07:39:12.818922+0100", "flow_id": 139543927206917, "event_type": "alert", "src_ip": "178.20.210.152", "src_port": 40685, "dest_ip": "134.19.61.215", "dest_port": 2222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:39:12.818922+0100", "src_ip": "178.20.210.152", "dest_ip": "134.19.61.215", "src_port": 40685, "dest_port": 2222}}'); INSERT INTO alerts VALUES(5826,1773124759.810604095,'{"timestamp": "2026-03-10T07:39:19.810604+0100", "flow_id": 2074146521753584, "event_type": "alert", "src_ip": "147.185.132.53", "src_port": 49488, "dest_ip": "134.19.61.215", "dest_port": 55422, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:39:19.810604+0100", "src_ip": "147.185.132.53", "dest_ip": "134.19.61.215", "src_port": 49488, "dest_port": 55422}}'); INSERT INTO alerts VALUES(5827,1773124765.745937109,'{"timestamp": "2026-03-10T07:39:25.745937+0100", "flow_id": 1514928324864864, "event_type": "alert", "src_ip": "65.49.1.92", "src_port": 39191, "dest_ip": "134.19.61.215", "dest_port": 6516, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:39:25.745937+0100", "src_ip": "65.49.1.92", "dest_ip": "134.19.61.215", "src_port": 39191, "dest_port": 6516}}'); INSERT INTO alerts VALUES(5828,1773124784.610718011,'{"timestamp": "2026-03-10T07:39:44.610718+0100", "flow_id": 89740279166971, "event_type": "alert", "src_ip": "167.94.138.128", "src_port": 39015, "dest_ip": "134.19.61.215", "dest_port": 6362, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-10T07:39:44.610718+0100", "src_ip": "167.94.138.128", "dest_ip": "134.19.61.215", "src_port": 39015, "dest_port": 6362}}'); INSERT INTO alerts VALUES(5829,1773124787.319333077,'{"timestamp": "2026-03-10T07:39:47.319333+0100", "flow_id": 1090050157749487, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53292, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21154, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:39:47.319333+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53292, "dest_port": 53}}'); INSERT INTO alerts VALUES(5830,1773124787.319936037,'{"timestamp": "2026-03-10T07:39:47.319936+0100", "flow_id": 1092641507027991, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57984, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42770, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:39:47.319936+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57984, "dest_port": 53}}'); INSERT INTO alerts VALUES(5831,1773124828.662672043,'{"timestamp": "2026-03-10T07:40:28.662672+0100", "flow_id": 1157306771512666, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:40:28.662672+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5832,1773124828.662672043,'{"timestamp": "2026-03-10T07:40:28.662672+0100", "flow_id": 1157304763827199, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:40:28.662672+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5833,1773124828.662832022,'{"timestamp": "2026-03-10T07:40:28.662832+0100", "flow_id": 1157995563525409, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60530, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19689, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:40:28.662832+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60530, "dest_port": 53}}'); INSERT INTO alerts VALUES(5834,1773124828.662832022,'{"timestamp": "2026-03-10T07:40:28.662832+0100", "flow_id": 1157992394126394, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63771, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14845, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:40:28.662832+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63771, "dest_port": 53}}'); INSERT INTO alerts VALUES(5835,1773124831.48597002,'{"timestamp": "2026-03-10T07:40:31.485970+0100", "flow_id": 2087225615386130, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49344, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55348, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:40:31.485970+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49344, "dest_port": 53}}'); INSERT INTO alerts VALUES(5836,1773124831.485970973,'{"timestamp": "2026-03-10T07:40:31.485971+0100", "flow_id": 2087231220149759, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63841, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53940, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:40:31.485971+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63841, "dest_port": 53}}'); INSERT INTO alerts VALUES(5837,1773124831.485970973,'{"timestamp": "2026-03-10T07:40:31.485971+0100", "flow_id": 2087233268445898, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56449, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6539, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:40:31.485971+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56449, "dest_port": 53}}'); INSERT INTO alerts VALUES(5838,1773124831.485970973,'{"timestamp": "2026-03-10T07:40:31.485971+0100", "flow_id": 2087231506480996, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63798, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30432, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:40:31.485971+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63798, "dest_port": 53}}'); INSERT INTO alerts VALUES(5839,1773124833.91057396,'{"timestamp": "2026-03-10T07:40:33.910574+0100", "flow_id": 533188154991627, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56527, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29197, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:40:33.910574+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56527, "dest_port": 53}}'); INSERT INTO alerts VALUES(5840,1773124833.910672903,'{"timestamp": "2026-03-10T07:40:33.910673+0100", "flow_id": 533611177677192, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54938, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49554, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:40:33.910673+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54938, "dest_port": 53}}'); INSERT INTO alerts VALUES(5841,1773124845.612425089,'{"timestamp": "2026-03-10T07:40:45.612425+0100", "flow_id": 1504446533954450, "event_type": "alert", "src_ip": "204.76.203.73", "src_port": 40000, "dest_ip": "134.19.61.215", "dest_port": 8181, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:40:45.612425+0100", "src_ip": "204.76.203.73", "dest_ip": "134.19.61.215", "src_port": 40000, "dest_port": 8181}}'); INSERT INTO alerts VALUES(5842,1773124851.37137103,'{"timestamp": "2026-03-10T07:40:51.371371+0100", "flow_id": 1032079263178163, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58201, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4672, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:40:51.371371+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58201, "dest_port": 53}}'); INSERT INTO alerts VALUES(5843,1773124851.371371985,'{"timestamp": "2026-03-10T07:40:51.371372+0100", "flow_id": 1032080835139998, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55414, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64124, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:40:51.371372+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55414, "dest_port": 53}}'); INSERT INTO alerts VALUES(5844,1773124859.788924932,'{"timestamp": "2026-03-10T07:40:59.788925+0100", "flow_id": 855134347402586, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:40:59.788925+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5845,1773124859.788925887,'{"timestamp": "2026-03-10T07:40:59.788926+0100", "flow_id": 855136634684415, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:40:59.788926+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5846,1773124859.788925887,'{"timestamp": "2026-03-10T07:40:59.788926+0100", "flow_id": 855140239615265, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60530, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19689, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:40:59.788926+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60530, "dest_port": 53}}'); INSERT INTO alerts VALUES(5847,1773124859.788925887,'{"timestamp": "2026-03-10T07:40:59.788926+0100", "flow_id": 855137070216250, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63771, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14845, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:40:59.788926+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63771, "dest_port": 53}}'); INSERT INTO alerts VALUES(5848,1773124863.000149966,'{"timestamp": "2026-03-10T07:41:03.000150+0100", "flow_id": 1970971220539590, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50122, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36296, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:41:03.000150+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50122, "dest_port": 53}}'); INSERT INTO alerts VALUES(5849,1773124863.000149966,'{"timestamp": "2026-03-10T07:41:03.000150+0100", "flow_id": 1970972538839779, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53190, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19828, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:41:03.000150+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53190, "dest_port": 53}}'); INSERT INTO alerts VALUES(5850,1773124863.950545073,'{"timestamp": "2026-03-10T07:41:03.950545+0100", "flow_id": 2112236260914902, "event_type": "alert", "src_ip": "167.94.138.111", "src_port": 23777, "dest_ip": "134.19.61.215", "dest_port": 21167, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-10T07:41:03.950545+0100", "src_ip": "167.94.138.111", "dest_ip": "134.19.61.215", "src_port": 23777, "dest_port": 21167}}'); INSERT INTO alerts VALUES(5851,1773124864.205786943,'{"timestamp": "2026-03-10T07:41:04.205787+0100", "flow_id": 39425236585818, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56004, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7739, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:41:04.205787+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56004, "dest_port": 53}}'); INSERT INTO alerts VALUES(5852,1773124864.206041097,'{"timestamp": "2026-03-10T07:41:04.206041+0100", "flow_id": 40517778489687, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62785, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25416, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:41:04.206041+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62785, "dest_port": 53}}'); INSERT INTO alerts VALUES(5853,1773124867.318394899,'{"timestamp": "2026-03-10T07:41:07.318395+0100", "flow_id": 1086024744834607, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56983, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9387, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:41:07.318395+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56983, "dest_port": 53}}'); INSERT INTO alerts VALUES(5854,1773124867.318396092,'{"timestamp": "2026-03-10T07:41:07.318396+0100", "flow_id": 1086025455345860, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63222, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33554, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:41:07.318396+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63222, "dest_port": 53}}'); INSERT INTO alerts VALUES(5855,1773124905.811971902,'{"timestamp": "2026-03-10T07:41:45.811972+0100", "flow_id": 391170473357878, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59664, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 324, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:41:45.811972+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59664, "dest_port": 53}}'); INSERT INTO alerts VALUES(5856,1773124905.811971902,'{"timestamp": "2026-03-10T07:41:45.811972+0100", "flow_id": 391171128935635, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55450, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59020, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:41:45.811972+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55450, "dest_port": 53}}'); INSERT INTO alerts VALUES(5857,1773124924.46538496,'{"timestamp": "2026-03-10T07:42:04.465385+0100", "flow_id": 1154390488718682, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:42:04.465385+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5858,1773124924.46538496,'{"timestamp": "2026-03-10T07:42:04.465385+0100", "flow_id": 1154388481033215, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:42:04.465385+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5859,1773124924.465385914,'{"timestamp": "2026-03-10T07:42:04.465386+0100", "flow_id": 1154396380931361, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60530, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19689, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:42:04.465386+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60530, "dest_port": 53}}'); INSERT INTO alerts VALUES(5860,1773124924.465385914,'{"timestamp": "2026-03-10T07:42:04.465386+0100", "flow_id": 1154393211532346, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63771, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14845, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:42:04.465386+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63771, "dest_port": 53}}'); INSERT INTO alerts VALUES(5861,1773124945.917397976,'{"timestamp": "2026-03-10T07:42:25.917398+0100", "flow_id": 562495154906552, "event_type": "alert", "src_ip": "205.210.31.255", "src_port": 56051, "dest_ip": "134.19.61.215", "dest_port": 808, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:42:25.917398+0100", "src_ip": "205.210.31.255", "dest_ip": "134.19.61.215", "src_port": 56051, "dest_port": 808}}'); INSERT INTO alerts VALUES(5862,1773124950.451440096,'{"timestamp": "2026-03-10T07:42:30.451440+0100", "flow_id": 1938921767882074, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56004, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7739, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:42:30.451440+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56004, "dest_port": 53}}'); INSERT INTO alerts VALUES(5863,1773124950.451440096,'{"timestamp": "2026-03-10T07:42:30.451440+0100", "flow_id": 1938923388092759, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62785, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25416, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:42:30.451440+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62785, "dest_port": 53}}'); INSERT INTO alerts VALUES(5864,1773124950.45144105,'{"timestamp": "2026-03-10T07:42:30.451441+0100", "flow_id": 1938927940408879, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56983, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9387, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:42:30.451441+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56983, "dest_port": 53}}'); INSERT INTO alerts VALUES(5865,1773124950.45144105,'{"timestamp": "2026-03-10T07:42:30.451441+0100", "flow_id": 1938924355952836, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63222, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33554, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:42:30.451441+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63222, "dest_port": 53}}'); INSERT INTO alerts VALUES(5866,1773124950.451442003,'{"timestamp": "2026-03-10T07:42:30.451442+0100", "flow_id": 1938930956206253, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50957, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27020, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:42:30.451442+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50957, "dest_port": 53}}'); INSERT INTO alerts VALUES(5867,1773124950.452178001,'{"timestamp": "2026-03-10T07:42:30.452178+0100", "flow_id": 1942091930594244, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51800, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55102, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:42:30.452178+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51800, "dest_port": 53}}'); INSERT INTO alerts VALUES(5868,1773124959.47439599,'{"timestamp": "2026-03-10T07:42:39.474396+0100", "flow_id": 2037517125820563, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50551, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57395, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:42:39.474396+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50551, "dest_port": 53}}'); INSERT INTO alerts VALUES(5869,1773124959.47439599,'{"timestamp": "2026-03-10T07:42:39.474396+0100", "flow_id": 2037516242096393, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50476, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42570, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:42:39.474396+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50476, "dest_port": 53}}'); INSERT INTO alerts VALUES(5870,1773124959.474883079,'{"timestamp": "2026-03-10T07:42:39.474883+0100", "flow_id": 2039610065864925, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64274, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:42:39.474883+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63181, "dest_port": 53}}'); INSERT INTO alerts VALUES(5871,1773124959.474884034,'{"timestamp": "2026-03-10T07:42:39.474884+0100", "flow_id": 2039611866727903, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57475, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58814, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:42:39.474884+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57475, "dest_port": 53}}'); INSERT INTO alerts VALUES(5872,1773124968.138981104,'{"timestamp": "2026-03-10T07:42:48.138981+0100", "flow_id": 33970928251446, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59664, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 324, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:42:48.138981+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59664, "dest_port": 53}}'); INSERT INTO alerts VALUES(5873,1773124968.139141083,'{"timestamp": "2026-03-10T07:42:48.139141+0100", "flow_id": 34658778596563, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55450, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59020, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:42:48.139141+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55450, "dest_port": 53}}'); INSERT INTO alerts VALUES(5874,1773124998.47883296,'{"timestamp": "2026-03-10T07:43:18.478833+0100", "flow_id": 1775099951072823, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49396, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43449, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:43:18.478833+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49396, "dest_port": 53}}'); INSERT INTO alerts VALUES(5875,1773124998.47883296,'{"timestamp": "2026-03-10T07:43:18.478833+0100", "flow_id": 1775098013151686, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51173, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14516, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:43:18.478833+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51173, "dest_port": 53}}'); INSERT INTO alerts VALUES(5876,1773125000.685409069,'{"timestamp": "2026-03-10T07:43:20.685409+0100", "flow_id": 129061536079194, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:43:20.685409+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5877,1773125000.686212063,'{"timestamp": "2026-03-10T07:43:20.686212+0100", "flow_id": 132508387132415, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:43:20.686212+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5878,1773125003.421844005,'{"timestamp": "2026-03-10T07:43:23.421844+0100", "flow_id": 967383662513949, "event_type": "alert", "src_ip": "65.49.1.90", "src_port": 57272, "dest_ip": "134.19.61.215", "dest_port": 10000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:43:23.421844+0100", "src_ip": "65.49.1.90", "dest_ip": "134.19.61.215", "src_port": 57272, "dest_port": 10000}}'); INSERT INTO alerts VALUES(5879,1773125005.364690066,'{"timestamp": "2026-03-10T07:43:25.364690+0100", "flow_id": 1566332183625612, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52134, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29288, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:43:25.364690+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52134, "dest_port": 53}}'); INSERT INTO alerts VALUES(5880,1773125005.364690066,'{"timestamp": "2026-03-10T07:43:25.364690+0100", "flow_id": 1566331637275005, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24990, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:43:25.364690+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60562, "dest_port": 53}}'); INSERT INTO alerts VALUES(5881,1773125031.841099978,'{"timestamp": "2026-03-10T07:43:51.841100+0100", "flow_id": 2205124172914010, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:43:51.841100+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5882,1773125031.841099978,'{"timestamp": "2026-03-10T07:43:51.841100+0100", "flow_id": 2205122165228543, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:43:51.841100+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5883,1773125062.775567055,'{"timestamp": "2026-03-10T07:44:22.775567+0100", "flow_id": 1923662081105242, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:44:22.775567+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5884,1773125062.775567055,'{"timestamp": "2026-03-10T07:44:22.775567+0100", "flow_id": 1923660073419775, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:44:22.775567+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5885,1773125065.962178946,'{"timestamp": "2026-03-10T07:44:25.962179+0100", "flow_id": 473356568815004, "event_type": "alert", "src_ip": "167.94.138.206", "src_port": 21966, "dest_ip": "134.19.61.215", "dest_port": 500, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "ike", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 364, "bytes_toclient": 0, "start": "2026-03-10T07:44:25.962179+0100", "src_ip": "167.94.138.206", "dest_ip": "134.19.61.215", "src_port": 21966, "dest_port": 500}}'); INSERT INTO alerts VALUES(5886,1773125094.067255021,'{"timestamp": "2026-03-10T07:44:54.067255+0100", "flow_id": 1696234972847450, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:44:54.067255+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5887,1773125094.067255021,'{"timestamp": "2026-03-10T07:44:54.067255+0100", "flow_id": 1696232965161983, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:44:54.067255+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5888,1773125105.167660952,'{"timestamp": "2026-03-10T07:45:05.167661+0100", "flow_id": 438626544200619, "event_type": "alert", "src_ip": "198.235.24.164", "src_port": 54435, "dest_ip": "134.19.61.215", "dest_port": 53524, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:45:05.167661+0100", "src_ip": "198.235.24.164", "dest_ip": "134.19.61.215", "src_port": 54435, "dest_port": 53524}}'); INSERT INTO alerts VALUES(5889,1773125110.396655083,'{"timestamp": "2026-03-10T07:45:10.396655+0100", "flow_id": 1703621397930431, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59730, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59126, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T07:45:10.396655+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59730, "dest_port": 53}}'); INSERT INTO alerts VALUES(5890,1773125123.441531897,'{"timestamp": "2026-03-10T07:45:23.441532+0100", "flow_id": 1051941130452876, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52134, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29288, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:45:23.441532+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52134, "dest_port": 53}}'); INSERT INTO alerts VALUES(5891,1773125123.441531897,'{"timestamp": "2026-03-10T07:45:23.441532+0100", "flow_id": 1051940584102269, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24990, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:45:23.441532+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60562, "dest_port": 53}}'); INSERT INTO alerts VALUES(5892,1773125123.441531897,'{"timestamp": "2026-03-10T07:45:23.441532+0100", "flow_id": 1051941484622278, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51173, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14516, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:45:23.441532+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51173, "dest_port": 53}}'); INSERT INTO alerts VALUES(5893,1773125123.441533089,'{"timestamp": "2026-03-10T07:45:23.441533+0100", "flow_id": 1051948700466236, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59788, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60705, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:45:23.441533+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59788, "dest_port": 53}}'); INSERT INTO alerts VALUES(5894,1773125126.458189965,'{"timestamp": "2026-03-10T07:45:26.458190+0100", "flow_id": 1967914024945269, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63206, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T07:45:26.458190+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63206, "dest_port": 53}}'); INSERT INTO alerts VALUES(5895,1773125126.458189965,'{"timestamp": "2026-03-10T07:45:26.458190+0100", "flow_id": 1967913154855919, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54291, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24393, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T07:45:26.458190+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54291, "dest_port": 53}}'); INSERT INTO alerts VALUES(5896,1773125132.311347007,'{"timestamp": "2026-03-10T07:45:32.311347+0100", "flow_id": 1337226722518894, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61049, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31639, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:45:32.311347+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61049, "dest_port": 53}}'); INSERT INTO alerts VALUES(5897,1773125147.807219028,'{"timestamp": "2026-03-10T07:45:47.807219+0100", "flow_id": 933707194489450, "event_type": "alert", "src_ip": "64.62.156.160", "src_port": 48351, "dest_ip": "134.19.61.215", "dest_port": 6025, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:45:47.807219+0100", "src_ip": "64.62.156.160", "dest_ip": "134.19.61.215", "src_port": 48351, "dest_port": 6025}}'); INSERT INTO alerts VALUES(5898,1773125175.964839936,'{"timestamp": "2026-03-10T07:46:15.964840+0100", "flow_id": 2173633229365395, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50551, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57395, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:46:15.964840+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50551, "dest_port": 53}}'); INSERT INTO alerts VALUES(5899,1773125175.964839936,'{"timestamp": "2026-03-10T07:46:15.964840+0100", "flow_id": 2173632345641225, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50476, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42570, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:46:15.964840+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50476, "dest_port": 53}}'); INSERT INTO alerts VALUES(5900,1773125175.964839936,'{"timestamp": "2026-03-10T07:46:15.964840+0100", "flow_id": 2173634520336605, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64274, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:46:15.964840+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63181, "dest_port": 53}}'); INSERT INTO alerts VALUES(5901,1773125175.964839936,'{"timestamp": "2026-03-10T07:46:15.964840+0100", "flow_id": 2173632026232287, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57475, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58814, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:46:15.964840+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57475, "dest_port": 53}}'); INSERT INTO alerts VALUES(5902,1773125175.964840889,'{"timestamp": "2026-03-10T07:46:15.964841+0100", "flow_id": 2173636211435698, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58061, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49488, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:46:15.964841+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58061, "dest_port": 53}}'); INSERT INTO alerts VALUES(5903,1773125175.964840889,'{"timestamp": "2026-03-10T07:46:15.964841+0100", "flow_id": 2173639870771878, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52386, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23147, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:46:15.964841+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52386, "dest_port": 53}}'); INSERT INTO alerts VALUES(5904,1773125175.965186119,'{"timestamp": "2026-03-10T07:46:15.965186+0100", "flow_id": 2175121068513968, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55259, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33861, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:46:15.965186+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55259, "dest_port": 53}}'); INSERT INTO alerts VALUES(5905,1773125175.965187072,'{"timestamp": "2026-03-10T07:46:15.965187+0100", "flow_id": 2175123449640684, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52842, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8106, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:46:15.965187+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52842, "dest_port": 53}}'); INSERT INTO alerts VALUES(5906,1773125177.153525114,'{"timestamp": "2026-03-10T07:46:17.153525+0100", "flow_id": 377912836998773, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63206, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42833, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T07:46:17.153525+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63206, "dest_port": 53}}'); INSERT INTO alerts VALUES(5907,1773125177.153526067,'{"timestamp": "2026-03-10T07:46:17.153526+0100", "flow_id": 377916261876719, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54291, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24393, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T07:46:17.153526+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54291, "dest_port": 53}}'); INSERT INTO alerts VALUES(5908,1773125177.153526067,'{"timestamp": "2026-03-10T07:46:17.153526+0100", "flow_id": 377916236176730, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42077, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:46:17.153526+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54318, "dest_port": 53}}'); INSERT INTO alerts VALUES(5909,1773125177.153526067,'{"timestamp": "2026-03-10T07:46:17.153526+0100", "flow_id": 377914228491263, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50064, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50792, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:46:17.153526+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50064, "dest_port": 53}}'); INSERT INTO alerts VALUES(5910,1773125177.153527022,'{"timestamp": "2026-03-10T07:46:17.153527+0100", "flow_id": 377918590196677, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4738, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T07:46:17.153527+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62181, "dest_port": 53}}'); INSERT INTO alerts VALUES(5911,1773125177.153527022,'{"timestamp": "2026-03-10T07:46:17.153527+0100", "flow_id": 377920933874397, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63753, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27421, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T07:46:17.153527+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63753, "dest_port": 53}}'); INSERT INTO alerts VALUES(5912,1773125177.154017926,'{"timestamp": "2026-03-10T07:46:17.154018+0100", "flow_id": 380029611067599, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53161, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39454, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:46:17.154018+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53161, "dest_port": 53}}'); INSERT INTO alerts VALUES(5913,1773125177.154017926,'{"timestamp": "2026-03-10T07:46:17.154018+0100", "flow_id": 380028394540161, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63353, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7246, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:46:17.154018+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63353, "dest_port": 53}}'); INSERT INTO alerts VALUES(5914,1773125180.755115986,'{"timestamp": "2026-03-10T07:46:20.755116+0100", "flow_id": 1272877788751922, "event_type": "alert", "src_ip": "45.156.87.127", "src_port": 59404, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:46:20.755116+0100", "src_ip": "45.156.87.127", "dest_ip": "134.19.61.215", "src_port": 59404, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5915,1773125180.755115986,'{"timestamp": "2026-03-10T07:46:20.755116+0100", "flow_id": 1272877788751922, "event_type": "alert", "src_ip": "45.156.87.127", "src_port": 59404, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:46:20.755116+0100", "src_ip": "45.156.87.127", "dest_ip": "134.19.61.215", "src_port": 59404, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5916,1773125180.755115986,'{"timestamp": "2026-03-10T07:46:20.755116+0100", "flow_id": 1272877788751922, "event_type": "alert", "src_ip": "45.156.87.127", "src_port": 59404, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:46:20.755116+0100", "src_ip": "45.156.87.127", "dest_ip": "134.19.61.215", "src_port": 59404, "dest_port": 3306}}'); INSERT INTO alerts VALUES(5917,1773125188.655580044,'{"timestamp": "2026-03-10T07:46:28.655580+0100", "flow_id": 1315492277722049, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 43116, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:46:28.633966+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 43116, "dest_port": 853}}'); INSERT INTO alerts VALUES(5918,1773125188.669068098,'{"timestamp": "2026-03-10T07:46:28.669068+0100", "flow_id": 1373256824029087, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 43132, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:46:28.647416+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 43132, "dest_port": 853}}'); INSERT INTO alerts VALUES(5919,1773125191.676259041,'{"timestamp": "2026-03-10T07:46:31.676259+0100", "flow_id": 1972297527289246, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 42276, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:46:31.655819+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 42276, "dest_port": 853}}'); INSERT INTO alerts VALUES(5920,1773125195.113610983,'{"timestamp": "2026-03-10T07:46:35.113611+0100", "flow_id": 1050907754818056, "event_type": "alert", "src_ip": "64.62.156.30", "src_port": 43829, "dest_ip": "134.19.61.215", "dest_port": 53413, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-10T07:46:35.113611+0100", "src_ip": "64.62.156.30", "dest_ip": "134.19.61.215", "src_port": 43829, "dest_port": 53413}}'); INSERT INTO alerts VALUES(5921,1773125205.146450042,'{"timestamp": "2026-03-10T07:46:45.146450+0100", "flow_id": 1473427024207326, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55611, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4424, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T07:46:45.146450+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55611, "dest_port": 53}}'); INSERT INTO alerts VALUES(5922,1773125205.146450996,'{"timestamp": "2026-03-10T07:46:45.146451+0100", "flow_id": 1473429567151415, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55600, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8175, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T07:46:45.146451+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55600, "dest_port": 53}}'); INSERT INTO alerts VALUES(5923,1773125205.147778988,'{"timestamp": "2026-03-10T07:46:45.147779+0100", "flow_id": 1479133587031368, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53469, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3718, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:46:45.147779+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53469, "dest_port": 53}}'); INSERT INTO alerts VALUES(5924,1773125205.147778988,'{"timestamp": "2026-03-10T07:46:45.147779+0100", "flow_id": 1479132047673286, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49406, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51460, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:46:45.147779+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49406, "dest_port": 53}}'); INSERT INTO alerts VALUES(5925,1773125217.870975017,'{"timestamp": "2026-03-10T07:46:57.870975+0100", "flow_id": 363109812649593, "event_type": "alert", "src_ip": "41.38.31.34", "src_port": 49328, "dest_ip": "134.19.61.215", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:46:57.870975+0100", "src_ip": "41.38.31.34", "dest_ip": "134.19.61.215", "src_port": 49328, "dest_port": 1433}}'); INSERT INTO alerts VALUES(5926,1773125231.983913899,'{"timestamp": "2026-03-10T07:47:11.983914+0100", "flow_id": 1974081629561078, "event_type": "alert", "src_ip": "64.62.156.226", "src_port": 45521, "dest_ip": "134.19.61.215", "dest_port": 7071, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:47:11.983914+0100", "src_ip": "64.62.156.226", "dest_ip": "134.19.61.215", "src_port": 45521, "dest_port": 7071}}'); INSERT INTO alerts VALUES(5927,1773125272.26494193,'{"timestamp": "2026-03-10T07:47:52.264942+0100", "flow_id": 12020003358024, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53469, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3718, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:47:52.264942+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53469, "dest_port": 53}}'); INSERT INTO alerts VALUES(5928,1773125272.26494193,'{"timestamp": "2026-03-10T07:47:52.264942+0100", "flow_id": 12018463999942, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49406, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51460, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:47:52.264942+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49406, "dest_port": 53}}'); INSERT INTO alerts VALUES(5929,1773125275.581990003,'{"timestamp": "2026-03-10T07:47:55.581990+0100", "flow_id": 1092253196947714, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50860, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41889, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:47:55.581990+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50860, "dest_port": 53}}'); INSERT INTO alerts VALUES(5930,1773125275.581990003,'{"timestamp": "2026-03-10T07:47:55.581990+0100", "flow_id": 1092254079889673, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59118, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:47:55.581990+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59118, "dest_port": 53}}'); INSERT INTO alerts VALUES(5931,1773125284.860277892,'{"timestamp": "2026-03-10T07:48:04.860278+0100", "flow_id": 1161592624883566, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61049, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31639, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:48:04.860278+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61049, "dest_port": 53}}'); INSERT INTO alerts VALUES(5932,1773125284.860277892,'{"timestamp": "2026-03-10T07:48:04.860278+0100", "flow_id": 1161594485340023, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59597, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:48:04.860278+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54747, "dest_port": 53}}'); INSERT INTO alerts VALUES(5933,1773125291.245398999,'{"timestamp": "2026-03-10T07:48:11.245399+0100", "flow_id": 1053984569488845, "event_type": "alert", "src_ip": "205.210.31.54", "src_port": 53052, "dest_ip": "134.19.61.215", "dest_port": 8090, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:48:11.245399+0100", "src_ip": "205.210.31.54", "dest_ip": "134.19.61.215", "src_port": 53052, "dest_port": 8090}}'); INSERT INTO alerts VALUES(5934,1773125323.325333118,'{"timestamp": "2026-03-10T07:48:43.325333+0100", "flow_id": 1115823352252474, "event_type": "alert", "src_ip": "87.121.84.72", "src_port": 59189, "dest_ip": "134.19.61.215", "dest_port": 123, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:48:43.325333+0100", "src_ip": "87.121.84.72", "dest_ip": "134.19.61.215", "src_port": 59189, "dest_port": 123}}'); INSERT INTO alerts VALUES(5935,1773125323.325333118,'{"timestamp": "2026-03-10T07:48:43.325333+0100", "flow_id": 1115823352252474, "event_type": "alert", "src_ip": "87.121.84.72", "src_port": 59189, "dest_ip": "134.19.61.215", "dest_port": 123, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:48:43.325333+0100", "src_ip": "87.121.84.72", "dest_ip": "134.19.61.215", "src_port": 59189, "dest_port": 123}}'); INSERT INTO alerts VALUES(5936,1773125332.428781033,'{"timestamp": "2026-03-10T07:48:52.428781+0100", "flow_id": 1278651119498384, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52524, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51882, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:48:52.428781+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52524, "dest_port": 53}}'); INSERT INTO alerts VALUES(5937,1773125332.432429075,'{"timestamp": "2026-03-10T07:48:52.432429+0100", "flow_id": 1294318708470301, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57948, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9783, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:48:52.432429+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57948, "dest_port": 53}}'); INSERT INTO alerts VALUES(5938,1773125337.470371961,'{"timestamp": "2026-03-10T07:48:57.470372+0100", "flow_id": 331382560592130, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50860, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41889, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:48:57.470372+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50860, "dest_port": 53}}'); INSERT INTO alerts VALUES(5939,1773125337.470690966,'{"timestamp": "2026-03-10T07:48:57.470691+0100", "flow_id": 332753538101513, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59118, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59222, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:48:57.470691+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59118, "dest_port": 53}}'); INSERT INTO alerts VALUES(5940,1773125354.910099029,'{"timestamp": "2026-03-10T07:49:14.910099+0100", "flow_id": 812621214792443, "event_type": "alert", "src_ip": "147.185.132.167", "src_port": 49820, "dest_ip": "134.19.61.215", "dest_port": 45490, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:49:14.910099+0100", "src_ip": "147.185.132.167", "dest_ip": "134.19.61.215", "src_port": 49820, "dest_port": 45490}}'); INSERT INTO alerts VALUES(5941,1773125400.021801949,'{"timestamp": "2026-03-10T07:50:00.021802+0100", "flow_id": 93641903583071, "event_type": "alert", "src_ip": "64.62.197.170", "src_port": 58064, "dest_ip": "134.19.61.215", "dest_port": 12846, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-10T07:50:00.021802+0100", "src_ip": "64.62.197.170", "dest_ip": "134.19.61.215", "src_port": 58064, "dest_port": 12846}}'); INSERT INTO alerts VALUES(5942,1773125401.081414937,'{"timestamp": "2026-03-10T07:50:01.081415+0100", "flow_id": 349677447267656, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53469, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3718, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:50:01.081415+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53469, "dest_port": 53}}'); INSERT INTO alerts VALUES(5943,1773125401.081414937,'{"timestamp": "2026-03-10T07:50:01.081415+0100", "flow_id": 349675907909574, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49406, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51460, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:50:01.081415+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49406, "dest_port": 53}}'); INSERT INTO alerts VALUES(5944,1773125415.480315923,'{"timestamp": "2026-03-10T07:50:15.480316+0100", "flow_id": 2062944438051725, "event_type": "alert", "src_ip": "64.62.156.44", "src_port": 11737, "dest_ip": "134.19.61.215", "dest_port": 10001, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 32, "bytes_toclient": 0, "start": "2026-03-10T07:50:15.480316+0100", "src_ip": "64.62.156.44", "dest_ip": "134.19.61.215", "src_port": 11737, "dest_port": 10001}}'); INSERT INTO alerts VALUES(5945,1773125430.563913107,'{"timestamp": "2026-03-10T07:50:30.563913+0100", "flow_id": 1859038850870752, "event_type": "alert", "src_ip": "65.49.1.80", "src_port": 60491, "dest_ip": "134.19.61.215", "dest_port": 8001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:50:30.563913+0100", "src_ip": "65.49.1.80", "dest_ip": "134.19.61.215", "src_port": 60491, "dest_port": 8001}}'); INSERT INTO alerts VALUES(5946,1773125431.648372889,'{"timestamp": "2026-03-10T07:50:31.648373+0100", "flow_id": 2221793562051912, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53469, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3718, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:50:31.648373+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53469, "dest_port": 53}}'); INSERT INTO alerts VALUES(5947,1773125431.648372889,'{"timestamp": "2026-03-10T07:50:31.648373+0100", "flow_id": 2221792022693830, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49406, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51460, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:50:31.648373+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49406, "dest_port": 53}}'); INSERT INTO alerts VALUES(5948,1773125434.451320886,'{"timestamp": "2026-03-10T07:50:34.451321+0100", "flow_id": 812511198057416, "event_type": "alert", "src_ip": "64.62.197.221", "src_port": 49191, "dest_ip": "134.19.61.215", "dest_port": 23656, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:50:34.451321+0100", "src_ip": "64.62.197.221", "dest_ip": "134.19.61.215", "src_port": 49191, "dest_port": 23656}}'); INSERT INTO alerts VALUES(5949,1773125434.751168967,'{"timestamp": "2026-03-10T07:50:34.751169+0100", "flow_id": 692974898640759, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59597, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:50:34.751169+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54747, "dest_port": 53}}'); INSERT INTO alerts VALUES(5950,1773125434.751169919,'{"timestamp": "2026-03-10T07:50:34.751170+0100", "flow_id": 692978218466127, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55063, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42147, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:50:34.751170+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55063, "dest_port": 53}}'); INSERT INTO alerts VALUES(5951,1773125453.112821102,'{"timestamp": "2026-03-10T07:50:53.112821+0100", "flow_id": 1610464866127012, "event_type": "alert", "src_ip": "64.62.156.136", "src_port": 44231, "dest_ip": "134.19.61.215", "dest_port": 23556, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:50:53.112821+0100", "src_ip": "64.62.156.136", "dest_ip": "134.19.61.215", "src_port": 44231, "dest_port": 23556}}'); INSERT INTO alerts VALUES(5952,1773125495.191107035,'{"timestamp": "2026-03-10T07:51:35.191107+0100", "flow_id": 2228176307415097, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59790, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38724, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T07:51:35.191107+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59790, "dest_port": 53}}'); INSERT INTO alerts VALUES(5953,1773125550.61706996,'{"timestamp": "2026-03-10T07:52:30.617070+0100", "flow_id": 1805871203530997, "event_type": "alert", "src_ip": "91.224.92.125", "src_port": 37101, "dest_ip": "134.19.61.215", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:52:30.617070+0100", "src_ip": "91.224.92.125", "dest_ip": "134.19.61.215", "src_port": 37101, "dest_port": 80}}'); INSERT INTO alerts VALUES(5954,1773125558.375770093,'{"timestamp": "2026-03-10T07:52:38.375770+0100", "flow_id": 1895397522392392, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53469, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3718, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:52:38.375770+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53469, "dest_port": 53}}'); INSERT INTO alerts VALUES(5955,1773125558.376244068,'{"timestamp": "2026-03-10T07:52:38.376244+0100", "flow_id": 1897431797532614, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49406, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51460, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:52:38.376244+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49406, "dest_port": 53}}'); INSERT INTO alerts VALUES(5956,1773125569.8603549,'{"timestamp": "2026-03-10T07:52:49.860355+0100", "flow_id": 317498274304818, "event_type": "alert", "src_ip": "205.210.31.251", "src_port": 54896, "dest_ip": "134.19.61.215", "dest_port": 2160, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:52:49.860355+0100", "src_ip": "205.210.31.251", "dest_ip": "134.19.61.215", "src_port": 54896, "dest_port": 2160}}'); INSERT INTO alerts VALUES(5957,1773125569.865237952,'{"timestamp": "2026-03-10T07:52:49.865238+0100", "flow_id": 338471018842985, "event_type": "alert", "src_ip": "147.185.132.214", "src_port": 54787, "dest_ip": "134.19.61.215", "dest_port": 13354, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:52:49.865238+0100", "src_ip": "147.185.132.214", "dest_ip": "134.19.61.215", "src_port": 54787, "dest_port": 13354}}'); INSERT INTO alerts VALUES(5958,1773125570.036154032,'{"timestamp": "2026-03-10T07:52:50.036154+0100", "flow_id": 718231245098776, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53940, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41499, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T07:52:50.036154+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53940, "dest_port": 53}}'); INSERT INTO alerts VALUES(5959,1773125578.530116082,'{"timestamp": "2026-03-10T07:52:58.530116+0100", "flow_id": 587983447948111, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 55063, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42147, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:52:58.530116+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 55063, "dest_port": 53}}'); INSERT INTO alerts VALUES(5960,1773125578.530116082,'{"timestamp": "2026-03-10T07:52:58.530116+0100", "flow_id": 587981283289191, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54427, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8370, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:52:58.530116+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54427, "dest_port": 53}}'); INSERT INTO alerts VALUES(5961,1773125603.027303935,'{"timestamp": "2026-03-10T07:53:23.027304+0100", "flow_id": 961696328286714, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55140, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10448, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:53:23.027304+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55140, "dest_port": 53}}'); INSERT INTO alerts VALUES(5962,1773125603.027304888,'{"timestamp": "2026-03-10T07:53:23.027305+0100", "flow_id": 961699954442446, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56444, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7092, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:53:23.027305+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56444, "dest_port": 53}}'); INSERT INTO alerts VALUES(5963,1773125603.829889059,'{"timestamp": "2026-03-10T07:53:23.829889+0100", "flow_id": 1031075366783099, "event_type": "alert", "src_ip": "167.94.138.149", "src_port": 51687, "dest_ip": "134.19.61.215", "dest_port": 18100, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-10T07:53:23.829889+0100", "src_ip": "167.94.138.149", "dest_ip": "134.19.61.215", "src_port": 51687, "dest_port": 18100}}'); INSERT INTO alerts VALUES(5964,1773125622.870357036,'{"timestamp": "2026-03-10T07:53:42.870357+0100", "flow_id": 1962643480786076, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 38946, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:53:42.850179+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 38946, "dest_port": 853}}'); INSERT INTO alerts VALUES(5965,1773125634.793076992,'{"timestamp": "2026-03-10T07:53:54.793077+0100", "flow_id": 591490483690174, "event_type": "alert", "src_ip": "147.185.132.89", "src_port": 56598, "dest_ip": "134.19.61.215", "dest_port": 39042, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:53:54.793077+0100", "src_ip": "147.185.132.89", "dest_ip": "134.19.61.215", "src_port": 56598, "dest_port": 39042}}'); INSERT INTO alerts VALUES(5966,1773125657.522820949,'{"timestamp": "2026-03-10T07:54:17.522821+0100", "flow_id": 556649333892422, "event_type": "alert", "src_ip": "147.185.132.46", "src_port": 51735, "dest_ip": "134.19.61.215", "dest_port": 20257, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:54:17.522821+0100", "src_ip": "147.185.132.46", "dest_ip": "134.19.61.215", "src_port": 51735, "dest_port": 20257}}'); INSERT INTO alerts VALUES(5967,1773125657.888222933,'{"timestamp": "2026-03-10T07:54:17.888223+0100", "flow_id": 347485405179608, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 33450, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T07:54:17.867337+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 33450, "dest_port": 853}}'); INSERT INTO alerts VALUES(5968,1773125670.368765116,'{"timestamp": "2026-03-10T07:54:30.368765+0100", "flow_id": 1865309107493460, "event_type": "alert", "src_ip": "193.163.125.132", "src_port": 35302, "dest_ip": "134.19.61.215", "dest_port": 1953, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:54:30.368765+0100", "src_ip": "193.163.125.132", "dest_ip": "134.19.61.215", "src_port": 35302, "dest_port": 1953}}'); INSERT INTO alerts VALUES(5969,1773125672.380779027,'{"timestamp": "2026-03-10T07:54:32.380779+0100", "flow_id": 228058976020658, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58061, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49488, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:54:32.380779+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58061, "dest_port": 53}}'); INSERT INTO alerts VALUES(5970,1773125672.380779027,'{"timestamp": "2026-03-10T07:54:32.380779+0100", "flow_id": 228062635356838, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52386, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23147, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:54:32.380779+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52386, "dest_port": 53}}'); INSERT INTO alerts VALUES(5971,1773125672.380779027,'{"timestamp": "2026-03-10T07:54:32.380779+0100", "flow_id": 228062069381808, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55259, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33861, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:54:32.380779+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55259, "dest_port": 53}}'); INSERT INTO alerts VALUES(5972,1773125672.380779982,'{"timestamp": "2026-03-10T07:54:32.380780+0100", "flow_id": 228064450508524, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52842, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8106, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:54:32.380780+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52842, "dest_port": 53}}'); INSERT INTO alerts VALUES(5973,1773125672.380779982,'{"timestamp": "2026-03-10T07:54:32.380780+0100", "flow_id": 228063332535984, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55423, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26675, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:54:32.380780+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55423, "dest_port": 53}}'); INSERT INTO alerts VALUES(5974,1773125672.380780936,'{"timestamp": "2026-03-10T07:54:32.380781+0100", "flow_id": 228070330518180, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50566, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47596, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:54:32.380781+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50566, "dest_port": 53}}'); INSERT INTO alerts VALUES(5975,1773125682.266732932,'{"timestamp": "2026-03-10T07:54:42.266733+0100", "flow_id": 582662059944902, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60704, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56920, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:54:42.266733+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60704, "dest_port": 53}}'); INSERT INTO alerts VALUES(5976,1773125682.277507067,'{"timestamp": "2026-03-10T07:54:42.277507+0100", "flow_id": 628934505895486, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56960, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15544, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:54:42.277507+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56960, "dest_port": 53}}'); INSERT INTO alerts VALUES(5977,1773125707.729532003,'{"timestamp": "2026-03-10T07:55:07.729532+0100", "flow_id": 881519582882316, "event_type": "alert", "src_ip": "193.163.125.120", "src_port": 46948, "dest_ip": "134.19.61.215", "dest_port": 11740, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:55:07.729532+0100", "src_ip": "193.163.125.120", "dest_ip": "134.19.61.215", "src_port": 46948, "dest_port": 11740}}'); INSERT INTO alerts VALUES(5978,1773125719.143914938,'{"timestamp": "2026-03-10T07:55:19.143915+0100", "flow_id": 2025488822659505, "event_type": "alert", "src_ip": "130.12.180.132", "src_port": 45162, "dest_ip": "134.19.61.215", "dest_port": 776, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:55:19.143915+0100", "src_ip": "130.12.180.132", "dest_ip": "134.19.61.215", "src_port": 45162, "dest_port": 776}}'); INSERT INTO alerts VALUES(5979,1773125719.143914938,'{"timestamp": "2026-03-10T07:55:19.143915+0100", "flow_id": 2025488822659505, "event_type": "alert", "src_ip": "130.12.180.132", "src_port": 45162, "dest_ip": "134.19.61.215", "dest_port": 776, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:55:19.143915+0100", "src_ip": "130.12.180.132", "dest_ip": "134.19.61.215", "src_port": 45162, "dest_port": 776}}'); INSERT INTO alerts VALUES(5980,1773125755.94468093,'{"timestamp": "2026-03-10T07:55:55.944681+0100", "flow_id": 961151895177562, "event_type": "alert", "src_ip": "65.49.1.126", "src_port": 57004, "dest_ip": "134.19.61.215", "dest_port": 123, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:55:55.944681+0100", "src_ip": "65.49.1.126", "dest_ip": "134.19.61.215", "src_port": 57004, "dest_port": 123}}'); INSERT INTO alerts VALUES(5981,1773125801.249958992,'{"timestamp": "2026-03-10T07:56:41.249959+0100", "flow_id": 510619610722090, "event_type": "alert", "src_ip": "198.235.24.70", "src_port": 56853, "dest_ip": "134.19.61.215", "dest_port": 8445, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:56:41.249959+0100", "src_ip": "198.235.24.70", "dest_ip": "134.19.61.215", "src_port": 56853, "dest_port": 8445}}'); INSERT INTO alerts VALUES(5982,1773125816.522902966,'{"timestamp": "2026-03-10T07:56:56.522903+0100", "flow_id": 275529132322438, "event_type": "alert", "src_ip": "198.235.24.46", "src_port": 54796, "dest_ip": "134.19.61.215", "dest_port": 10255, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T07:56:56.522903+0100", "src_ip": "198.235.24.46", "dest_ip": "134.19.61.215", "src_port": 54796, "dest_port": 10255}}'); INSERT INTO alerts VALUES(5983,1773125835.487268924,'{"timestamp": "2026-03-10T07:57:15.487269+0100", "flow_id": 966908683974674, "event_type": "alert", "src_ip": "34.95.58.63", "src_port": 45432, "dest_ip": "134.19.61.215", "dest_port": 5432, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010939, "rev": 3, "signature": "ET SCAN Suspicious inbound to PostgreSQL port 5432", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:57:15.487269+0100", "src_ip": "34.95.58.63", "dest_ip": "134.19.61.215", "src_port": 45432, "dest_port": 5432}}'); INSERT INTO alerts VALUES(5984,1773125901.9165349,'{"timestamp": "2026-03-10T07:58:21.916535+0100", "flow_id": 1684688297420903, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54427, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8370, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:58:21.916535+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54427, "dest_port": 53}}'); INSERT INTO alerts VALUES(5985,1773125901.916536092,'{"timestamp": "2026-03-10T07:58:21.916536+0100", "flow_id": 1684695859839382, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63271, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19776, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:58:21.916536+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63271, "dest_port": 53}}'); INSERT INTO alerts VALUES(5986,1773125923.796694994,'{"timestamp": "2026-03-10T07:58:43.796695+0100", "flow_id": 888505095348261, "event_type": "alert", "src_ip": "79.124.62.178", "src_port": 51180, "dest_ip": "134.19.61.215", "dest_port": 7676, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:58:43.796695+0100", "src_ip": "79.124.62.178", "dest_ip": "134.19.61.215", "src_port": 51180, "dest_port": 7676}}'); INSERT INTO alerts VALUES(5987,1773125933.192353964,'{"timestamp": "2026-03-10T07:58:53.192354+0100", "flow_id": 1670579177822500, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64322, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28391, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:58:53.192354+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64322, "dest_port": 53}}'); INSERT INTO alerts VALUES(5988,1773125936.159950971,'{"timestamp": "2026-03-10T07:58:56.159951+0100", "flow_id": 124035971645946, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55140, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10448, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:58:56.159951+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55140, "dest_port": 53}}'); INSERT INTO alerts VALUES(5989,1773125936.159950971,'{"timestamp": "2026-03-10T07:58:56.159951+0100", "flow_id": 124035302834382, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56444, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7092, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:58:56.159951+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56444, "dest_port": 53}}'); INSERT INTO alerts VALUES(5990,1773125937.573426008,'{"timestamp": "2026-03-10T07:58:57.573426+0100", "flow_id": 492523027705754, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:58:57.573426+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(5991,1773125937.57616806,'{"timestamp": "2026-03-10T07:58:57.576168+0100", "flow_id": 504298052026816, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:58:57.576168+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(5992,1773125938.870618105,'{"timestamp": "2026-03-10T07:58:58.870618+0100", "flow_id": 643053595093958, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60704, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56920, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:58:58.870618+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60704, "dest_port": 53}}'); INSERT INTO alerts VALUES(5993,1773125938.870619059,'{"timestamp": "2026-03-10T07:58:58.870619+0100", "flow_id": 643056358364734, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56960, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15544, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:58:58.870619+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56960, "dest_port": 53}}'); INSERT INTO alerts VALUES(5994,1773125938.870619059,'{"timestamp": "2026-03-10T07:58:58.870619+0100", "flow_id": 643057827898284, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51116, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15822, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:58:58.870619+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51116, "dest_port": 53}}'); INSERT INTO alerts VALUES(5995,1773125938.870620012,'{"timestamp": "2026-03-10T07:58:58.870620+0100", "flow_id": 643063164796392, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58274, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50365, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T07:58:58.870620+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58274, "dest_port": 53}}'); INSERT INTO alerts VALUES(5996,1773125940.365931988,'{"timestamp": "2026-03-10T07:59:00.365932+0100", "flow_id": 1290195143449341, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63487, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50933, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:59:00.365932+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63487, "dest_port": 53}}'); INSERT INTO alerts VALUES(5997,1773125940.365931988,'{"timestamp": "2026-03-10T07:59:00.365932+0100", "flow_id": 1290191092311881, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56822, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T07:59:00.365932+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56822, "dest_port": 53}}'); INSERT INTO alerts VALUES(5998,1773125942.429001093,'{"timestamp": "2026-03-10T07:59:02.429001+0100", "flow_id": 1842548981027424, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55757, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22814, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:59:02.429001+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55757, "dest_port": 53}}'); INSERT INTO alerts VALUES(5999,1773125942.429001093,'{"timestamp": "2026-03-10T07:59:02.429001+0100", "flow_id": 1842548796805472, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62204, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57260, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T07:59:02.429001+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62204, "dest_port": 53}}'); INSERT INTO alerts VALUES(6000,1773125968.852056027,'{"timestamp": "2026-03-10T07:59:28.852056+0100", "flow_id": 381654024849, "event_type": "alert", "src_ip": "185.156.73.86", "src_port": 44082, "dest_ip": "134.19.61.215", "dest_port": 44321, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400034, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 35", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T07:59:28.852056+0100", "src_ip": "185.156.73.86", "dest_ip": "134.19.61.215", "src_port": 44082, "dest_port": 44321}}'); INSERT INTO alerts VALUES(6001,1773125974.245814085,'{"timestamp": "2026-03-10T07:59:34.245814+0100", "flow_id": 1900191742333208, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49903, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35747, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T07:59:34.245814+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49903, "dest_port": 53}}'); INSERT INTO alerts VALUES(6002,1773125974.245815039,'{"timestamp": "2026-03-10T07:59:34.245815+0100", "flow_id": 1900193804947772, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64653, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45777, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T07:59:34.245815+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64653, "dest_port": 53}}'); INSERT INTO alerts VALUES(6003,1773125980.069245101,'{"timestamp": "2026-03-10T07:59:40.069245+0100", "flow_id": 1141834073005778, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64186, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmf.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-10T07:59:40.069245+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64186, "dest_port": 53}}'); INSERT INTO alerts VALUES(6004,1773125980.413546085,'{"timestamp": "2026-03-10T07:59:40.413546+0100", "flow_id": 1213218745349321, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60117, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54296, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T07:59:40.413546+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60117, "dest_port": 53}}'); INSERT INTO alerts VALUES(6005,1773125980.413546085,'{"timestamp": "2026-03-10T07:59:40.413546+0100", "flow_id": 1213217386693461, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61470, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 965, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T07:59:40.413546+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61470, "dest_port": 53}}'); INSERT INTO alerts VALUES(6006,1773126001.492258071,'{"timestamp": "2026-03-10T08:00:01.492258+0100", "flow_id": 425382259366180, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64322, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28391, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:00:01.492258+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64322, "dest_port": 53}}'); INSERT INTO alerts VALUES(6007,1773126001.492259026,'{"timestamp": "2026-03-10T08:00:01.492259+0100", "flow_id": 425387231638922, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64878, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5128, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:00:01.492259+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64878, "dest_port": 53}}'); INSERT INTO alerts VALUES(6008,1773126031.240107059,'{"timestamp": "2026-03-10T08:00:31.240107+0100", "flow_id": 2157154942311761, "event_type": "alert", "src_ip": "204.76.203.17", "src_port": 47534, "dest_ip": "134.19.61.215", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 62, "bytes_toclient": 0, "start": "2026-03-10T08:00:31.240107+0100", "src_ip": "204.76.203.17", "dest_ip": "134.19.61.215", "src_port": 47534, "dest_port": 161}}'); INSERT INTO alerts VALUES(6009,1773126031.240107059,'{"timestamp": "2026-03-10T08:00:31.240107+0100", "flow_id": 2157154942311761, "event_type": "alert", "src_ip": "204.76.203.17", "src_port": 47534, "dest_ip": "134.19.61.215", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 62, "bytes_toclient": 0, "start": "2026-03-10T08:00:31.240107+0100", "src_ip": "204.76.203.17", "dest_ip": "134.19.61.215", "src_port": 47534, "dest_port": 161}}'); INSERT INTO alerts VALUES(6010,1773126032.940862895,'{"timestamp": "2026-03-10T08:00:32.940863+0100", "flow_id": 100330222535408, "event_type": "alert", "src_ip": "147.185.132.100", "src_port": 55464, "dest_ip": "134.19.61.215", "dest_port": 5986, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:00:32.940863+0100", "src_ip": "147.185.132.100", "dest_ip": "134.19.61.215", "src_port": 55464, "dest_port": 5986}}'); INSERT INTO alerts VALUES(6011,1773126035.047580957,'{"timestamp": "2026-03-10T08:00:35.047581+0100", "flow_id": 1048784742786527, "event_type": "alert", "src_ip": "64.62.156.100", "src_port": 34609, "dest_ip": "134.19.61.215", "dest_port": 523, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 48, "bytes_toclient": 0, "start": "2026-03-10T08:00:35.047581+0100", "src_ip": "64.62.156.100", "dest_ip": "134.19.61.215", "src_port": 34609, "dest_port": 523}}'); INSERT INTO alerts VALUES(6012,1773126036.093548059,'{"timestamp": "2026-03-10T08:00:36.093548+0100", "flow_id": 1246212561694954, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61572, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43339, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:00:36.093548+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61572, "dest_port": 53}}'); INSERT INTO alerts VALUES(6013,1773126036.093810082,'{"timestamp": "2026-03-10T08:00:36.093810+0100", "flow_id": 1247339581450034, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61462, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11944, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:00:36.093810+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61462, "dest_port": 53}}'); INSERT INTO alerts VALUES(6014,1773126040.269269944,'{"timestamp": "2026-03-10T08:00:40.269270+0100", "flow_id": 30607878621755, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52662, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41796, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmf.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-10T08:00:40.269270+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52662, "dest_port": 53}}'); INSERT INTO alerts VALUES(6015,1773126040.269606114,'{"timestamp": "2026-03-10T08:00:40.269606+0100", "flow_id": 32049459281991, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60672, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3080, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmf.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-10T08:00:40.269606+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60672, "dest_port": 53}}'); INSERT INTO alerts VALUES(6016,1773126046.01522708,'{"timestamp": "2026-03-10T08:00:46.015227+0100", "flow_id": 1754249568407678, "event_type": "alert", "src_ip": "205.210.31.182", "src_port": 50417, "dest_ip": "134.19.61.215", "dest_port": 2096, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:00:46.015227+0100", "src_ip": "205.210.31.182", "dest_ip": "134.19.61.215", "src_port": 50417, "dest_port": 2096}}'); INSERT INTO alerts VALUES(6017,1773126088.721692086,'{"timestamp": "2026-03-10T08:01:28.721692+0100", "flow_id": 3421344786570, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57616, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30481, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T08:01:28.721692+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57616, "dest_port": 53}}'); INSERT INTO alerts VALUES(6018,1773126089.120441913,'{"timestamp": "2026-03-10T08:01:29.120442+0100", "flow_id": 420610456121670, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 60442, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:01:29.097931+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 60442, "dest_port": 853}}'); INSERT INTO alerts VALUES(6019,1773126089.121020079,'{"timestamp": "2026-03-10T08:01:29.121020+0100", "flow_id": 419494841668865, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 60444, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:01:29.097671+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 60444, "dest_port": 853}}'); INSERT INTO alerts VALUES(6020,1773126089.646816015,'{"timestamp": "2026-03-10T08:01:29.646816+0100", "flow_id": 526258003001852, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60273, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49235, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:01:29.646816+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60273, "dest_port": 53}}'); INSERT INTO alerts VALUES(6021,1773126089.65439701,'{"timestamp": "2026-03-10T08:01:29.654397+0100", "flow_id": 460874282436356, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 60460, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:01:29.631593+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 60460, "dest_port": 853}}'); INSERT INTO alerts VALUES(6022,1773126089.658580064,'{"timestamp": "2026-03-10T08:01:29.658580+0100", "flow_id": 485422351797783, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 60468, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:01:29.637309+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 60468, "dest_port": 853}}'); INSERT INTO alerts VALUES(6023,1773126092.120553971,'{"timestamp": "2026-03-10T08:01:32.120554+0100", "flow_id": 1269406769163502, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 54378, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:01:32.098948+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 54378, "dest_port": 853}}'); INSERT INTO alerts VALUES(6024,1773126092.120846034,'{"timestamp": "2026-03-10T08:01:32.120846+0100", "flow_id": 1271464671168815, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 54376, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:01:32.099427+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 54376, "dest_port": 853}}'); INSERT INTO alerts VALUES(6025,1773126092.362148047,'{"timestamp": "2026-03-10T08:01:32.362148+0100", "flow_id": 1180698978314094, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 54402, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:01:32.340438+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 54402, "dest_port": 853}}'); INSERT INTO alerts VALUES(6026,1773126092.660171031,'{"timestamp": "2026-03-10T08:01:32.660171+0100", "flow_id": 1336763676985552, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 54404, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:01:32.638919+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 54404, "dest_port": 853}}'); INSERT INTO alerts VALUES(6027,1773126095.234905958,'{"timestamp": "2026-03-10T08:01:35.234906+0100", "flow_id": 2134816442074382, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57068, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59774, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmipmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 74, "bytes_toclient": 0, "start": "2026-03-10T08:01:35.234906+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57068, "dest_port": 53}}'); INSERT INTO alerts VALUES(6028,1773126095.375145913,'{"timestamp": "2026-03-10T08:01:35.375146+0100", "flow_id": 2174192003384853, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60990, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34208, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:01:35.375146+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60990, "dest_port": 53}}'); INSERT INTO alerts VALUES(6029,1773126095.585103035,'{"timestamp": "2026-03-10T08:01:35.585103+0100", "flow_id": 2231526778498813, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61549, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8541, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "acsegateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-10T08:01:35.585103+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61549, "dest_port": 53}}'); INSERT INTO alerts VALUES(6030,1773126095.859935999,'{"timestamp": "2026-03-10T08:01:35.859936+0100", "flow_id": 2004548833629300, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56704, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13854, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmip.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-10T08:01:35.859936+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56704, "dest_port": 53}}'); INSERT INTO alerts VALUES(6031,1773126096.817003011,'{"timestamp": "2026-03-10T08:01:36.817003+0100", "flow_id": 131302230947210, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64878, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5128, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:01:36.817003+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64878, "dest_port": 53}}'); INSERT INTO alerts VALUES(6032,1773126096.817003966,'{"timestamp": "2026-03-10T08:01:36.817004+0100", "flow_id": 131307671810147, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64109, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38621, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:01:36.817004+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64109, "dest_port": 53}}'); INSERT INTO alerts VALUES(6033,1773126097.223145008,'{"timestamp": "2026-03-10T08:01:37.223145+0100", "flow_id": 395453747639473, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51989, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63162, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmip.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-10T08:01:37.223145+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51989, "dest_port": 53}}'); INSERT INTO alerts VALUES(6034,1773126098.174982071,'{"timestamp": "2026-03-10T08:01:38.174982+0100", "flow_id": 751542727462681, "event_type": "alert", "src_ip": "34.67.77.159", "src_port": 41461, "dest_ip": "134.19.61.215", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:01:38.174982+0100", "src_ip": "34.67.77.159", "dest_ip": "134.19.61.215", "src_port": 41461, "dest_port": 1433}}'); INSERT INTO alerts VALUES(6035,1773126098.174982071,'{"timestamp": "2026-03-10T08:01:38.174982+0100", "flow_id": 751542727462681, "event_type": "alert", "src_ip": "34.67.77.159", "src_port": 41461, "dest_ip": "134.19.61.215", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 80, "bytes_toclient": 0, "start": "2026-03-10T08:01:38.174982+0100", "src_ip": "34.67.77.159", "dest_ip": "134.19.61.215", "src_port": 41461, "dest_port": 1433}}'); INSERT INTO alerts VALUES(6036,1773126098.841826915,'{"timestamp": "2026-03-10T08:01:38.841827+0100", "flow_id": 800869810427100, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64358, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22522, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T08:01:38.841827+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64358, "dest_port": 53}}'); INSERT INTO alerts VALUES(6037,1773126099.060514926,'{"timestamp": "2026-03-10T08:01:39.060515+0100", "flow_id": 1104337694707231, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63263, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11566, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmip.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-10T08:01:39.060515+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63263, "dest_port": 53}}'); INSERT INTO alerts VALUES(6038,1773126101.241367101,'{"timestamp": "2026-03-10T08:01:41.241367+0100", "flow_id": 1599615356869737, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63643, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39171, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:01:41.241367+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63643, "dest_port": 53}}'); INSERT INTO alerts VALUES(6039,1773126101.241802931,'{"timestamp": "2026-03-10T08:01:41.241803+0100", "flow_id": 1601486296924494, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49766, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51133, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:01:41.241803+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49766, "dest_port": 53}}'); INSERT INTO alerts VALUES(6040,1773126108.086765051,'{"timestamp": "2026-03-10T08:01:48.086765+0100", "flow_id": 1217080921025071, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61356, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27027, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:01:48.086765+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61356, "dest_port": 53}}'); INSERT INTO alerts VALUES(6041,1773126112.189812899,'{"timestamp": "2026-03-10T08:01:52.189813+0100", "flow_id": 252292172031605, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59895, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25816, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T08:01:52.189813+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59895, "dest_port": 53}}'); INSERT INTO alerts VALUES(6042,1773126112.193365097,'{"timestamp": "2026-03-10T08:01:52.193365+0100", "flow_id": 267547270969458, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49966, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11824, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:01:52.193365+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49966, "dest_port": 53}}'); INSERT INTO alerts VALUES(6043,1773126141.237827063,'{"timestamp": "2026-03-10T08:02:21.237827+0100", "flow_id": 1584411723213632, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58323, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33116, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:02:21.237827+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58323, "dest_port": 53}}'); INSERT INTO alerts VALUES(6044,1773126147.039068937,'{"timestamp": "2026-03-10T08:02:27.039069+0100", "flow_id": 1012226799186026, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59872, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7454, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:02:27.039069+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59872, "dest_port": 53}}'); INSERT INTO alerts VALUES(6045,1773126149.366280079,'{"timestamp": "2026-03-10T08:02:29.366280+0100", "flow_id": 1573164843833704, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52570, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44233, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:02:29.366280+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52570, "dest_port": 53}}'); INSERT INTO alerts VALUES(6046,1773126149.366280079,'{"timestamp": "2026-03-10T08:02:29.366280+0100", "flow_id": 1573164743810510, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51561, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:02:29.366280+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51561, "dest_port": 53}}'); INSERT INTO alerts VALUES(6047,1773126158.393647909,'{"timestamp": "2026-03-10T08:02:38.393648+0100", "flow_id": 1690709324907203, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64403, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31814, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T08:02:38.393648+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64403, "dest_port": 53}}'); INSERT INTO alerts VALUES(6048,1773126162.757196903,'{"timestamp": "2026-03-10T08:02:42.757197+0100", "flow_id": 718864084641619, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53643, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30705, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:02:42.757197+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53643, "dest_port": 53}}'); INSERT INTO alerts VALUES(6049,1773126180.085711956,'{"timestamp": "2026-03-10T08:03:00.085712+0100", "flow_id": 1212557115010970, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:03:00.085712+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6050,1773126180.085711956,'{"timestamp": "2026-03-10T08:03:00.085712+0100", "flow_id": 1212555339006400, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:03:00.085712+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6051,1773126196.731153964,'{"timestamp": "2026-03-10T08:03:16.731154+0100", "flow_id": 1169960264051520, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58323, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33116, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:03:16.731154+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58323, "dest_port": 53}}'); INSERT INTO alerts VALUES(6052,1773126196.731153964,'{"timestamp": "2026-03-10T08:03:16.731154+0100", "flow_id": 1169959175454952, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62931, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10722, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:03:16.731154+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62931, "dest_port": 53}}'); INSERT INTO alerts VALUES(6053,1773126196.819278002,'{"timestamp": "2026-03-10T08:03:16.819278+0100", "flow_id": 1266973886056160, "event_type": "alert", "src_ip": "92.63.197.236", "src_port": 42086, "dest_ip": "134.19.61.215", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400014, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 15", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:03:16.819278+0100", "src_ip": "92.63.197.236", "dest_ip": "134.19.61.215", "src_port": 42086, "dest_port": 3389}}'); INSERT INTO alerts VALUES(6054,1773126206.52443409,'{"timestamp": "2026-03-10T08:03:26.524434+0100", "flow_id": 1689477213695656, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62835, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36896, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:03:26.524434+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62835, "dest_port": 53}}'); INSERT INTO alerts VALUES(6055,1773126207.319653987,'{"timestamp": "2026-03-10T08:03:27.319654+0100", "flow_id": 2217329441671195, "event_type": "alert", "src_ip": "176.65.148.197", "src_port": 49015, "dest_ip": "134.19.61.215", "dest_port": 5005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:03:27.319654+0100", "src_ip": "176.65.148.197", "dest_ip": "134.19.61.215", "src_port": 49015, "dest_port": 5005}}'); INSERT INTO alerts VALUES(6056,1773126211.122662068,'{"timestamp": "2026-03-10T08:03:31.122662+0100", "flow_id": 1089781179887514, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:03:31.122662+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6057,1773126211.122662068,'{"timestamp": "2026-03-10T08:03:31.122662+0100", "flow_id": 1089779403882944, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:03:31.122662+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6058,1773126211.615711928,'{"timestamp": "2026-03-10T08:03:31.615712+0100", "flow_id": 955617266145640, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52570, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44233, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:03:31.615712+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52570, "dest_port": 53}}'); INSERT INTO alerts VALUES(6059,1773126211.616504907,'{"timestamp": "2026-03-10T08:03:31.616505+0100", "flow_id": 959023075188174, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51561, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:03:31.616505+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51561, "dest_port": 53}}'); INSERT INTO alerts VALUES(6060,1773126216.602269888,'{"timestamp": "2026-03-10T08:03:36.602270+0100", "flow_id": 53458448706507, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52279, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1644, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmip.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-10T08:03:36.602270+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52279, "dest_port": 53}}'); INSERT INTO alerts VALUES(6061,1773126216.60227108,'{"timestamp": "2026-03-10T08:03:36.602271+0100", "flow_id": 53460973825142, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55125, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32665, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmip.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-10T08:03:36.602271+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55125, "dest_port": 53}}'); INSERT INTO alerts VALUES(6062,1773126219.516204118,'{"timestamp": "2026-03-10T08:03:39.516204+0100", "flow_id": 1091182425832018, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57524, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8838, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmip.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-10T08:03:39.516204+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57524, "dest_port": 53}}'); INSERT INTO alerts VALUES(6063,1773126219.516204118,'{"timestamp": "2026-03-10T08:03:39.516204+0100", "flow_id": 1091179710773891, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62132, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19715, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmip.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-10T08:03:39.516204+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62132, "dest_port": 53}}'); INSERT INTO alerts VALUES(6064,1773126221.118818045,'{"timestamp": "2026-03-10T08:03:41.118818+0100", "flow_id": 1636219432276177, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56072, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27149, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:03:41.118818+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56072, "dest_port": 53}}'); INSERT INTO alerts VALUES(6065,1773126221.119129896,'{"timestamp": "2026-03-10T08:03:41.119130+0100", "flow_id": 1637561447867064, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62659, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19049, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:03:41.119130+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62659, "dest_port": 53}}'); INSERT INTO alerts VALUES(6066,1773126231.810182095,'{"timestamp": "2026-03-10T08:03:51.810182+0100", "flow_id": 2072332567378377, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56945, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12888, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:03:51.810182+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56945, "dest_port": 53}}'); INSERT INTO alerts VALUES(6067,1773126233.589879036,'{"timestamp": "2026-03-10T08:03:53.589879+0100", "flow_id": 281714214560882, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59711, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50416, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:03:53.589879+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59711, "dest_port": 53}}'); INSERT INTO alerts VALUES(6068,1773126241.985490084,'{"timestamp": "2026-03-10T08:04:01.985490+0100", "flow_id": 291999594590106, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:04:01.985490+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6069,1773126241.985491037,'{"timestamp": "2026-03-10T08:04:01.985491+0100", "flow_id": 292002113552832, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:04:01.985491+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6070,1773126252.656307936,'{"timestamp": "2026-03-10T08:04:12.656308+0100", "flow_id": 1129975356840842, "event_type": "alert", "src_ip": "34.93.191.230", "src_port": 53022, "dest_ip": "134.19.61.215", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:04:12.656308+0100", "src_ip": "34.93.191.230", "dest_ip": "134.19.61.215", "src_port": 53022, "dest_port": 1433}}'); INSERT INTO alerts VALUES(6071,1773126272.234949112,'{"timestamp": "2026-03-10T08:04:32.234949+0100", "flow_id": 164675289100186, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:04:32.234949+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6072,1773126272.235306024,'{"timestamp": "2026-03-10T08:04:32.235306+0100", "flow_id": 166206816420288, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:04:32.235306+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6073,1773126314.427449941,'{"timestamp": "2026-03-10T08:05:14.427450+0100", "flow_id": 709985010646887, "event_type": "alert", "src_ip": "61.4.72.89", "src_port": 57011, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:05:14.427450+0100", "src_ip": "61.4.72.89", "dest_ip": "134.19.61.215", "src_port": 57011, "dest_port": 3306}}'); INSERT INTO alerts VALUES(6074,1773126338.819734096,'{"timestamp": "2026-03-10T08:05:38.819734+0100", "flow_id": 705983796581393, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50501, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42843, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:05:38.819734+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50501, "dest_port": 53}}'); INSERT INTO alerts VALUES(6075,1773126338.819734096,'{"timestamp": "2026-03-10T08:05:38.819734+0100", "flow_id": 705984748046541, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52582, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44479, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:05:38.819734+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52582, "dest_port": 53}}'); INSERT INTO alerts VALUES(6076,1773126374.259059907,'{"timestamp": "2026-03-10T08:06:14.259060+0100", "flow_id": 1957080165668048, "event_type": "alert", "src_ip": "45.153.34.27", "src_port": 46426, "dest_ip": "134.19.61.215", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:06:14.259060+0100", "src_ip": "45.153.34.27", "dest_ip": "134.19.61.215", "src_port": 46426, "dest_port": 8080}}'); INSERT INTO alerts VALUES(6077,1773126374.259059907,'{"timestamp": "2026-03-10T08:06:14.259060+0100", "flow_id": 1957080165668048, "event_type": "alert", "src_ip": "45.153.34.27", "src_port": 46426, "dest_ip": "134.19.61.215", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:06:14.259060+0100", "src_ip": "45.153.34.27", "dest_ip": "134.19.61.215", "src_port": 46426, "dest_port": 8080}}'); INSERT INTO alerts VALUES(6078,1773126401.15032196,'{"timestamp": "2026-03-10T08:06:41.150322+0100", "flow_id": 364155939427345, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50501, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42843, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:06:41.150322+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50501, "dest_port": 53}}'); INSERT INTO alerts VALUES(6079,1773126401.150322915,'{"timestamp": "2026-03-10T08:06:41.150323+0100", "flow_id": 364161185859789, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52582, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44479, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:06:41.150323+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52582, "dest_port": 53}}'); INSERT INTO alerts VALUES(6080,1773126402.286030055,'{"timestamp": "2026-03-10T08:06:42.286030+0100", "flow_id": 665541490257818, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:06:42.286030+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6081,1773126402.286031008,'{"timestamp": "2026-03-10T08:06:42.286031+0100", "flow_id": 665544009220544, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:06:42.286031+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6082,1773126419.185611964,'{"timestamp": "2026-03-10T08:06:59.185612+0100", "flow_id": 1078672516012117, "event_type": "alert", "src_ip": "167.94.138.130", "src_port": 23459, "dest_ip": "134.19.61.215", "dest_port": 27015, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 53, "bytes_toclient": 0, "start": "2026-03-10T08:06:59.185612+0100", "src_ip": "167.94.138.130", "dest_ip": "134.19.61.215", "src_port": 23459, "dest_port": 27015}}'); INSERT INTO alerts VALUES(6083,1773126428.907773017,'{"timestamp": "2026-03-10T08:07:08.907773+0100", "flow_id": 1365582447536620, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 46378, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:07:08.907773+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.61.215", "src_port": 46378, "dest_port": 3306}}'); INSERT INTO alerts VALUES(6084,1773126428.907773017,'{"timestamp": "2026-03-10T08:07:08.907773+0100", "flow_id": 1365582447536620, "event_type": "alert", "src_ip": "46.151.182.187", "src_port": 46378, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:07:08.907773+0100", "src_ip": "46.151.182.187", "dest_ip": "134.19.61.215", "src_port": 46378, "dest_port": 3306}}'); INSERT INTO alerts VALUES(6085,1773126454.526618004,'{"timestamp": "2026-03-10T08:07:34.526618+0100", "flow_id": 1698860016905170, "event_type": "alert", "src_ip": "198.235.24.166", "src_port": 49806, "dest_ip": "134.19.61.215", "dest_port": 1900, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 125, "bytes_toclient": 0, "start": "2026-03-10T08:07:34.526618+0100", "src_ip": "198.235.24.166", "dest_ip": "134.19.61.215", "src_port": 49806, "dest_port": 1900}}'); INSERT INTO alerts VALUES(6086,1773126462.57883501,'{"timestamp": "2026-03-10T08:07:42.578835+0100", "flow_id": 1923128791747044, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59546, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37041, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:07:42.578835+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59546, "dest_port": 53}}'); INSERT INTO alerts VALUES(6087,1773126462.5795331,'{"timestamp": "2026-03-10T08:07:42.579533+0100", "flow_id": 1926127155309853, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52055, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65197, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:07:42.579533+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52055, "dest_port": 53}}'); INSERT INTO alerts VALUES(6088,1773126462.643342019,'{"timestamp": "2026-03-10T08:07:42.643342+0100", "flow_id": 1918710125665112, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59122, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20733, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "contacts.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:07:42.643342+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59122, "dest_port": 53}}'); INSERT INTO alerts VALUES(6089,1773126462.703773975,'{"timestamp": "2026-03-10T08:07:42.703774+0100", "flow_id": 1896790612004519, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60495, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43987, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "caldav.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-10T08:07:42.703774+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60495, "dest_port": 53}}'); INSERT INTO alerts VALUES(6090,1773126462.859663963,'{"timestamp": "2026-03-10T08:07:42.859664+0100", "flow_id": 1721904518621395, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52595, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 786, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T08:07:42.859664+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52595, "dest_port": 53}}'); INSERT INTO alerts VALUES(6091,1773126463.297343015,'{"timestamp": "2026-03-10T08:07:43.297343+0100", "flow_id": 2121506028938997, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64846, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11938, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "escrowproxy.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-10T08:07:43.297343+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64846, "dest_port": 53}}'); INSERT INTO alerts VALUES(6092,1773126464.294857025,'{"timestamp": "2026-03-10T08:07:44.294857+0100", "flow_id": 140502721772972, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62467, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63025, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:07:44.294857+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62467, "dest_port": 53}}'); INSERT INTO alerts VALUES(6093,1773126464.294857025,'{"timestamp": "2026-03-10T08:07:44.294857+0100", "flow_id": 140501566832488, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63318, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65169, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:07:44.294857+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63318, "dest_port": 53}}'); INSERT INTO alerts VALUES(6094,1773126468.461524964,'{"timestamp": "2026-03-10T08:07:48.461525+0100", "flow_id": 1137812889062307, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 43296, "dest_ip": "134.19.61.215", "dest_port": 23441, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:07:48.461525+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.61.215", "src_port": 43296, "dest_port": 23441}}'); INSERT INTO alerts VALUES(6095,1773126469.101538896,'{"timestamp": "2026-03-10T08:07:49.101539+0100", "flow_id": 1562007105749487, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61594, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51478, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmipmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 74, "bytes_toclient": 0, "start": "2026-03-10T08:07:49.101539+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61594, "dest_port": 53}}'); INSERT INTO alerts VALUES(6096,1773126469.102627993,'{"timestamp": "2026-03-10T08:07:49.102628+0100", "flow_id": 1566683907900550, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59918, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9664, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmipmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 74, "bytes_toclient": 0, "start": "2026-03-10T08:07:49.102628+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59918, "dest_port": 53}}'); INSERT INTO alerts VALUES(6097,1773126488.574507952,'{"timestamp": "2026-03-10T08:08:08.574508+0100", "flow_id": 215696272254066, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59711, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50416, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:08:08.574508+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59711, "dest_port": 53}}'); INSERT INTO alerts VALUES(6098,1773126488.574508905,'{"timestamp": "2026-03-10T08:08:08.574509+0100", "flow_id": 215698979553657, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51504, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61258, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:08:08.574509+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51504, "dest_port": 53}}'); INSERT INTO alerts VALUES(6099,1773126488.574508905,'{"timestamp": "2026-03-10T08:08:08.574509+0100", "flow_id": 215701772600536, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49375, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34618, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:08:08.574509+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49375, "dest_port": 53}}'); INSERT INTO alerts VALUES(6100,1773126488.574510097,'{"timestamp": "2026-03-10T08:08:08.574510+0100", "flow_id": 215703334978986, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49815, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15197, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:08:08.574510+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49815, "dest_port": 53}}'); INSERT INTO alerts VALUES(6101,1773126526.326715946,'{"timestamp": "2026-03-10T08:08:46.326716+0100", "flow_id": 1966188188490842, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65357, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:08:46.326716+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53673, "dest_port": 53}}'); INSERT INTO alerts VALUES(6102,1773126526.327827931,'{"timestamp": "2026-03-10T08:08:46.327828+0100", "flow_id": 1689487780857091, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56146, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54448, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:08:46.327828+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56146, "dest_port": 53}}'); INSERT INTO alerts VALUES(6103,1773126531.79794097,'{"timestamp": "2026-03-10T08:08:51.797941+0100", "flow_id": 893857937231167, "event_type": "alert", "src_ip": "167.94.138.139", "src_port": 63895, "dest_ip": "134.19.61.215", "dest_port": 47001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-10T08:08:51.797941+0100", "src_ip": "167.94.138.139", "dest_ip": "134.19.61.215", "src_port": 63895, "dest_port": 47001}}'); INSERT INTO alerts VALUES(6104,1773126532.322906018,'{"timestamp": "2026-03-10T08:08:52.322906+0100", "flow_id": 1386872657686426, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:08:52.322906+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6105,1773126532.322906018,'{"timestamp": "2026-03-10T08:08:52.322906+0100", "flow_id": 1386870881681856, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:08:52.322906+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6106,1773126545.980582952,'{"timestamp": "2026-03-10T08:09:05.980583+0100", "flow_id": 552400256584827, "event_type": "alert", "src_ip": "176.65.149.180", "src_port": 44751, "dest_ip": "134.19.61.215", "dest_port": 8265, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:09:05.980583+0100", "src_ip": "176.65.149.180", "dest_ip": "134.19.61.215", "src_port": 44751, "dest_port": 8265}}'); INSERT INTO alerts VALUES(6107,1773126545.980582952,'{"timestamp": "2026-03-10T08:09:05.980583+0100", "flow_id": 552400256584827, "event_type": "alert", "src_ip": "176.65.149.180", "src_port": 44751, "dest_ip": "134.19.61.215", "dest_port": 8265, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:09:05.980583+0100", "src_ip": "176.65.149.180", "dest_ip": "134.19.61.215", "src_port": 44751, "dest_port": 8265}}'); INSERT INTO alerts VALUES(6108,1773126563.727524043,'{"timestamp": "2026-03-10T08:09:23.727524+0100", "flow_id": 872893400351097, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51504, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61258, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:09:23.727524+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51504, "dest_port": 53}}'); INSERT INTO alerts VALUES(6109,1773126563.727524043,'{"timestamp": "2026-03-10T08:09:23.727524+0100", "flow_id": 872895940477149, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64831, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12745, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:09:23.727524+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64831, "dest_port": 53}}'); INSERT INTO alerts VALUES(6110,1773126574.684953927,'{"timestamp": "2026-03-10T08:09:34.684954+0100", "flow_id": 1815958055047001, "event_type": "alert", "src_ip": "198.235.24.230", "src_port": 57217, "dest_ip": "134.19.61.215", "dest_port": 8899, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:09:34.684954+0100", "src_ip": "198.235.24.230", "dest_ip": "134.19.61.215", "src_port": 57217, "dest_port": 8899}}'); INSERT INTO alerts VALUES(6111,1773126591.776422977,'{"timestamp": "2026-03-10T08:09:51.776423+0100", "flow_id": 2208812070611103, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.61.215", "dest_port": 22680, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:09:51.776423+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.61.215", "src_port": 52302, "dest_port": 22680}}'); INSERT INTO alerts VALUES(6112,1773126591.776422977,'{"timestamp": "2026-03-10T08:09:51.776423+0100", "flow_id": 2208812070611103, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.61.215", "dest_port": 22680, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:09:51.776423+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.61.215", "src_port": 52302, "dest_port": 22680}}'); INSERT INTO alerts VALUES(6113,1773126593.342587947,'{"timestamp": "2026-03-10T08:09:53.342588+0100", "flow_id": 345507212277280, "event_type": "alert", "src_ip": "193.163.125.131", "src_port": 51622, "dest_ip": "134.19.61.215", "dest_port": 8610, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:09:53.342588+0100", "src_ip": "193.163.125.131", "dest_ip": "134.19.61.215", "src_port": 51622, "dest_port": 8610}}'); INSERT INTO alerts VALUES(6114,1773126606.983521939,'{"timestamp": "2026-03-10T08:10:06.983522+0100", "flow_id": 1690920760579883, "event_type": "alert", "src_ip": "205.210.31.65", "src_port": 51560, "dest_ip": "134.19.61.215", "dest_port": 20122, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:10:06.983522+0100", "src_ip": "205.210.31.65", "dest_ip": "134.19.61.215", "src_port": 51560, "dest_port": 20122}}'); INSERT INTO alerts VALUES(6115,1773126607.353068113,'{"timestamp": "2026-03-10T08:10:07.353068+0100", "flow_id": 2079367414689690, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:10:07.353068+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6116,1773126607.353069067,'{"timestamp": "2026-03-10T08:10:07.353069+0100", "flow_id": 2079369933652416, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:10:07.353069+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6117,1773126617.841305971,'{"timestamp": "2026-03-10T08:10:17.841306+0100", "flow_id": 517161180792908, "event_type": "alert", "src_ip": "176.65.148.58", "src_port": 45708, "dest_ip": "134.19.61.215", "dest_port": 3389, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:10:17.841306+0100", "src_ip": "176.65.148.58", "dest_ip": "134.19.61.215", "src_port": 45708, "dest_port": 3389}}'); INSERT INTO alerts VALUES(6118,1773126638.721477032,'{"timestamp": "2026-03-10T08:10:38.721477+0100", "flow_id": 1691347184267162, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:10:38.721477+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6119,1773126638.721477032,'{"timestamp": "2026-03-10T08:10:38.721477+0100", "flow_id": 1691345408262592, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:10:38.721477+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6120,1773126665.719257116,'{"timestamp": "2026-03-10T08:11:05.719257+0100", "flow_id": 555911663171210, "event_type": "alert", "src_ip": "205.210.31.206", "src_port": 54652, "dest_ip": "134.19.61.215", "dest_port": 10000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:11:05.719257+0100", "src_ip": "205.210.31.206", "dest_ip": "134.19.61.215", "src_port": 54652, "dest_port": 10000}}'); INSERT INTO alerts VALUES(6121,1773126666.948378087,'{"timestamp": "2026-03-10T08:11:06.948378+0100", "flow_id": 695556740825309, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64831, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 12745, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:11:06.948378+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64831, "dest_port": 53}}'); INSERT INTO alerts VALUES(6122,1773126666.94837904,'{"timestamp": "2026-03-10T08:11:06.948379+0100", "flow_id": 695558848237547, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60577, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:11:06.948379+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60577, "dest_port": 53}}'); INSERT INTO alerts VALUES(6123,1773126669.689486027,'{"timestamp": "2026-03-10T08:11:09.689486+0100", "flow_id": 1553946885500826, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:11:09.689486+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6124,1773126669.689486027,'{"timestamp": "2026-03-10T08:11:09.689486+0100", "flow_id": 1553945109496256, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:11:09.689486+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6125,1773126699.895658016,'{"timestamp": "2026-03-10T08:11:39.895658+0100", "flow_id": 1032073999298458, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:11:39.895658+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6126,1773126699.895658016,'{"timestamp": "2026-03-10T08:11:39.895658+0100", "flow_id": 1032072223293888, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:11:39.895658+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6127,1773126711.454180003,'{"timestamp": "2026-03-10T08:11:51.454180+0100", "flow_id": 2232166595850623, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62081, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15552, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:11:51.454180+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62081, "dest_port": 53}}'); INSERT INTO alerts VALUES(6128,1773126711.454180955,'{"timestamp": "2026-03-10T08:11:51.454181+0100", "flow_id": 2232169950434457, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50379, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48417, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:11:51.454181+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50379, "dest_port": 53}}'); INSERT INTO alerts VALUES(6129,1773126719.373923064,'{"timestamp": "2026-03-10T08:11:59.373923+0100", "flow_id": 2168939491419985, "event_type": "alert", "src_ip": "64.62.156.161", "src_port": 35276, "dest_ip": "134.19.61.215", "dest_port": 7547, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:11:59.373923+0100", "src_ip": "64.62.156.161", "dest_ip": "134.19.61.215", "src_port": 35276, "dest_port": 7547}}'); INSERT INTO alerts VALUES(6130,1773126730.857098102,'{"timestamp": "2026-03-10T08:12:10.857098+0100", "flow_id": 584985083654042, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:12:10.857098+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6131,1773126730.857098102,'{"timestamp": "2026-03-10T08:12:10.857098+0100", "flow_id": 584983307649472, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:12:10.857098+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6132,1773126755.952533006,'{"timestamp": "2026-03-10T08:12:35.952533+0100", "flow_id": 994875114630881, "event_type": "alert", "src_ip": "65.49.1.162", "src_port": 36063, "dest_ip": "134.19.61.215", "dest_port": 30005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:12:35.952533+0100", "src_ip": "65.49.1.162", "dest_ip": "134.19.61.215", "src_port": 36063, "dest_port": 30005}}'); INSERT INTO alerts VALUES(6133,1773126762.161845923,'{"timestamp": "2026-03-10T08:12:42.161846+0100", "flow_id": 695125224992666, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:12:42.161846+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6134,1773126762.162220002,'{"timestamp": "2026-03-10T08:12:42.162220+0100", "flow_id": 696729766756800, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:12:42.162220+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6135,1773126769.910167932,'{"timestamp": "2026-03-10T08:12:49.910168+0100", "flow_id": 531446058888869, "event_type": "alert", "src_ip": "198.235.24.223", "src_port": 55971, "dest_ip": "134.19.61.215", "dest_port": 20257, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:12:49.910168+0100", "src_ip": "198.235.24.223", "dest_ip": "134.19.61.215", "src_port": 55971, "dest_port": 20257}}'); INSERT INTO alerts VALUES(6136,1773126792.406887055,'{"timestamp": "2026-03-10T08:13:12.406887+0100", "flow_id": 58718445907866, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:13:12.406887+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6137,1773126792.406888008,'{"timestamp": "2026-03-10T08:13:12.406888+0100", "flow_id": 58720964870592, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:13:12.406888+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6138,1773126822.214678049,'{"timestamp": "2026-03-10T08:13:42.214678+0100", "flow_id": 1960631540454226, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35488, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:13:42.194351+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 35488, "dest_port": 853}}'); INSERT INTO alerts VALUES(6139,1773126823.565665961,'{"timestamp": "2026-03-10T08:13:43.565666+0100", "flow_id": 2148043941752730, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:13:43.565666+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6140,1773126823.565665961,'{"timestamp": "2026-03-10T08:13:43.565666+0100", "flow_id": 2148042165748160, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:13:43.565666+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6141,1773126823.85232997,'{"timestamp": "2026-03-10T08:13:43.852330+0100", "flow_id": 1971881831130796, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59400, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53426, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:13:43.852330+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59400, "dest_port": 53}}'); INSERT INTO alerts VALUES(6142,1773126823.853252887,'{"timestamp": "2026-03-10T08:13:43.853253+0100", "flow_id": 1975844049368729, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60775, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57496, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:13:43.853253+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60775, "dest_port": 53}}'); INSERT INTO alerts VALUES(6143,1773126825.21677494,'{"timestamp": "2026-03-10T08:13:45.216775+0100", "flow_id": 560391346723376, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 46546, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:13:45.196012+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 46546, "dest_port": 853}}'); INSERT INTO alerts VALUES(6144,1773126831.650773048,'{"timestamp": "2026-03-10T08:13:51.650773+0100", "flow_id": 2232100413469627, "event_type": "alert", "src_ip": "64.62.156.80", "src_port": 19886, "dest_ip": "134.19.61.215", "dest_port": 10074, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 34, "bytes_toclient": 0, "start": "2026-03-10T08:13:51.650773+0100", "src_ip": "64.62.156.80", "dest_ip": "134.19.61.215", "src_port": 19886, "dest_port": 10074}}'); INSERT INTO alerts VALUES(6145,1773126839.994781017,'{"timestamp": "2026-03-10T08:13:59.994781+0100", "flow_id": 2020753623763378, "event_type": "alert", "src_ip": "205.210.31.236", "src_port": 51303, "dest_ip": "134.19.61.215", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:13:59.994781+0100", "src_ip": "205.210.31.236", "dest_ip": "134.19.61.215", "src_port": 51303, "dest_port": 8088}}'); INSERT INTO alerts VALUES(6146,1773126854.439680099,'{"timestamp": "2026-03-10T08:14:14.439680+0100", "flow_id": 1888413168709530, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:14:14.439680+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6147,1773126854.439681053,'{"timestamp": "2026-03-10T08:14:14.439681+0100", "flow_id": 1888415687672256, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:14:14.439681+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6148,1773126900.633613109,'{"timestamp": "2026-03-10T08:15:00.633613+0100", "flow_id": 1313975914581017, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52172, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53934, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:15:00.633613+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52172, "dest_port": 53}}'); INSERT INTO alerts VALUES(6149,1773126900.635392905,'{"timestamp": "2026-03-10T08:15:00.635393+0100", "flow_id": 1321620940653467, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52603, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21173, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:15:00.635393+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52603, "dest_port": 53}}'); INSERT INTO alerts VALUES(6150,1773126914.509084939,'{"timestamp": "2026-03-10T08:15:14.509085+0100", "flow_id": 779130321883115, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60577, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24989, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:15:14.509085+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60577, "dest_port": 53}}'); INSERT INTO alerts VALUES(6151,1773126914.509084939,'{"timestamp": "2026-03-10T08:15:14.509085+0100", "flow_id": 779131771152299, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64784, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40439, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:15:14.509085+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64784, "dest_port": 53}}'); INSERT INTO alerts VALUES(6152,1773126914.509519101,'{"timestamp": "2026-03-10T08:15:14.509519+0100", "flow_id": 780992900260856, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52629, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11672, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:15:14.509519+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52629, "dest_port": 53}}'); INSERT INTO alerts VALUES(6153,1773126914.509520054,'{"timestamp": "2026-03-10T08:15:14.509520+0100", "flow_id": 780997627037023, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59683, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35291, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:15:14.509520+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59683, "dest_port": 53}}'); INSERT INTO alerts VALUES(6154,1773126963.829093933,'{"timestamp": "2026-03-10T08:16:03.829094+0100", "flow_id": 1027658772918170, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:16:03.829094+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6155,1773126963.829093933,'{"timestamp": "2026-03-10T08:16:03.829094+0100", "flow_id": 1027656996913600, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:16:03.829094+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6156,1773126976.441302061,'{"timestamp": "2026-03-10T08:16:16.441302+0100", "flow_id": 206528045399687, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57972, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6133, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:16:16.441302+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57972, "dest_port": 53}}'); INSERT INTO alerts VALUES(6157,1773126976.441303015,'{"timestamp": "2026-03-10T08:16:16.441303+0100", "flow_id": 206535745152468, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59504, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39333, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:16:16.441303+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59504, "dest_port": 53}}'); INSERT INTO alerts VALUES(6158,1773126983.83997798,'{"timestamp": "2026-03-10T08:16:23.839978+0100", "flow_id": 2200303260097666, "event_type": "alert", "src_ip": "176.65.139.38", "src_port": 50000, "dest_ip": "134.19.61.215", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:16:23.839978+0100", "src_ip": "176.65.139.38", "dest_ip": "134.19.61.215", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(6159,1773126994.736186981,'{"timestamp": "2026-03-10T08:16:34.736187+0100", "flow_id": 628626246348698, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:16:34.736187+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6160,1773126994.736186981,'{"timestamp": "2026-03-10T08:16:34.736187+0100", "flow_id": 628624470344128, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:16:34.736187+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6161,1773126995.710639953,'{"timestamp": "2026-03-10T08:16:35.710640+0100", "flow_id": 989974434929887, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 50844, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:16:35.689248+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 50844, "dest_port": 853}}'); INSERT INTO alerts VALUES(6162,1773126998.711841106,'{"timestamp": "2026-03-10T08:16:38.711841+0100", "flow_id": 1844867855271594, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 49364, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:16:38.691685+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 49364, "dest_port": 853}}'); INSERT INTO alerts VALUES(6163,1773127001.835019111,'{"timestamp": "2026-03-10T08:16:41.835019+0100", "flow_id": 396074593669995, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 42860, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:16:41.813114+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 42860, "dest_port": 853}}'); INSERT INTO alerts VALUES(6164,1773127002.025378942,'{"timestamp": "2026-03-10T08:16:42.025379+0100", "flow_id": 581456716806752, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 49378, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:16:42.004308+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 49378, "dest_port": 853}}'); INSERT INTO alerts VALUES(6165,1773127003.768287898,'{"timestamp": "2026-03-10T08:16:43.768288+0100", "flow_id": 1047972915331676, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50635, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47657, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:16:43.768288+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50635, "dest_port": 53}}'); INSERT INTO alerts VALUES(6166,1773127003.768287898,'{"timestamp": "2026-03-10T08:16:43.768288+0100", "flow_id": 1047976260672519, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54794, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61334, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:16:43.768288+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54794, "dest_port": 53}}'); INSERT INTO alerts VALUES(6167,1773127004.841501952,'{"timestamp": "2026-03-10T08:16:44.841502+0100", "flow_id": 1273379703032308, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 49394, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:16:44.820769+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 49394, "dest_port": 853}}'); INSERT INTO alerts VALUES(6168,1773127019.216398954,'{"timestamp": "2026-03-10T08:16:59.216399+0100", "flow_id": 929429856708523, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64784, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40439, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:16:59.216399+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64784, "dest_port": 53}}'); INSERT INTO alerts VALUES(6169,1773127019.216399908,'{"timestamp": "2026-03-10T08:16:59.216400+0100", "flow_id": 929431424344807, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56842, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33017, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:16:59.216400+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56842, "dest_port": 53}}'); INSERT INTO alerts VALUES(6170,1773127019.216399908,'{"timestamp": "2026-03-10T08:16:59.216400+0100", "flow_id": 929431222122888, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 60783, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8500, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:16:59.216400+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 60783, "dest_port": 53}}'); INSERT INTO alerts VALUES(6171,1773127019.216399908,'{"timestamp": "2026-03-10T08:16:59.216400+0100", "flow_id": 929432056622433, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58360, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62057, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:16:59.216400+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58360, "dest_port": 53}}'); INSERT INTO alerts VALUES(6172,1773127025.05151391,'{"timestamp": "2026-03-10T08:17:05.051514+0100", "flow_id": 502727870001050, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:17:05.051514+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6173,1773127025.05151391,'{"timestamp": "2026-03-10T08:17:05.051514+0100", "flow_id": 502726093996480, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:17:05.051514+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6174,1773127056.364346981,'{"timestamp": "2026-03-10T08:17:36.364347+0100", "flow_id": 157485513846682, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:17:36.364347+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6175,1773127056.364346981,'{"timestamp": "2026-03-10T08:17:36.364347+0100", "flow_id": 157483737842112, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:17:36.364347+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6176,1773127059.187484979,'{"timestamp": "2026-03-10T08:17:39.187485+0100", "flow_id": 1086717769670890, "event_type": "alert", "src_ip": "45.142.154.98", "src_port": 58914, "dest_ip": "134.19.61.215", "dest_port": 7170, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:17:39.187485+0100", "src_ip": "45.142.154.98", "dest_ip": "134.19.61.215", "src_port": 58914, "dest_port": 7170}}'); INSERT INTO alerts VALUES(6177,1773127059.187484979,'{"timestamp": "2026-03-10T08:17:39.187485+0100", "flow_id": 1086717769670890, "event_type": "alert", "src_ip": "45.142.154.98", "src_port": 58914, "dest_ip": "134.19.61.215", "dest_port": 7170, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:17:39.187485+0100", "src_ip": "45.142.154.98", "dest_ip": "134.19.61.215", "src_port": 58914, "dest_port": 7170}}'); INSERT INTO alerts VALUES(6178,1773127087.031677007,'{"timestamp": "2026-03-10T08:18:07.031677+0100", "flow_id": 2106378464014234, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56216, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:18:07.031677+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6179,1773127087.031677961,'{"timestamp": "2026-03-10T08:18:07.031678+0100", "flow_id": 2106380982976960, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51048, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5392, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:18:07.031678+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51048, "dest_port": 53}}'); INSERT INTO alerts VALUES(6180,1773127097.098175048,'{"timestamp": "2026-03-10T08:18:17.098175+0100", "flow_id": 421661745568398, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 61361, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45240, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:18:17.098175+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 61361, "dest_port": 53}}'); INSERT INTO alerts VALUES(6181,1773127106.871541977,'{"timestamp": "2026-03-10T08:18:26.871542+0100", "flow_id": 647022929361435, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55033, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53629, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T08:18:26.871542+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55033, "dest_port": 53}}'); INSERT INTO alerts VALUES(6182,1773127106.871541977,'{"timestamp": "2026-03-10T08:18:26.871542+0100", "flow_id": 647019927062926, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63421, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51352, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T08:18:26.871542+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63421, "dest_port": 53}}'); INSERT INTO alerts VALUES(6183,1773127108.363579988,'{"timestamp": "2026-03-10T08:18:28.363580+0100", "flow_id": 1280090098699602, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54241, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30237, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:18:28.363580+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54241, "dest_port": 53}}'); INSERT INTO alerts VALUES(6184,1773127137.012160062,'{"timestamp": "2026-03-10T08:18:57.012160+0100", "flow_id": 333703781457454, "event_type": "alert", "src_ip": "193.163.125.129", "src_port": 54677, "dest_ip": "134.19.61.215", "dest_port": 2107, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:18:57.012160+0100", "src_ip": "193.163.125.129", "dest_ip": "134.19.61.215", "src_port": 54677, "dest_port": 2107}}'); INSERT INTO alerts VALUES(6185,1773127141.992456913,'{"timestamp": "2026-03-10T08:19:01.992457+0100", "flow_id": 1447822968181078, "event_type": "alert", "src_ip": "130.12.180.175", "src_port": 45092, "dest_ip": "134.19.61.215", "dest_port": 712, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:19:01.992457+0100", "src_ip": "130.12.180.175", "dest_ip": "134.19.61.215", "src_port": 45092, "dest_port": 712}}'); INSERT INTO alerts VALUES(6186,1773127141.992456913,'{"timestamp": "2026-03-10T08:19:01.992457+0100", "flow_id": 1447822968181078, "event_type": "alert", "src_ip": "130.12.180.175", "src_port": 45092, "dest_ip": "134.19.61.215", "dest_port": 712, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:19:01.992457+0100", "src_ip": "130.12.180.175", "dest_ip": "134.19.61.215", "src_port": 45092, "dest_port": 712}}'); INSERT INTO alerts VALUES(6187,1773127157.600511074,'{"timestamp": "2026-03-10T08:19:17.600511+0100", "flow_id": 1453277567998145, "event_type": "alert", "src_ip": "65.49.1.167", "src_port": 37152, "dest_ip": "134.19.61.215", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:19:17.600511+0100", "src_ip": "65.49.1.167", "dest_ip": "134.19.61.215", "src_port": 37152, "dest_port": 8080}}'); INSERT INTO alerts VALUES(6188,1773127169.541424037,'{"timestamp": "2026-03-10T08:19:29.541424+0100", "flow_id": 355076822383131, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55033, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53629, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T08:19:29.541424+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55033, "dest_port": 53}}'); INSERT INTO alerts VALUES(6189,1773127169.541424037,'{"timestamp": "2026-03-10T08:19:29.541424+0100", "flow_id": 355073820084622, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63421, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51352, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T08:19:29.541424+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63421, "dest_port": 53}}'); INSERT INTO alerts VALUES(6190,1773127171.792081118,'{"timestamp": "2026-03-10T08:19:31.792081+0100", "flow_id": 868688536111542, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64895, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51294, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:19:31.792081+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64895, "dest_port": 53}}'); INSERT INTO alerts VALUES(6191,1773127185.629160882,'{"timestamp": "2026-03-10T08:19:45.629161+0100", "flow_id": 450426631845630, "event_type": "alert", "src_ip": "205.210.31.183", "src_port": 52972, "dest_ip": "134.19.61.215", "dest_port": 9443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:19:45.629161+0100", "src_ip": "205.210.31.183", "dest_ip": "134.19.61.215", "src_port": 52972, "dest_port": 9443}}'); INSERT INTO alerts VALUES(6192,1773127200.887638092,'{"timestamp": "2026-03-10T08:20:00.887638+0100", "flow_id": 153204769536539, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55033, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53629, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T08:20:00.887638+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55033, "dest_port": 53}}'); INSERT INTO alerts VALUES(6193,1773127200.887638092,'{"timestamp": "2026-03-10T08:20:00.887638+0100", "flow_id": 153201767238030, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63421, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51352, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T08:20:00.887638+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63421, "dest_port": 53}}'); INSERT INTO alerts VALUES(6194,1773127210.434072972,'{"timestamp": "2026-03-10T08:20:10.434073+0100", "flow_id": 738433323467883, "event_type": "alert", "src_ip": "77.90.185.79", "src_port": 58371, "dest_ip": "134.19.61.215", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:20:10.434073+0100", "src_ip": "77.90.185.79", "dest_ip": "134.19.61.215", "src_port": 58371, "dest_port": 8545}}'); INSERT INTO alerts VALUES(6195,1773127217.750982999,'{"timestamp": "2026-03-10T08:20:17.750983+0100", "flow_id": 410700128350643, "event_type": "alert", "src_ip": "147.185.132.21", "src_port": 55705, "dest_ip": "134.19.61.215", "dest_port": 12345, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:20:17.750983+0100", "src_ip": "147.185.132.21", "dest_ip": "134.19.61.215", "src_port": 55705, "dest_port": 12345}}'); INSERT INTO alerts VALUES(6196,1773127229.538906098,'{"timestamp": "2026-03-10T08:20:29.538906+0100", "flow_id": 1470159506932757, "event_type": "alert", "src_ip": "185.242.226.97", "src_port": 43334, "dest_ip": "134.19.61.215", "dest_port": 41036, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 29, "bytes_toclient": 0, "start": "2026-03-10T08:20:29.538906+0100", "src_ip": "185.242.226.97", "dest_ip": "134.19.61.215", "src_port": 43334, "dest_port": 41036}}'); INSERT INTO alerts VALUES(6197,1773127231.371146918,'{"timestamp": "2026-03-10T08:20:31.371147+0100", "flow_id": 2157017466518043, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55033, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53629, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T08:20:31.371147+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55033, "dest_port": 53}}'); INSERT INTO alerts VALUES(6198,1773127231.371915102,'{"timestamp": "2026-03-10T08:20:31.371915+0100", "flow_id": 2160312999102862, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63421, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51352, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmfmobile.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 73, "bytes_toclient": 0, "start": "2026-03-10T08:20:31.371915+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63421, "dest_port": 53}}'); INSERT INTO alerts VALUES(6199,1773127251.244178057,'{"timestamp": "2026-03-10T08:20:51.244178+0100", "flow_id": 1048739698112816, "event_type": "alert", "src_ip": "147.185.132.84", "src_port": 11225, "dest_ip": "134.19.61.215", "dest_port": 5351, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 88, "bytes_toclient": 0, "start": "2026-03-10T08:20:51.244178+0100", "src_ip": "147.185.132.84", "dest_ip": "134.19.61.215", "src_port": 11225, "dest_port": 5351}}'); INSERT INTO alerts VALUES(6200,1773127264.041003943,'{"timestamp": "2026-03-10T08:21:04.041004+0100", "flow_id": 176115003861090, "event_type": "alert", "src_ip": "193.163.125.137", "src_port": 45436, "dest_ip": "134.19.61.215", "dest_port": 9009, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:21:04.041004+0100", "src_ip": "193.163.125.137", "dest_ip": "134.19.61.215", "src_port": 45436, "dest_port": 9009}}'); INSERT INTO alerts VALUES(6201,1773127264.753269911,'{"timestamp": "2026-03-10T08:21:04.753270+0100", "flow_id": 139045393153217, "event_type": "alert", "src_ip": "147.185.132.139", "src_port": 56879, "dest_ip": "134.19.61.215", "dest_port": 65094, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:21:04.753270+0100", "src_ip": "147.185.132.139", "dest_ip": "134.19.61.215", "src_port": 56879, "dest_port": 65094}}'); INSERT INTO alerts VALUES(6202,1773127276.942810059,'{"timestamp": "2026-03-10T08:21:16.942810+0100", "flow_id": 1234589029393725, "event_type": "alert", "src_ip": "202.57.30.210", "src_port": 52566, "dest_ip": "134.19.61.215", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:21:16.942810+0100", "src_ip": "202.57.30.210", "dest_ip": "134.19.61.215", "src_port": 52566, "dest_port": 1433}}'); INSERT INTO alerts VALUES(6203,1773127306.15003109,'{"timestamp": "2026-03-10T08:21:46.150031+0100", "flow_id": 644379862736376, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58981, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13231, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:21:46.150031+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58981, "dest_port": 53}}'); INSERT INTO alerts VALUES(6204,1773127306.150032044,'{"timestamp": "2026-03-10T08:21:46.150032+0100", "flow_id": 644385380326420, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49580, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39533, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:21:46.150032+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49580, "dest_port": 53}}'); INSERT INTO alerts VALUES(6205,1773127318.603513003,'{"timestamp": "2026-03-10T08:21:58.603513+0100", "flow_id": 1747647228968579, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58990, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23889, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:21:58.603513+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58990, "dest_port": 53}}'); INSERT INTO alerts VALUES(6206,1773127318.604038953,'{"timestamp": "2026-03-10T08:21:58.604039+0100", "flow_id": 1749904039836746, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62673, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4403, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:21:58.604039+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62673, "dest_port": 53}}'); INSERT INTO alerts VALUES(6207,1773127331.581267119,'{"timestamp": "2026-03-10T08:22:11.581267+0100", "flow_id": 1089151778818453, "event_type": "alert", "src_ip": "198.235.24.107", "src_port": 49466, "dest_ip": "134.19.61.215", "dest_port": 5443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:22:11.581267+0100", "src_ip": "198.235.24.107", "dest_ip": "134.19.61.215", "src_port": 49466, "dest_port": 5443}}'); INSERT INTO alerts VALUES(6208,1773127387.068202018,'{"timestamp": "2026-03-10T08:23:07.068202+0100", "flow_id": 855875756834873, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63730, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30460, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:23:07.068202+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63730, "dest_port": 53}}'); INSERT INTO alerts VALUES(6209,1773127387.068202973,'{"timestamp": "2026-03-10T08:23:07.068203+0100", "flow_id": 855883756438835, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57175, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45879, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:23:07.068203+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57175, "dest_port": 53}}'); INSERT INTO alerts VALUES(6210,1773127387.625871896,'{"timestamp": "2026-03-10T08:23:07.625872+0100", "flow_id": 999253629127626, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63794, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62478, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T08:23:07.625872+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63794, "dest_port": 53}}'); INSERT INTO alerts VALUES(6211,1773127390.607095957,'{"timestamp": "2026-03-10T08:23:10.607096+0100", "flow_id": 1763035860419723, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51480, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23889, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:23:10.607096+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51480, "dest_port": 53}}'); INSERT INTO alerts VALUES(6212,1773127390.607095957,'{"timestamp": "2026-03-10T08:23:10.607096+0100", "flow_id": 1763033199243114, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64219, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4403, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:23:10.607096+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64219, "dest_port": 53}}'); INSERT INTO alerts VALUES(6213,1773127398.369584084,'{"timestamp": "2026-03-10T08:23:18.369584+0100", "flow_id": 1868830146257865, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60850, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32208, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:23:18.369584+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60850, "dest_port": 53}}'); INSERT INTO alerts VALUES(6214,1773127398.37067008,'{"timestamp": "2026-03-10T08:23:18.370670+0100", "flow_id": 1873491912824284, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51480, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37027, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:23:18.370670+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51480, "dest_port": 53}}'); INSERT INTO alerts VALUES(6215,1773127415.678680896,'{"timestamp": "2026-03-10T08:23:35.678681+0100", "flow_id": 2070489236997400, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56655, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49202, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:23:35.678681+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56655, "dest_port": 53}}'); INSERT INTO alerts VALUES(6216,1773127415.678682089,'{"timestamp": "2026-03-10T08:23:35.678682+0100", "flow_id": 2070495589302330, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53944, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48645, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:23:35.678682+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53944, "dest_port": 53}}'); INSERT INTO alerts VALUES(6217,1773127435.906164885,'{"timestamp": "2026-03-10T08:23:55.906165+0100", "flow_id": 1077199529196664, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57679, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51936, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:23:55.906165+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57679, "dest_port": 53}}'); INSERT INTO alerts VALUES(6218,1773127435.906164885,'{"timestamp": "2026-03-10T08:23:55.906165+0100", "flow_id": 1077200523600856, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50672, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51198, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:23:55.906165+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50672, "dest_port": 53}}'); INSERT INTO alerts VALUES(6219,1773127438.244290113,'{"timestamp": "2026-03-10T08:23:58.244290+0100", "flow_id": 1893642992362215, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56842, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33017, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:23:58.244290+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56842, "dest_port": 53}}'); INSERT INTO alerts VALUES(6220,1773127438.244291068,'{"timestamp": "2026-03-10T08:23:58.244291+0100", "flow_id": 1893649677701791, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57583, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:23:58.244291+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57583, "dest_port": 53}}'); INSERT INTO alerts VALUES(6221,1773127438.244291068,'{"timestamp": "2026-03-10T08:23:58.244291+0100", "flow_id": 1893649324118616, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62396, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5378, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:23:58.244291+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62396, "dest_port": 53}}'); INSERT INTO alerts VALUES(6222,1773127438.244291068,'{"timestamp": "2026-03-10T08:23:58.244291+0100", "flow_id": 1893647780038876, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57617, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31249, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:23:58.244291+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57617, "dest_port": 53}}'); INSERT INTO alerts VALUES(6223,1773127438.640593052,'{"timestamp": "2026-03-10T08:23:58.640593+0100", "flow_id": 1906903464616820, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61777, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50062, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:23:58.640593+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61777, "dest_port": 53}}'); INSERT INTO alerts VALUES(6224,1773127438.641233921,'{"timestamp": "2026-03-10T08:23:58.641234+0100", "flow_id": 1909657831619893, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59730, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11135, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:23:58.641234+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59730, "dest_port": 53}}'); INSERT INTO alerts VALUES(6225,1773127448.326440096,'{"timestamp": "2026-03-10T08:24:08.326440+0100", "flow_id": 276149679320132, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53873, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43432, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:24:08.326440+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53873, "dest_port": 53}}'); INSERT INTO alerts VALUES(6226,1773127449.043035031,'{"timestamp": "2026-03-10T08:24:09.043035+0100", "flow_id": 466309815356095, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52212, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24355, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:24:09.043035+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52212, "dest_port": 53}}'); INSERT INTO alerts VALUES(6227,1773127461.188756943,'{"timestamp": "2026-03-10T08:24:21.188757+0100", "flow_id": 1655132624542894, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:24:21.188757+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57886, "dest_port": 53}}'); INSERT INTO alerts VALUES(6228,1773127461.188756943,'{"timestamp": "2026-03-10T08:24:21.188757+0100", "flow_id": 1655134201462342, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:24:21.188757+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54367, "dest_port": 53}}'); INSERT INTO alerts VALUES(6229,1773127465.145833015,'{"timestamp": "2026-03-10T08:24:25.145833+0100", "flow_id": 344874247688784, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59956, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7259, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:24:25.145833+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59956, "dest_port": 53}}'); INSERT INTO alerts VALUES(6230,1773127465.14583397,'{"timestamp": "2026-03-10T08:24:25.145834+0100", "flow_id": 344879639854197, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58966, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3092, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:24:25.145834+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58966, "dest_port": 53}}'); INSERT INTO alerts VALUES(6231,1773127475.719957113,'{"timestamp": "2026-03-10T08:24:35.719957+0100", "flow_id": 1121870133568465, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52686, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62776, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:24:35.719957+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52686, "dest_port": 53}}'); INSERT INTO alerts VALUES(6232,1773127482.656655074,'{"timestamp": "2026-03-10T08:24:42.656655+0100", "flow_id": 568515502863207, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64628, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18215, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:24:42.656655+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64628, "dest_port": 53}}'); INSERT INTO alerts VALUES(6233,1773127487.246239901,'{"timestamp": "2026-03-10T08:24:47.246240+0100", "flow_id": 2183493310304024, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53448, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64662, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:24:47.246240+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53448, "dest_port": 53}}'); INSERT INTO alerts VALUES(6234,1773127487.246239901,'{"timestamp": "2026-03-10T08:24:47.246240+0100", "flow_id": 2183495279563563, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57989, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27432, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:24:47.246240+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57989, "dest_port": 53}}'); INSERT INTO alerts VALUES(6235,1773127494.371908903,'{"timestamp": "2026-03-10T08:24:54.371909+0100", "flow_id": 1878813896860941, "event_type": "alert", "src_ip": "205.210.31.110", "src_port": 51057, "dest_ip": "134.19.61.215", "dest_port": 10011, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:24:54.371909+0100", "src_ip": "205.210.31.110", "dest_ip": "134.19.61.215", "src_port": 51057, "dest_port": 10011}}'); INSERT INTO alerts VALUES(6236,1773127495.253503084,'{"timestamp": "2026-03-10T08:24:55.253503+0100", "flow_id": 2214687950332770, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53096, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3787, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:24:55.253503+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53096, "dest_port": 53}}'); INSERT INTO alerts VALUES(6237,1773127505.442385912,'{"timestamp": "2026-03-10T08:25:05.442386+0100", "flow_id": 492662682074921, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55698, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3714, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:25:05.442386+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55698, "dest_port": 53}}'); INSERT INTO alerts VALUES(6238,1773127505.442387105,'{"timestamp": "2026-03-10T08:25:05.442387+0100", "flow_id": 492664523716233, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62101, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30348, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:25:05.442387+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62101, "dest_port": 53}}'); INSERT INTO alerts VALUES(6239,1773127507.141666889,'{"timestamp": "2026-03-10T08:25:07.141667+0100", "flow_id": 889930536965487, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53561, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15036, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:25:07.141667+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53561, "dest_port": 53}}'); INSERT INTO alerts VALUES(6240,1773127509.167428017,'{"timestamp": "2026-03-10T08:25:09.167428+0100", "flow_id": 1563522949444181, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58747, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8801, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T08:25:09.167428+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58747, "dest_port": 53}}'); INSERT INTO alerts VALUES(6241,1773127509.172360898,'{"timestamp": "2026-03-10T08:25:09.172361+0100", "flow_id": 1584710421018084, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63901, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47081, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T08:25:09.172361+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63901, "dest_port": 53}}'); INSERT INTO alerts VALUES(6242,1773127518.183619023,'{"timestamp": "2026-03-10T08:25:18.183619+0100", "flow_id": 1914537629423801, "event_type": "alert", "src_ip": "45.142.154.86", "src_port": 58914, "dest_ip": "134.19.61.215", "dest_port": 56999, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400005, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 6", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:25:18.183619+0100", "src_ip": "45.142.154.86", "dest_ip": "134.19.61.215", "src_port": 58914, "dest_port": 56999}}'); INSERT INTO alerts VALUES(6243,1773127518.183619023,'{"timestamp": "2026-03-10T08:25:18.183619+0100", "flow_id": 1914537629423801, "event_type": "alert", "src_ip": "45.142.154.86", "src_port": 58914, "dest_ip": "134.19.61.215", "dest_port": 56999, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:25:18.183619+0100", "src_ip": "45.142.154.86", "dest_ip": "134.19.61.215", "src_port": 58914, "dest_port": 56999}}'); INSERT INTO alerts VALUES(6244,1773127519.087917089,'{"timestamp": "2026-03-10T08:25:19.087917+0100", "flow_id": 2066451661129117, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57270, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45137, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:25:19.087917+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57270, "dest_port": 53}}'); INSERT INTO alerts VALUES(6245,1773127530.647027969,'{"timestamp": "2026-03-10T08:25:30.647028+0100", "flow_id": 808639517690680, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53825, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30232, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:25:30.647028+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53825, "dest_port": 53}}'); INSERT INTO alerts VALUES(6246,1773127538.282521963,'{"timestamp": "2026-03-10T08:25:38.282522+0100", "flow_id": 650475349499054, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:25:38.282522+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57886, "dest_port": 53}}'); INSERT INTO alerts VALUES(6247,1773127538.282521963,'{"timestamp": "2026-03-10T08:25:38.282522+0100", "flow_id": 650476926418502, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:25:38.282522+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54367, "dest_port": 53}}'); INSERT INTO alerts VALUES(6248,1773127542.264770985,'{"timestamp": "2026-03-10T08:25:42.264771+0100", "flow_id": 1700135109073895, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64818, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6717, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:25:42.264771+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64818, "dest_port": 53}}'); INSERT INTO alerts VALUES(6249,1773127548.384258986,'{"timestamp": "2026-03-10T08:25:48.384259+0100", "flow_id": 1368907900980135, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 42292, "dest_ip": "134.19.61.215", "dest_port": 2222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:25:48.384259+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.61.215", "src_port": 42292, "dest_port": 2222}}'); INSERT INTO alerts VALUES(6250,1773127548.384258986,'{"timestamp": "2026-03-10T08:25:48.384259+0100", "flow_id": 1368907900980135, "event_type": "alert", "src_ip": "185.242.246.37", "src_port": 42292, "dest_ip": "134.19.61.215", "dest_port": 2222, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:25:48.384259+0100", "src_ip": "185.242.246.37", "dest_ip": "134.19.61.215", "src_port": 42292, "dest_port": 2222}}'); INSERT INTO alerts VALUES(6251,1773127554.34788394,'{"timestamp": "2026-03-10T08:25:54.347884+0100", "flow_id": 649727901867649, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51624, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11678, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:25:54.347884+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51624, "dest_port": 53}}'); INSERT INTO alerts VALUES(6252,1773127564.439460993,'{"timestamp": "2026-03-10T08:26:04.439461+0100", "flow_id": 1324524697836320, "event_type": "alert", "src_ip": "205.210.31.96", "src_port": 51642, "dest_ip": "134.19.61.215", "dest_port": 9051, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:26:04.439461+0100", "src_ip": "205.210.31.96", "dest_ip": "134.19.61.215", "src_port": 51642, "dest_port": 9051}}'); INSERT INTO alerts VALUES(6253,1773127565.943870067,'{"timestamp": "2026-03-10T08:26:05.943870+0100", "flow_id": 1520617804112712, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55692, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17972, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:26:05.943870+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55692, "dest_port": 53}}'); INSERT INTO alerts VALUES(6254,1773127568.391659976,'{"timestamp": "2026-03-10T08:26:08.391660+0100", "flow_id": 274794560117934, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:26:08.391660+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57886, "dest_port": 53}}'); INSERT INTO alerts VALUES(6255,1773127568.391659976,'{"timestamp": "2026-03-10T08:26:08.391660+0100", "flow_id": 274796137037382, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:26:08.391660+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54367, "dest_port": 53}}'); INSERT INTO alerts VALUES(6256,1773127577.695583106,'{"timestamp": "2026-03-10T08:26:17.695583+0100", "flow_id": 454233417865046, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52358, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7767, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:26:17.695583+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52358, "dest_port": 53}}'); INSERT INTO alerts VALUES(6257,1773127589.245856046,'{"timestamp": "2026-03-10T08:26:29.245856+0100", "flow_id": 1618896446472729, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57196, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46730, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:26:29.245856+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57196, "dest_port": 53}}'); INSERT INTO alerts VALUES(6258,1773127599.386661053,'{"timestamp": "2026-03-10T08:26:39.386661+0100", "flow_id": 2223648855579822, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:26:39.386661+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57886, "dest_port": 53}}'); INSERT INTO alerts VALUES(6259,1773127599.386662006,'{"timestamp": "2026-03-10T08:26:39.386662+0100", "flow_id": 2223654727466566, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:26:39.386662+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54367, "dest_port": 53}}'); INSERT INTO alerts VALUES(6260,1773127600.721573115,'{"timestamp": "2026-03-10T08:26:40.721573+0100", "flow_id": 2911977159733, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56555, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54369, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:26:40.721573+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56555, "dest_port": 53}}'); INSERT INTO alerts VALUES(6261,1773127603.407418966,'{"timestamp": "2026-03-10T08:26:43.407419+0100", "flow_id": 905426656023405, "event_type": "alert", "src_ip": "185.241.208.163", "src_port": 50251, "dest_ip": "134.19.61.215", "dest_port": 33900, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:26:43.407419+0100", "src_ip": "185.241.208.163", "dest_ip": "134.19.61.215", "src_port": 50251, "dest_port": 33900}}'); INSERT INTO alerts VALUES(6262,1773127612.391760111,'{"timestamp": "2026-03-10T08:26:52.391760+0100", "flow_id": 1401123335136787, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55977, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13133, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:26:52.391760+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55977, "dest_port": 53}}'); INSERT INTO alerts VALUES(6263,1773127623.888173103,'{"timestamp": "2026-03-10T08:27:03.888173+0100", "flow_id": 2125827496328498, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52932, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3963, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:27:03.888173+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52932, "dest_port": 53}}'); INSERT INTO alerts VALUES(6264,1773127629.699389935,'{"timestamp": "2026-03-10T08:27:09.699390+0100", "flow_id": 1596484846116014, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:27:09.699390+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57886, "dest_port": 53}}'); INSERT INTO alerts VALUES(6265,1773127629.699390889,'{"timestamp": "2026-03-10T08:27:09.699391+0100", "flow_id": 1596490718002758, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:27:09.699391+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54367, "dest_port": 53}}'); INSERT INTO alerts VALUES(6266,1773127635.64644599,'{"timestamp": "2026-03-10T08:27:15.646446+0100", "flow_id": 1087615541860205, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56263, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28637, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:27:15.646446+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56263, "dest_port": 53}}'); INSERT INTO alerts VALUES(6267,1773127647.390990972,'{"timestamp": "2026-03-10T08:27:27.390991+0100", "flow_id": 2242246593793915, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53447, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33324, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:27:27.390991+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53447, "dest_port": 53}}'); INSERT INTO alerts VALUES(6268,1773127659.147413015,'{"timestamp": "2026-03-10T08:27:39.147413+0100", "flow_id": 914610740283548, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54544, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11364, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:27:39.147413+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54544, "dest_port": 53}}'); INSERT INTO alerts VALUES(6269,1773127660.019984007,'{"timestamp": "2026-03-10T08:27:40.019984+0100", "flow_id": 1211733085805742, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:27:40.019984+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57886, "dest_port": 53}}'); INSERT INTO alerts VALUES(6270,1773127660.01998496,'{"timestamp": "2026-03-10T08:27:40.019985+0100", "flow_id": 1211738957692486, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:27:40.019985+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54367, "dest_port": 53}}'); INSERT INTO alerts VALUES(6271,1773127670.475733996,'{"timestamp": "2026-03-10T08:27:50.475734+0100", "flow_id": 1761789763267762, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53223, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52821, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:27:50.475734+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53223, "dest_port": 53}}'); INSERT INTO alerts VALUES(6272,1773127682.691023111,'{"timestamp": "2026-03-10T08:28:02.691023+0100", "flow_id": 716122318816846, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54158, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8494, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:28:02.691023+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54158, "dest_port": 53}}'); INSERT INTO alerts VALUES(6273,1773127690.373497962,'{"timestamp": "2026-03-10T08:28:10.373498+0100", "flow_id": 759739966006225, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52686, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62776, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:28:10.373498+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52686, "dest_port": 53}}'); INSERT INTO alerts VALUES(6274,1773127690.373497962,'{"timestamp": "2026-03-10T08:28:10.373498+0100", "flow_id": 759738023711312, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59956, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7259, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:28:10.373498+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59956, "dest_port": 53}}'); INSERT INTO alerts VALUES(6275,1773127690.373497962,'{"timestamp": "2026-03-10T08:28:10.373498+0100", "flow_id": 759739120909429, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 58966, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3092, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:28:10.373498+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 58966, "dest_port": 53}}'); INSERT INTO alerts VALUES(6276,1773127690.373498916,'{"timestamp": "2026-03-10T08:28:10.373499+0100", "flow_id": 759743951819423, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57583, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8341, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:28:10.373499+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57583, "dest_port": 53}}'); INSERT INTO alerts VALUES(6277,1773127690.373498916,'{"timestamp": "2026-03-10T08:28:10.373499+0100", "flow_id": 759742333820732, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51442, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24405, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:28:10.373499+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51442, "dest_port": 53}}'); INSERT INTO alerts VALUES(6278,1773127690.373498916,'{"timestamp": "2026-03-10T08:28:10.373499+0100", "flow_id": 759743067891749, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55525, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:28:10.373499+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6279,1773127690.373498916,'{"timestamp": "2026-03-10T08:28:10.373499+0100", "flow_id": 759741118810815, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64126, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7134, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:28:10.373499+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64126, "dest_port": 53}}'); INSERT INTO alerts VALUES(6280,1773127690.373500109,'{"timestamp": "2026-03-10T08:28:10.373500+0100", "flow_id": 759747064632542, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56523, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63581, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:28:10.373500+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56523, "dest_port": 53}}'); INSERT INTO alerts VALUES(6281,1773127690.414684058,'{"timestamp": "2026-03-10T08:28:10.414684+0100", "flow_id": 655156863851694, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:28:10.414684+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57886, "dest_port": 53}}'); INSERT INTO alerts VALUES(6282,1773127690.414684058,'{"timestamp": "2026-03-10T08:28:10.414684+0100", "flow_id": 655158440771142, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:28:10.414684+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54367, "dest_port": 53}}'); INSERT INTO alerts VALUES(6283,1773127694.346724034,'{"timestamp": "2026-03-10T08:28:14.346724+0100", "flow_id": 1770645644998250, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59845, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51067, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:28:14.346724+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59845, "dest_port": 53}}'); INSERT INTO alerts VALUES(6284,1773127698.126957893,'{"timestamp": "2026-03-10T08:28:18.126958+0100", "flow_id": 826756116120382, "event_type": "alert", "src_ip": "147.185.132.72", "src_port": 56237, "dest_ip": "134.19.61.215", "dest_port": 6363, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:28:18.126958+0100", "src_ip": "147.185.132.72", "dest_ip": "134.19.61.215", "src_port": 56237, "dest_port": 6363}}'); INSERT INTO alerts VALUES(6285,1773127701.650110961,'{"timestamp": "2026-03-10T08:28:21.650111+0100", "flow_id": 1666306843440053, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61104, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3543, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:28:21.650111+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61104, "dest_port": 53}}'); INSERT INTO alerts VALUES(6286,1773127706.099771976,'{"timestamp": "2026-03-10T08:28:26.099772+0100", "flow_id": 709994781254750, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61687, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38314, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:28:26.099772+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61687, "dest_port": 53}}'); INSERT INTO alerts VALUES(6287,1773127717.761779069,'{"timestamp": "2026-03-10T08:28:37.761779+0100", "flow_id": 1582968169986246, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50122, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64170, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:28:37.761779+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50122, "dest_port": 53}}'); INSERT INTO alerts VALUES(6288,1773127720.734523058,'{"timestamp": "2026-03-10T08:28:40.734523+0100", "flow_id": 58530071862446, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:28:40.734523+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57886, "dest_port": 53}}'); INSERT INTO alerts VALUES(6289,1773127720.734524011,'{"timestamp": "2026-03-10T08:28:40.734524+0100", "flow_id": 58535943749190, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:28:40.734524+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54367, "dest_port": 53}}'); INSERT INTO alerts VALUES(6290,1773127721.727580071,'{"timestamp": "2026-03-10T08:28:41.727580+0100", "flow_id": 310183437072129, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 41709, "dest_ip": "134.19.61.215", "dest_port": 8022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:28:41.727580+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.61.215", "src_port": 41709, "dest_port": 8022}}'); INSERT INTO alerts VALUES(6291,1773127721.727580071,'{"timestamp": "2026-03-10T08:28:41.727580+0100", "flow_id": 310183437072129, "event_type": "alert", "src_ip": "185.242.246.36", "src_port": 41709, "dest_ip": "134.19.61.215", "dest_port": 8022, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:28:41.727580+0100", "src_ip": "185.242.246.36", "dest_ip": "134.19.61.215", "src_port": 41709, "dest_port": 8022}}'); INSERT INTO alerts VALUES(6292,1773127729.428011894,'{"timestamp": "2026-03-10T08:28:49.428012+0100", "flow_id": 430923595666901, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57712, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6173, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:28:49.428012+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57712, "dest_port": 53}}'); INSERT INTO alerts VALUES(6293,1773127732.03482294,'{"timestamp": "2026-03-10T08:28:52.034823+0100", "flow_id": 1275466482320791, "event_type": "alert", "src_ip": "145.90.8.9", "src_port": 47576, "dest_ip": "134.19.61.215", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2101411, "rev": 13, "signature": "GPL SNMP public access udp", "category": "Attempted Information Leak", "severity": 2, "metadata": {"created_at": ["2010_09_23"], "cve": ["CVE_1999_0517"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2019_10_08"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:28:52.034823+0100", "src_ip": "145.90.8.9", "dest_ip": "134.19.61.215", "src_port": 47576, "dest_port": 161}}'); INSERT INTO alerts VALUES(6294,1773127740.764895916,'{"timestamp": "2026-03-10T08:29:00.764896+0100", "flow_id": 1314880357665626, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64847, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43975, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:29:00.764896+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64847, "dest_port": 53}}'); INSERT INTO alerts VALUES(6295,1773127747.435926915,'{"timestamp": "2026-03-10T08:29:07.435927+0100", "flow_id": 1027868552175420, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 51442, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24405, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:29:07.435927+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 51442, "dest_port": 53}}'); INSERT INTO alerts VALUES(6296,1773127747.435926915,'{"timestamp": "2026-03-10T08:29:07.435927+0100", "flow_id": 1027869286246437, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55525, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:29:07.435927+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6297,1773127747.435926915,'{"timestamp": "2026-03-10T08:29:07.435927+0100", "flow_id": 1027867337165503, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64126, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7134, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:29:07.435927+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64126, "dest_port": 53}}'); INSERT INTO alerts VALUES(6298,1773127747.435928106,'{"timestamp": "2026-03-10T08:29:07.435928+0100", "flow_id": 1027873282987230, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56523, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63581, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:29:07.435928+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56523, "dest_port": 53}}'); INSERT INTO alerts VALUES(6299,1773127747.435928106,'{"timestamp": "2026-03-10T08:29:07.435928+0100", "flow_id": 1027872999368743, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52043, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53520, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:29:07.435928+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52043, "dest_port": 53}}'); INSERT INTO alerts VALUES(6300,1773127747.436367988,'{"timestamp": "2026-03-10T08:29:07.436368+0100", "flow_id": 1029761788987280, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 49228, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41172, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:29:07.436368+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 49228, "dest_port": 53}}'); INSERT INTO alerts VALUES(6301,1773127747.436368942,'{"timestamp": "2026-03-10T08:29:07.436369+0100", "flow_id": 1029767701474503, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53710, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50724, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:29:07.436369+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53710, "dest_port": 53}}'); INSERT INTO alerts VALUES(6302,1773127751.666984082,'{"timestamp": "2026-03-10T08:29:11.666984+0100", "flow_id": 2020252089343150, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:29:11.666984+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57886, "dest_port": 53}}'); INSERT INTO alerts VALUES(6303,1773127751.667604924,'{"timestamp": "2026-03-10T08:29:11.667605+0100", "flow_id": 2022920840953414, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:29:11.667605+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54367, "dest_port": 53}}'); INSERT INTO alerts VALUES(6304,1773127752.508106947,'{"timestamp": "2026-03-10T08:29:12.508107+0100", "flow_id": 211979422055079, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58560, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17319, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:29:12.508107+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58560, "dest_port": 53}}'); INSERT INTO alerts VALUES(6305,1773127762.742908,'{"timestamp": "2026-03-10T08:29:22.742908+0100", "flow_id": 657492905876998, "event_type": "alert", "src_ip": "92.63.197.181", "src_port": 44083, "dest_ip": "134.19.61.215", "dest_port": 5247, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400014, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 15", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:29:22.742908+0100", "src_ip": "92.63.197.181", "dest_ip": "134.19.61.215", "src_port": 44083, "dest_port": 5247}}'); INSERT INTO alerts VALUES(6306,1773127763.960037946,'{"timestamp": "2026-03-10T08:29:23.960038+0100", "flow_id": 1027109661553629, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52732, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11728, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:29:23.960038+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52732, "dest_port": 53}}'); INSERT INTO alerts VALUES(6307,1773127765.739289046,'{"timestamp": "2026-03-10T08:29:25.739289+0100", "flow_id": 1486376215027333, "event_type": "alert", "src_ip": "204.76.203.233", "src_port": 48741, "dest_ip": "134.19.61.215", "dest_port": 10042, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:29:25.739289+0100", "src_ip": "204.76.203.233", "dest_ip": "134.19.61.215", "src_port": 48741, "dest_port": 10042}}'); INSERT INTO alerts VALUES(6308,1773127775.7676301,'{"timestamp": "2026-03-10T08:29:35.767630+0100", "flow_id": 2171047894167648, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53066, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27824, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:29:35.767630+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53066, "dest_port": 53}}'); INSERT INTO alerts VALUES(6309,1773127782.900719881,'{"timestamp": "2026-03-10T08:29:42.900720+0100", "flow_id": 1898240658398382, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:29:42.900720+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57886, "dest_port": 53}}'); INSERT INTO alerts VALUES(6310,1773127782.900721074,'{"timestamp": "2026-03-10T08:29:42.900721+0100", "flow_id": 1898246530285126, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:29:42.900721+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54367, "dest_port": 53}}'); INSERT INTO alerts VALUES(6311,1773127787.711819887,'{"timestamp": "2026-03-10T08:29:47.711820+0100", "flow_id": 1086922238891471, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 51099, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31056, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:29:47.711820+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 51099, "dest_port": 53}}'); INSERT INTO alerts VALUES(6312,1773127799.030788898,'{"timestamp": "2026-03-10T08:29:59.030789+0100", "flow_id": 2102564903313497, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 52260, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24063, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:29:59.030789+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 52260, "dest_port": 53}}'); INSERT INTO alerts VALUES(6313,1773127810.489867926,'{"timestamp": "2026-03-10T08:30:10.489868+0100", "flow_id": 696592623603028, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50283, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46298, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:30:10.489868+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50283, "dest_port": 53}}'); INSERT INTO alerts VALUES(6314,1773127822.015727044,'{"timestamp": "2026-03-10T08:30:22.015727+0100", "flow_id": 1756398256198184, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50313, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44146, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:30:22.015727+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50313, "dest_port": 53}}'); INSERT INTO alerts VALUES(6315,1773127823.006927967,'{"timestamp": "2026-03-10T08:30:23.006928+0100", "flow_id": 2000081796491303, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52043, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53520, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:30:23.006928+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52043, "dest_port": 53}}'); INSERT INTO alerts VALUES(6316,1773127823.006927967,'{"timestamp": "2026-03-10T08:30:23.006928+0100", "flow_id": 2000082490365160, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62695, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55875, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:30:23.006928+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62695, "dest_port": 53}}'); INSERT INTO alerts VALUES(6317,1773127827.337860107,'{"timestamp": "2026-03-10T08:30:27.337860+0100", "flow_id": 888151925779599, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49301, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26936, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:30:27.337860+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49301, "dest_port": 53}}'); INSERT INTO alerts VALUES(6318,1773127833.967708111,'{"timestamp": "2026-03-10T08:30:33.967708+0100", "flow_id": 497100094420084, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65312, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43283, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:30:33.967708+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65312, "dest_port": 53}}'); INSERT INTO alerts VALUES(6319,1773127839.917320966,'{"timestamp": "2026-03-10T08:30:39.917321+0100", "flow_id": 2251014023169543, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58089, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45116, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmf.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-10T08:30:39.917321+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58089, "dest_port": 53}}'); INSERT INTO alerts VALUES(6320,1773127841.079523086,'{"timestamp": "2026-03-10T08:30:41.079523+0100", "flow_id": 341548822465229, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:30:41.079523+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6321,1773127841.080770016,'{"timestamp": "2026-03-10T08:30:41.080770+0100", "flow_id": 346906626522204, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:30:41.080770+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6322,1773127846.497886897,'{"timestamp": "2026-03-10T08:30:46.497887+0100", "flow_id": 1856934675645329, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62160, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52873, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:30:46.497887+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62160, "dest_port": 53}}'); INSERT INTO alerts VALUES(6323,1773127857.777360916,'{"timestamp": "2026-03-10T08:30:57.777361+0100", "flow_id": 523994504990089, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56554, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33756, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:30:57.777361+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56554, "dest_port": 53}}'); INSERT INTO alerts VALUES(6324,1773127869.507285118,'{"timestamp": "2026-03-10T08:31:09.507285+0100", "flow_id": 1615823273549609, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58107, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2381, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:31:09.507285+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58107, "dest_port": 53}}'); INSERT INTO alerts VALUES(6325,1773127875.840929031,'{"timestamp": "2026-03-10T08:31:15.840929+0100", "flow_id": 1078490063322801, "event_type": "alert", "src_ip": "205.210.31.215", "src_port": 52642, "dest_ip": "134.19.61.215", "dest_port": 4332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:31:15.840929+0100", "src_ip": "205.210.31.215", "dest_ip": "134.19.61.215", "src_port": 52642, "dest_port": 4332}}'); INSERT INTO alerts VALUES(6326,1773127880.93512988,'{"timestamp": "2026-03-10T08:31:20.935130+0100", "flow_id": 75706035400892, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 63109, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38758, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:31:20.935130+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 63109, "dest_port": 53}}'); INSERT INTO alerts VALUES(6327,1773127884.472311974,'{"timestamp": "2026-03-10T08:31:24.472312+0100", "flow_id": 1184140639058771, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 51029, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59414, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "probe.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-10T08:31:24.472312+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 51029, "dest_port": 53}}'); INSERT INTO alerts VALUES(6328,1773127892.434478045,'{"timestamp": "2026-03-10T08:31:32.434478+0100", "flow_id": 1303119836536356, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 49450, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30584, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:31:32.434478+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 49450, "dest_port": 53}}'); INSERT INTO alerts VALUES(6329,1773127898.930864096,'{"timestamp": "2026-03-10T08:31:38.930864+0100", "flow_id": 805959531509674, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 55644, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:31:38.908548+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 55644, "dest_port": 853}}'); INSERT INTO alerts VALUES(6330,1773127901.931529998,'{"timestamp": "2026-03-10T08:31:41.931530+0100", "flow_id": 1660727991688476, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 45980, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:31:41.910956+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 45980, "dest_port": 853}}'); INSERT INTO alerts VALUES(6331,1773127903.957657098,'{"timestamp": "2026-03-10T08:31:43.957657+0100", "flow_id": 2142781213664536, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60427, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5344, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:31:43.957657+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60427, "dest_port": 53}}'); INSERT INTO alerts VALUES(6332,1773127904.935455083,'{"timestamp": "2026-03-10T08:31:44.935455+0100", "flow_id": 262024903209706, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 45992, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:31:44.912975+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 45992, "dest_port": 853}}'); INSERT INTO alerts VALUES(6333,1773127915.20363307,'{"timestamp": "2026-03-10T08:31:55.203633+0100", "flow_id": 874599098047369, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60294, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30674, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:31:55.203633+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60294, "dest_port": 53}}'); INSERT INTO alerts VALUES(6334,1773127927.504793882,'{"timestamp": "2026-03-10T08:32:07.504794+0100", "flow_id": 2168076153059437, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60689, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54124, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:32:07.504794+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60689, "dest_port": 53}}'); INSERT INTO alerts VALUES(6335,1773127939.472949982,'{"timestamp": "2026-03-10T08:32:19.472950+0100", "flow_id": 905406089626911, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61204, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50837, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:32:19.472950+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61204, "dest_port": 53}}'); INSERT INTO alerts VALUES(6336,1773127947.004821062,'{"timestamp": "2026-03-10T08:32:27.004821+0100", "flow_id": 865134416776125, "event_type": "alert", "src_ip": "205.210.31.69", "src_port": 52801, "dest_ip": "134.19.61.215", "dest_port": 9093, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:32:27.004821+0100", "src_ip": "205.210.31.69", "dest_ip": "134.19.61.215", "src_port": 52801, "dest_port": 9093}}'); INSERT INTO alerts VALUES(6337,1773127951.529512883,'{"timestamp": "2026-03-10T08:32:31.529513+0100", "flow_id": 1992769124426802, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56568, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8958, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:32:31.529513+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56568, "dest_port": 53}}'); INSERT INTO alerts VALUES(6338,1773127955.926203966,'{"timestamp": "2026-03-10T08:32:35.926204+0100", "flow_id": 881793698127022, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57886, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21265, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:32:35.926204+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57886, "dest_port": 53}}'); INSERT INTO alerts VALUES(6339,1773127955.92620492,'{"timestamp": "2026-03-10T08:32:35.926205+0100", "flow_id": 881799570013766, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39961, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:32:35.926205+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54367, "dest_port": 53}}'); INSERT INTO alerts VALUES(6340,1773127960.15489006,'{"timestamp": "2026-03-10T08:32:40.154890+0100", "flow_id": 102299351349739, "event_type": "alert", "src_ip": "204.76.203.56", "src_port": 50182, "dest_ip": "134.19.61.215", "dest_port": 8545, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:32:40.154890+0100", "src_ip": "204.76.203.56", "dest_ip": "134.19.61.215", "src_port": 50182, "dest_port": 8545}}'); INSERT INTO alerts VALUES(6341,1773127963.507263899,'{"timestamp": "2026-03-10T08:32:43.507264+0100", "flow_id": 1052783769016460, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 59636, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48417, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:32:43.507264+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 59636, "dest_port": 53}}'); INSERT INTO alerts VALUES(6342,1773127969.276770114,'{"timestamp": "2026-03-10T08:32:49.276770+0100", "flow_id": 344297078053084, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54041, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40234, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:32:49.276770+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54041, "dest_port": 53}}'); INSERT INTO alerts VALUES(6343,1773127969.276771069,'{"timestamp": "2026-03-10T08:32:49.276771+0100", "flow_id": 344299805907734, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56043, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58643, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:32:49.276771+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56043, "dest_port": 53}}'); INSERT INTO alerts VALUES(6344,1773127975.022304058,'{"timestamp": "2026-03-10T08:32:55.022304+0100", "flow_id": 2066122131264041, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55219, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 35483, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:32:55.022304+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55219, "dest_port": 53}}'); INSERT INTO alerts VALUES(6345,1773127976.761652947,'{"timestamp": "2026-03-10T08:32:56.761653+0100", "flow_id": 86082775646559, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 33094, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:32:56.740938+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 33094, "dest_port": 853}}'); INSERT INTO alerts VALUES(6346,1773127986.587188005,'{"timestamp": "2026-03-10T08:33:06.587188+0100", "flow_id": 833106225734325, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 55137, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 3738, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:33:06.587188+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 55137, "dest_port": 53}}'); INSERT INTO alerts VALUES(6347,1773127989.641407012,'{"timestamp": "2026-03-10T08:33:09.641407+0100", "flow_id": 1628922319768269, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:33:09.641407+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6348,1773127989.641407967,'{"timestamp": "2026-03-10T08:33:09.641408+0100", "flow_id": 1628928594574428, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:33:09.641408+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6349,1773127998.282485962,'{"timestamp": "2026-03-10T08:33:18.282486+0100", "flow_id": 1776221178803658, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54708, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1561, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:33:18.282486+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54708, "dest_port": 53}}'); INSERT INTO alerts VALUES(6350,1773128009.993927001,'{"timestamp": "2026-03-10T08:33:29.993927+0100", "flow_id": 328235088948391, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60880, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47982, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:33:29.993927+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60880, "dest_port": 53}}'); INSERT INTO alerts VALUES(6351,1773128021.764740943,'{"timestamp": "2026-03-10T08:33:41.764741+0100", "flow_id": 1595690875509346, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54562, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:33:41.764741+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54562, "dest_port": 53}}'); INSERT INTO alerts VALUES(6352,1773128033.282186986,'{"timestamp": "2026-03-10T08:33:53.282187+0100", "flow_id": 367561376324983, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57879, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13908, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:33:53.282187+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57879, "dest_port": 53}}'); INSERT INTO alerts VALUES(6353,1773128040.22833705,'{"timestamp": "2026-03-10T08:34:00.228337+0100", "flow_id": 136275724427394, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:34:00.228337+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6354,1773128043.680665017,'{"timestamp": "2026-03-10T08:34:03.680665+0100", "flow_id": 953113033271558, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:34:03.680665+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6355,1773128043.680665017,'{"timestamp": "2026-03-10T08:34:03.680665+0100", "flow_id": 953109971779296, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:34:03.680665+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6356,1773128054.055438996,'{"timestamp": "2026-03-10T08:34:14.055439+0100", "flow_id": 1926958779421774, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 62915, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62895, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:34:14.055439+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 62915, "dest_port": 53}}'); INSERT INTO alerts VALUES(6357,1773128066.406755924,'{"timestamp": "2026-03-10T08:34:26.406756+0100", "flow_id": 621106574605857, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63885, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61408, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T08:34:26.406756+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63885, "dest_port": 53}}'); INSERT INTO alerts VALUES(6358,1773128070.719794034,'{"timestamp": "2026-03-10T08:34:30.719794+0100", "flow_id": 1965595616449976, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36841, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34794, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T08:34:30.719794+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36841, "dest_port": 53}}'); INSERT INTO alerts VALUES(6359,1773128070.722243071,'{"timestamp": "2026-03-10T08:34:30.722243+0100", "flow_id": 1694637696654938, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 37081, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 57578, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T08:34:30.722243+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 37081, "dest_port": 53}}'); INSERT INTO alerts VALUES(6360,1773128070.722244025,'{"timestamp": "2026-03-10T08:34:30.722244+0100", "flow_id": 1694641236440884, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57310, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54829, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T08:34:30.722244+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57310, "dest_port": 53}}'); INSERT INTO alerts VALUES(6361,1773128071.250437022,'{"timestamp": "2026-03-10T08:34:31.250437+0100", "flow_id": 2201520283262955, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44776, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58853, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cloudflare-dns.com", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-10T08:34:31.250437+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44776, "dest_port": 53}}'); INSERT INTO alerts VALUES(6362,1773128088.839345932,'{"timestamp": "2026-03-10T08:34:48.839346+0100", "flow_id": 227265651086162, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41087, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 15698, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:34:48.839346+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41087, "dest_port": 53}}'); INSERT INTO alerts VALUES(6363,1773128088.839710951,'{"timestamp": "2026-03-10T08:34:48.839711+0100", "flow_id": 228833010049849, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 47171, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2726, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:34:48.839711+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 47171, "dest_port": 53}}'); INSERT INTO alerts VALUES(6364,1773128094.288330078,'{"timestamp": "2026-03-10T08:34:54.288330+0100", "flow_id": 1801318391241589, "event_type": "alert", "src_ip": "79.124.62.230", "src_port": 47201, "dest_ip": "134.19.61.215", "dest_port": 1362, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:34:54.288330+0100", "src_ip": "79.124.62.230", "dest_ip": "134.19.61.215", "src_port": 47201, "dest_port": 1362}}'); INSERT INTO alerts VALUES(6365,1773128106.538630962,'{"timestamp": "2026-03-10T08:35:06.538631+0100", "flow_id": 624554789311720, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 62695, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 55875, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:35:06.538631+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 62695, "dest_port": 53}}'); INSERT INTO alerts VALUES(6366,1773128106.538630962,'{"timestamp": "2026-03-10T08:35:06.538631+0100", "flow_id": 624556291013130, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59359, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25234, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:35:06.538631+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59359, "dest_port": 53}}'); INSERT INTO alerts VALUES(6367,1773128115.319224119,'{"timestamp": "2026-03-10T08:35:15.319224+0100", "flow_id": 1089582370480258, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:35:15.319224+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6368,1773128115.319224119,'{"timestamp": "2026-03-10T08:35:15.319224+0100", "flow_id": 1089585619101958, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:35:15.319224+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6369,1773128115.319225073,'{"timestamp": "2026-03-10T08:35:15.319225+0100", "flow_id": 1089586852576992, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:35:15.319225+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6370,1773128122.05051303,'{"timestamp": "2026-03-10T08:35:22.050513+0100", "flow_id": 779905471241433, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 49389, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30316, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T08:35:22.050513+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 49389, "dest_port": 53}}'); INSERT INTO alerts VALUES(6371,1773128130.01206994,'{"timestamp": "2026-03-10T08:35:30.012070+0100", "flow_id": 614790346869453, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:35:30.012070+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6372,1773128130.01206994,'{"timestamp": "2026-03-10T08:35:30.012070+0100", "flow_id": 614792326708316, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:35:30.012070+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6373,1773128145.55064106,'{"timestamp": "2026-03-10T08:35:45.550641+0100", "flow_id": 394660956954754, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:35:45.550641+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6374,1773128145.550642013,'{"timestamp": "2026-03-10T08:35:45.550642+0100", "flow_id": 394668500543750, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:35:45.550642+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6375,1773128145.550642013,'{"timestamp": "2026-03-10T08:35:45.550642+0100", "flow_id": 394665439051488, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:35:45.550642+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6376,1773128160.981806994,'{"timestamp": "2026-03-10T08:36:00.981807+0100", "flow_id": 276179420220109, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:36:00.981807+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6377,1773128160.982707977,'{"timestamp": "2026-03-10T08:36:00.982708+0100", "flow_id": 280051165592668, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:36:00.982708+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6378,1773128176.990590096,'{"timestamp": "2026-03-10T08:36:16.990590+0100", "flow_id": 32427710177410, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:36:16.990590+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6379,1773128176.990590096,'{"timestamp": "2026-03-10T08:36:16.990590+0100", "flow_id": 32430958799110, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:36:16.990590+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6380,1773128176.990590096,'{"timestamp": "2026-03-10T08:36:16.990590+0100", "flow_id": 32427897306848, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:36:16.990590+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6381,1773128192.104927062,'{"timestamp": "2026-03-10T08:36:32.104927+0100", "flow_id": 169183194942157, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:36:32.104927+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6382,1773128192.104927062,'{"timestamp": "2026-03-10T08:36:32.104927+0100", "flow_id": 169185174781020, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:36:32.104927+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6383,1773128204.676534891,'{"timestamp": "2026-03-10T08:36:44.676535+0100", "flow_id": 1216848494386821, "event_type": "alert", "src_ip": "45.156.87.24", "src_port": 33794, "dest_ip": "134.19.61.215", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:36:44.676535+0100", "src_ip": "45.156.87.24", "dest_ip": "134.19.61.215", "src_port": 33794, "dest_port": 5555}}'); INSERT INTO alerts VALUES(6384,1773128204.676534891,'{"timestamp": "2026-03-10T08:36:44.676535+0100", "flow_id": 1216848494386821, "event_type": "alert", "src_ip": "45.156.87.24", "src_port": 33794, "dest_ip": "134.19.61.215", "dest_port": 5555, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:36:44.676535+0100", "src_ip": "45.156.87.24", "dest_ip": "134.19.61.215", "src_port": 33794, "dest_port": 5555}}'); INSERT INTO alerts VALUES(6385,1773128207.388802051,'{"timestamp": "2026-03-10T08:36:47.388802+0100", "flow_id": 2232842535133314, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:36:47.388802+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6386,1773128207.388802051,'{"timestamp": "2026-03-10T08:36:47.388802+0100", "flow_id": 2232845783755014, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:36:47.388802+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6387,1773128207.388802051,'{"timestamp": "2026-03-10T08:36:47.388802+0100", "flow_id": 2232842722262752, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:36:47.388802+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6388,1773128218.886778116,'{"timestamp": "2026-03-10T08:36:58.886778+0100", "flow_id": 712461020843955, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59083, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 2736, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:36:58.886778+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59083, "dest_port": 53}}'); INSERT INTO alerts VALUES(6389,1773128218.88677907,'{"timestamp": "2026-03-10T08:36:58.886779+0100", "flow_id": 712464920188836, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60383, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60501, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:36:58.886779+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60383, "dest_port": 53}}'); INSERT INTO alerts VALUES(6390,1773128222.868360042,'{"timestamp": "2026-03-10T08:37:02.868360+0100", "flow_id": 1759253102365389, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:37:02.868360+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6391,1773128222.868360042,'{"timestamp": "2026-03-10T08:37:02.868360+0100", "flow_id": 1759255082204252, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:37:02.868360+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6392,1773128238.545068026,'{"timestamp": "2026-03-10T08:37:18.545068+0100", "flow_id": 1778099987767426, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:37:18.545068+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6393,1773128238.54506898,'{"timestamp": "2026-03-10T08:37:18.545069+0100", "flow_id": 1778107531356422, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:37:18.545069+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6394,1773128238.54506898,'{"timestamp": "2026-03-10T08:37:18.545069+0100", "flow_id": 1778104469864160, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:37:18.545069+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6395,1773128269.637526989,'{"timestamp": "2026-03-10T08:37:49.637527+0100", "flow_id": 1612258415566978, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:37:49.637527+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6396,1773128269.637527943,'{"timestamp": "2026-03-10T08:37:49.637528+0100", "flow_id": 1612265959155974, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:37:49.637528+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6397,1773128269.637527943,'{"timestamp": "2026-03-10T08:37:49.637528+0100", "flow_id": 1612262897663712, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:37:49.637528+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6398,1773128281.328605891,'{"timestamp": "2026-03-10T08:38:01.328606+0100", "flow_id": 285452832540299, "event_type": "alert", "src_ip": "79.124.62.126", "src_port": 46340, "dest_ip": "134.19.61.215", "dest_port": 12047, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:38:01.328606+0100", "src_ip": "79.124.62.126", "dest_ip": "134.19.61.215", "src_port": 46340, "dest_port": 12047}}'); INSERT INTO alerts VALUES(6399,1773128282.956327916,'{"timestamp": "2026-03-10T08:38:02.956328+0100", "flow_id": 729701421656959, "event_type": "alert", "src_ip": "66.132.153.158", "src_port": 24397, "dest_ip": "134.19.61.215", "dest_port": 111, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 68, "bytes_toclient": 0, "start": "2026-03-10T08:38:02.956328+0100", "src_ip": "66.132.153.158", "dest_ip": "134.19.61.215", "src_port": 24397, "dest_port": 111}}'); INSERT INTO alerts VALUES(6400,1773128288.179301977,'{"timestamp": "2026-03-10T08:38:08.179302+0100", "flow_id": 207149953117192, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65414, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7924, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:38:08.179302+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65414, "dest_port": 53}}'); INSERT INTO alerts VALUES(6401,1773128288.17930293,'{"timestamp": "2026-03-10T08:38:08.179303+0100", "flow_id": 207154445018759, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49737, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64166, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:38:08.179303+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49737, "dest_port": 53}}'); INSERT INTO alerts VALUES(6402,1773128292.79996109,'{"timestamp": "2026-03-10T08:38:12.799961+0100", "flow_id": 1184006657575629, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:38:12.799961+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6403,1773128292.799962044,'{"timestamp": "2026-03-10T08:38:12.799962+0100", "flow_id": 1184012932381788, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:38:12.799962+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6404,1773128300.897093058,'{"timestamp": "2026-03-10T08:38:20.897093+0100", "flow_id": 1319711013167234, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:38:20.897093+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6405,1773128300.897093058,'{"timestamp": "2026-03-10T08:38:20.897093+0100", "flow_id": 1319714261788934, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:38:20.897093+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6406,1773128300.897094011,'{"timestamp": "2026-03-10T08:38:20.897094+0100", "flow_id": 1319715495263968, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:38:20.897094+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6407,1773128314.496592998,'{"timestamp": "2026-03-10T08:38:34.496593+0100", "flow_id": 725476400849267, "event_type": "alert", "src_ip": "185.242.3.253", "src_port": 42589, "dest_ip": "134.19.61.215", "dest_port": 5905, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400035, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 36", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:38:34.496593+0100", "src_ip": "185.242.3.253", "dest_ip": "134.19.61.215", "src_port": 42589, "dest_port": 5905}}'); INSERT INTO alerts VALUES(6408,1773128323.856682062,'{"timestamp": "2026-03-10T08:38:43.856682+0100", "flow_id": 864671544150733, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:38:43.856682+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6409,1773128323.856682062,'{"timestamp": "2026-03-10T08:38:43.856682+0100", "flow_id": 864673523989596, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:38:43.856682+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6410,1773128331.924143076,'{"timestamp": "2026-03-10T08:38:51.924143+0100", "flow_id": 872939925102722, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:38:51.924143+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6411,1773128331.92414403,'{"timestamp": "2026-03-10T08:38:51.924144+0100", "flow_id": 872947468691718, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:38:51.924144+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6412,1773128331.92414403,'{"timestamp": "2026-03-10T08:38:51.924144+0100", "flow_id": 872944407199456, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:38:51.924144+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6413,1773128350.889270067,'{"timestamp": "2026-03-10T08:39:10.889270+0100", "flow_id": 1849062887782467, "event_type": "alert", "src_ip": "205.210.31.193", "src_port": 51586, "dest_ip": "134.19.61.215", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 88, "bytes_toclient": 0, "start": "2026-03-10T08:39:10.889270+0100", "src_ip": "205.210.31.193", "dest_ip": "134.19.61.215", "src_port": 51586, "dest_port": 161}}'); INSERT INTO alerts VALUES(6414,1773128355.32674694,'{"timestamp": "2026-03-10T08:39:15.326747+0100", "flow_id": 1121892840540877, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:39:15.326747+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6415,1773128355.326747895,'{"timestamp": "2026-03-10T08:39:15.326748+0100", "flow_id": 1121899115347036, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:39:15.326748+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6416,1773128358.300549983,'{"timestamp": "2026-03-10T08:39:18.300550+0100", "flow_id": 1853804376453484, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 58495, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1386, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmf.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-10T08:39:18.300550+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 58495, "dest_port": 53}}'); INSERT INTO alerts VALUES(6417,1773128358.954365015,'{"timestamp": "2026-03-10T08:39:18.954365+0100", "flow_id": 1847168443993222, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 52338, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10607, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:39:18.954365+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 52338, "dest_port": 53}}'); INSERT INTO alerts VALUES(6418,1773128358.954365015,'{"timestamp": "2026-03-10T08:39:18.954365+0100", "flow_id": 1847168277653911, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 54990, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13839, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:39:18.954365+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 54990, "dest_port": 53}}'); INSERT INTO alerts VALUES(6419,1773128386.577063084,'{"timestamp": "2026-03-10T08:39:46.577063+0100", "flow_id": 789616990653133, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:39:46.577063+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6420,1773128386.577063084,'{"timestamp": "2026-03-10T08:39:46.577063+0100", "flow_id": 789618970491996, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:39:46.577063+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6421,1773128389.865397931,'{"timestamp": "2026-03-10T08:39:49.865398+0100", "flow_id": 1465059590220780, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64004, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20399, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "caldav.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 70, "bytes_toclient": 0, "start": "2026-03-10T08:39:49.865398+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64004, "dest_port": 53}}'); INSERT INTO alerts VALUES(6422,1773128393.324701071,'{"timestamp": "2026-03-10T08:39:53.324701+0100", "flow_id": 550157618788431, "event_type": "alert", "src_ip": "65.49.1.81", "src_port": 51053, "dest_ip": "134.19.61.215", "dest_port": 5443, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:39:53.324701+0100", "src_ip": "65.49.1.81", "dest_ip": "134.19.61.215", "src_port": 51053, "dest_port": 5443}}'); INSERT INTO alerts VALUES(6423,1773128432.988195896,'{"timestamp": "2026-03-10T08:40:32.988196+0100", "flow_id": 22145558470786, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:40:32.988196+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6424,1773128432.988195896,'{"timestamp": "2026-03-10T08:40:32.988196+0100", "flow_id": 22148807092486, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:40:32.988196+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6425,1773128432.988195896,'{"timestamp": "2026-03-10T08:40:32.988196+0100", "flow_id": 22145745600224, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:40:32.988196+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6426,1773128443.842011928,'{"timestamp": "2026-03-10T08:40:43.842012+0100", "flow_id": 1083141791603611, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50645, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 186, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T08:40:43.842012+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50645, "dest_port": 53}}'); INSERT INTO alerts VALUES(6427,1773128464.332963943,'{"timestamp": "2026-03-10T08:41:04.332964+0100", "flow_id": 22695314284674, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:41:04.332964+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6428,1773128464.332964897,'{"timestamp": "2026-03-10T08:41:04.332965+0100", "flow_id": 22702857873670, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:41:04.332965+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6429,1773128464.332964897,'{"timestamp": "2026-03-10T08:41:04.332965+0100", "flow_id": 22699796381408, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:41:04.332965+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6430,1773128464.362205982,'{"timestamp": "2026-03-10T08:41:04.362206+0100", "flow_id": 148291662526986, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59359, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25234, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:41:04.362206+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59359, "dest_port": 53}}'); INSERT INTO alerts VALUES(6431,1773128464.362205982,'{"timestamp": "2026-03-10T08:41:04.362206+0100", "flow_id": 148291677253916, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61429, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 396, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:41:04.362206+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61429, "dest_port": 53}}'); INSERT INTO alerts VALUES(6432,1773128499.015845061,'{"timestamp": "2026-03-10T08:41:39.015845+0100", "flow_id": 912479109228211, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 58760, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:41:39.015845+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 58760, "dest_port": 53}}'); INSERT INTO alerts VALUES(6433,1773128499.01610899,'{"timestamp": "2026-03-10T08:41:39.016109+0100", "flow_id": 913614957130741, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 38206, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33766, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:41:39.016109+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 38206, "dest_port": 53}}'); INSERT INTO alerts VALUES(6434,1773128501.73207903,'{"timestamp": "2026-03-10T08:41:41.732079+0100", "flow_id": 1455407577218721, "event_type": "alert", "src_ip": "64.62.156.181", "src_port": 49428, "dest_ip": "134.19.61.215", "dest_port": 9000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:41:41.732079+0100", "src_ip": "64.62.156.181", "dest_ip": "134.19.61.215", "src_port": 49428, "dest_port": 9000}}'); INSERT INTO alerts VALUES(6435,1773128507.862792968,'{"timestamp": "2026-03-10T08:41:47.862793+0100", "flow_id": 890918089296589, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:41:47.862793+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6436,1773128507.862792968,'{"timestamp": "2026-03-10T08:41:47.862793+0100", "flow_id": 890920069135452, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:41:47.862793+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6437,1773128534.635536909,'{"timestamp": "2026-03-10T08:42:14.635537+0100", "flow_id": 1885189126428432, "event_type": "alert", "src_ip": "176.65.148.29", "src_port": 46735, "dest_ip": "134.19.61.215", "dest_port": 8332, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:42:14.635537+0100", "src_ip": "176.65.148.29", "dest_ip": "134.19.61.215", "src_port": 46735, "dest_port": 8332}}'); INSERT INTO alerts VALUES(6438,1773128537.867461919,'{"timestamp": "2026-03-10T08:42:17.867462+0100", "flow_id": 348021338180301, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:42:17.867462+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6439,1773128537.867463112,'{"timestamp": "2026-03-10T08:42:17.867463+0100", "flow_id": 348027612986460, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:42:17.867463+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6440,1773128566.001089096,'{"timestamp": "2026-03-10T08:42:46.001089+0100", "flow_id": 1693527786741890, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:42:46.001089+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6441,1773128566.001090049,'{"timestamp": "2026-03-10T08:42:46.001090+0100", "flow_id": 1693535330330886, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:42:46.001090+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6442,1773128566.001940966,'{"timestamp": "2026-03-10T08:42:46.001941+0100", "flow_id": 1697187286007520, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:42:46.001941+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6443,1773128568.708503962,'{"timestamp": "2026-03-10T08:42:48.708504+0100", "flow_id": 228251880164045, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:42:48.708504+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6444,1773128568.708503962,'{"timestamp": "2026-03-10T08:42:48.708504+0100", "flow_id": 228253860002908, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:42:48.708504+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6445,1773128580.632657052,'{"timestamp": "2026-03-10T08:43:00.632657+0100", "flow_id": 1309869877424412, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 61429, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 396, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:43:00.632657+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 61429, "dest_port": 53}}'); INSERT INTO alerts VALUES(6446,1773128580.632657052,'{"timestamp": "2026-03-10T08:43:00.632657+0100", "flow_id": 1309869314415660, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65095, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61217, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:43:00.632657+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65095, "dest_port": 53}}'); INSERT INTO alerts VALUES(6447,1773128584.480102063,'{"timestamp": "2026-03-10T08:43:04.480102+0100", "flow_id": 91698970169455, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54847, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20580, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "contacts.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T08:43:04.480102+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54847, "dest_port": 53}}'); INSERT INTO alerts VALUES(6448,1773128597.050477028,'{"timestamp": "2026-03-10T08:43:17.050477+0100", "flow_id": 1624172654846082, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:43:17.050477+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6449,1773128597.050477028,'{"timestamp": "2026-03-10T08:43:17.050477+0100", "flow_id": 1624175903467782, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:43:17.050477+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6450,1773128597.050477028,'{"timestamp": "2026-03-10T08:43:17.050477+0100", "flow_id": 1624172841975520, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:43:17.050477+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6451,1773128605.073020935,'{"timestamp": "2026-03-10T08:43:25.073021+0100", "flow_id": 1439523225874989, "event_type": "alert", "src_ip": "65.49.1.184", "src_port": 34535, "dest_ip": "134.19.61.215", "dest_port": 1900, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 125, "bytes_toclient": 0, "start": "2026-03-10T08:43:25.073021+0100", "src_ip": "65.49.1.184", "dest_ip": "134.19.61.215", "src_port": 34535, "dest_port": 1900}}'); INSERT INTO alerts VALUES(6452,1773128609.421659946,'{"timestamp": "2026-03-10T08:43:29.421660+0100", "flow_id": 403642202861302, "event_type": "alert", "src_ip": "193.163.125.114", "src_port": 45981, "dest_ip": "134.19.61.215", "dest_port": 4050, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:43:29.421660+0100", "src_ip": "193.163.125.114", "dest_ip": "134.19.61.215", "src_port": 45981, "dest_port": 4050}}'); INSERT INTO alerts VALUES(6453,1773128628.052105904,'{"timestamp": "2026-03-10T08:43:48.052106+0100", "flow_id": 1349694179860610, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:43:48.052106+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6454,1773128628.052105904,'{"timestamp": "2026-03-10T08:43:48.052106+0100", "flow_id": 1349697428482310, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:43:48.052106+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6455,1773128628.052107095,'{"timestamp": "2026-03-10T08:43:48.052107+0100", "flow_id": 1349698661957344, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:43:48.052107+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6456,1773128639.090728998,'{"timestamp": "2026-03-10T08:43:59.090729+0100", "flow_id": 2078532066836716, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46891, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53427, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:43:59.090729+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46891, "dest_port": 53}}'); INSERT INTO alerts VALUES(6457,1773128639.099530936,'{"timestamp": "2026-03-10T08:43:59.099531+0100", "flow_id": 2116336128093612, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 59336, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56353, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:43:59.099531+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 59336, "dest_port": 53}}'); INSERT INTO alerts VALUES(6458,1773128648.288583993,'{"timestamp": "2026-03-10T08:44:08.288584+0100", "flow_id": 113559073491661, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:44:08.288584+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6459,1773128648.288583993,'{"timestamp": "2026-03-10T08:44:08.288584+0100", "flow_id": 113561053330524, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:44:08.288584+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6460,1773128651.744396924,'{"timestamp": "2026-03-10T08:44:11.744397+0100", "flow_id": 945362163763111, "event_type": "alert", "src_ip": "205.210.31.106", "src_port": 50465, "dest_ip": "134.19.61.215", "dest_port": 52590, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:44:11.744397+0100", "src_ip": "205.210.31.106", "dest_ip": "134.19.61.215", "src_port": 50465, "dest_port": 52590}}'); INSERT INTO alerts VALUES(6461,1773128681.280761957,'{"timestamp": "2026-03-10T08:44:41.280762+0100", "flow_id": 361442356164140, "event_type": "alert", "src_ip": "65.49.1.240", "src_port": 48510, "dest_ip": "134.19.61.215", "dest_port": 4433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:44:41.280762+0100", "src_ip": "65.49.1.240", "dest_ip": "134.19.61.215", "src_port": 48510, "dest_port": 4433}}'); INSERT INTO alerts VALUES(6462,1773128750.893112897,'{"timestamp": "2026-03-10T08:45:50.893113+0100", "flow_id": 1865566996750466, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:45:50.893113+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6463,1773128750.89311409,'{"timestamp": "2026-03-10T08:45:50.893114+0100", "flow_id": 1865574540339462, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:45:50.893114+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6464,1773128750.89311409,'{"timestamp": "2026-03-10T08:45:50.893114+0100", "flow_id": 1865571478847200, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:45:50.893114+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6465,1773128770.622936965,'{"timestamp": "2026-03-10T08:46:10.622937+0100", "flow_id": 705169343679181, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:46:10.622937+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6466,1773128770.622936965,'{"timestamp": "2026-03-10T08:46:10.622937+0100", "flow_id": 705171323518044, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:46:10.622937+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6467,1773128779.154052972,'{"timestamp": "2026-03-10T08:46:19.154053+0100", "flow_id": 943128386991365, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44698, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26499, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:46:19.154053+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44698, "dest_port": 53}}'); INSERT INTO alerts VALUES(6468,1773128779.15434289,'{"timestamp": "2026-03-10T08:46:19.154343+0100", "flow_id": 944373501857937, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40173, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 6701, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:46:19.154343+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40173, "dest_port": 53}}'); INSERT INTO alerts VALUES(6469,1773128781.002494097,'{"timestamp": "2026-03-10T08:46:21.002494+0100", "flow_id": 1418087239082114, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:46:21.002494+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6470,1773128781.002494097,'{"timestamp": "2026-03-10T08:46:21.002494+0100", "flow_id": 1418090487703814, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:46:21.002494+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6471,1773128781.002494097,'{"timestamp": "2026-03-10T08:46:21.002494+0100", "flow_id": 1418087426211552, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:46:21.002494+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6472,1773128801.5878129,'{"timestamp": "2026-03-10T08:46:41.587813+0100", "flow_id": 554312912374477, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:46:41.587813+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6473,1773128801.587814093,'{"timestamp": "2026-03-10T08:46:41.587814+0100", "flow_id": 554319187180636, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:46:41.587814+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6474,1773128811.669665098,'{"timestamp": "2026-03-10T08:46:51.669665+0100", "flow_id": 905865144393858, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:46:51.669665+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6475,1773128811.669665098,'{"timestamp": "2026-03-10T08:46:51.669665+0100", "flow_id": 905868393015558, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:46:51.669665+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6476,1773128811.669665098,'{"timestamp": "2026-03-10T08:46:51.669665+0100", "flow_id": 905865331523296, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:46:51.669665+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6477,1773128814.445252895,'{"timestamp": "2026-03-10T08:46:54.445253+0100", "flow_id": 1809406818834992, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 40444, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:46:54.421285+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 40444, "dest_port": 853}}'); INSERT INTO alerts VALUES(6478,1773128818.047358989,'{"timestamp": "2026-03-10T08:46:58.047359+0100", "flow_id": 766355681564912, "event_type": "alert", "src_ip": "147.185.132.99", "src_port": 50025, "dest_ip": "134.19.61.215", "dest_port": 9042, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:46:58.047359+0100", "src_ip": "147.185.132.99", "dest_ip": "134.19.61.215", "src_port": 50025, "dest_port": 9042}}'); INSERT INTO alerts VALUES(6479,1773128841.948916913,'{"timestamp": "2026-03-10T08:47:21.948917+0100", "flow_id": 416393491472514, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:47:21.948917+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6480,1773128841.948916913,'{"timestamp": "2026-03-10T08:47:21.948917+0100", "flow_id": 416396740094214, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:47:21.948917+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6481,1773128841.948916913,'{"timestamp": "2026-03-10T08:47:21.948917+0100", "flow_id": 416393678601952, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:47:21.948917+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6482,1773128849.45176506,'{"timestamp": "2026-03-10T08:47:29.451765+0100", "flow_id": 441955061096358, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 53122, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:47:29.430580+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 53122, "dest_port": 853}}'); INSERT INTO alerts VALUES(6483,1773128872.083631992,'{"timestamp": "2026-03-10T08:47:52.083632+0100", "flow_id": 77721866373837, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:47:52.083632+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6484,1773128872.084507942,'{"timestamp": "2026-03-10T08:47:52.084508+0100", "flow_id": 81486237563996, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:47:52.084508+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6485,1773128873.063483953,'{"timestamp": "2026-03-10T08:47:53.063484+0100", "flow_id": 554137387622530, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:47:53.063484+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6486,1773128873.063483953,'{"timestamp": "2026-03-10T08:47:53.063484+0100", "flow_id": 554140636244230, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:47:53.063484+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6487,1773128873.063483953,'{"timestamp": "2026-03-10T08:47:53.063484+0100", "flow_id": 554137574751968, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:47:53.063484+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6488,1773128876.532355071,'{"timestamp": "2026-03-10T08:47:56.532355+0100", "flow_id": 1160549868270295, "event_type": "alert", "src_ip": "193.163.125.116", "src_port": 49583, "dest_ip": "134.19.61.215", "dest_port": 5364, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:47:56.532355+0100", "src_ip": "193.163.125.116", "dest_ip": "134.19.61.215", "src_port": 49583, "dest_port": 5364}}'); INSERT INTO alerts VALUES(6489,1773128880.760574103,'{"timestamp": "2026-03-10T08:48:00.760574+0100", "flow_id": 89478827393791, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 43888, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:48:00.741729+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 43888, "dest_port": 853}}'); INSERT INTO alerts VALUES(6490,1773128883.765360117,'{"timestamp": "2026-03-10T08:48:03.765360+0100", "flow_id": 945262495105551, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 41664, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:48:03.744374+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 41664, "dest_port": 853}}'); INSERT INTO alerts VALUES(6491,1773128902.086780072,'{"timestamp": "2026-03-10T08:48:22.086780+0100", "flow_id": 1780092283685581, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:48:22.086780+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6492,1773128902.086781024,'{"timestamp": "2026-03-10T08:48:22.086781+0100", "flow_id": 1780098558491740, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:48:22.086781+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6493,1773128904.112520934,'{"timestamp": "2026-03-10T08:48:24.112521+0100", "flow_id": 201799745495170, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:48:24.112521+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6494,1773128904.112521887,'{"timestamp": "2026-03-10T08:48:24.112522+0100", "flow_id": 201807289084166, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:48:24.112522+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6495,1773128904.112521887,'{"timestamp": "2026-03-10T08:48:24.112522+0100", "flow_id": 201804227591904, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:48:24.112522+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6496,1773128919.248414039,'{"timestamp": "2026-03-10T08:48:39.248414+0100", "flow_id": 2192832069579549, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 58205, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26554, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:48:39.248414+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 58205, "dest_port": 53}}'); INSERT INTO alerts VALUES(6497,1773128919.248414993,'{"timestamp": "2026-03-10T08:48:39.248415+0100", "flow_id": 2192836313913703, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51926, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60065, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:48:39.248415+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51926, "dest_port": 53}}'); INSERT INTO alerts VALUES(6498,1773128930.479756116,'{"timestamp": "2026-03-10T08:48:50.479756+0100", "flow_id": 653164558931796, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57940, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4931, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:48:50.479756+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57940, "dest_port": 53}}'); INSERT INTO alerts VALUES(6499,1773128930.482052088,'{"timestamp": "2026-03-10T08:48:50.482052+0100", "flow_id": 663023583242941, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53143, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33466, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:48:50.482052+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53143, "dest_port": 53}}'); INSERT INTO alerts VALUES(6500,1773128932.153281928,'{"timestamp": "2026-03-10T08:48:52.153282+0100", "flow_id": 1221291268672205, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:48:52.153282+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6501,1773128932.153281928,'{"timestamp": "2026-03-10T08:48:52.153282+0100", "flow_id": 1221293248511068, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:48:52.153282+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6502,1773128934.504070997,'{"timestamp": "2026-03-10T08:48:54.504071+0100", "flow_id": 1883494190243970, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:48:54.504071+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6503,1773128934.50407195,'{"timestamp": "2026-03-10T08:48:54.504072+0100", "flow_id": 1883501733832966, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:48:54.504072+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6504,1773128934.50407195,'{"timestamp": "2026-03-10T08:48:54.504072+0100", "flow_id": 1883498672340704, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:48:54.504072+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6505,1773128970.836009025,'{"timestamp": "2026-03-10T08:49:30.836009+0100", "flow_id": 775885833637771, "event_type": "alert", "src_ip": "205.210.31.203", "src_port": 53803, "dest_ip": "134.19.61.215", "dest_port": 1200, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:49:30.836009+0100", "src_ip": "205.210.31.203", "dest_ip": "134.19.61.215", "src_port": 53803, "dest_port": 1200}}'); INSERT INTO alerts VALUES(6506,1773129003.564943076,'{"timestamp": "2026-03-10T08:50:03.564943+0100", "flow_id": 1019039898934316, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65095, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61217, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:50:03.564943+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65095, "dest_port": 53}}'); INSERT INTO alerts VALUES(6507,1773129003.56541109,'{"timestamp": "2026-03-10T08:50:03.565411+0100", "flow_id": 1021047776772471, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52566, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26487, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:50:03.565411+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52566, "dest_port": 53}}'); INSERT INTO alerts VALUES(6508,1773129011.048660993,'{"timestamp": "2026-03-10T08:50:11.048661+0100", "flow_id": 1053423040815234, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:50:11.048661+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6509,1773129011.048661948,'{"timestamp": "2026-03-10T08:50:11.048662+0100", "flow_id": 1053430584404230, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:50:11.048662+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6510,1773129011.048661948,'{"timestamp": "2026-03-10T08:50:11.048662+0100", "flow_id": 1053427522911968, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:50:11.048662+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6511,1773129011.939069032,'{"timestamp": "2026-03-10T08:50:11.939069+0100", "flow_id": 937048184818127, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50362, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13094, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:50:11.939069+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50362, "dest_port": 53}}'); INSERT INTO alerts VALUES(6512,1773129011.943371057,'{"timestamp": "2026-03-10T08:50:11.943371+0100", "flow_id": 955524317232633, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 57713, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50435, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:50:11.943371+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 57713, "dest_port": 53}}'); INSERT INTO alerts VALUES(6513,1773129018.002509117,'{"timestamp": "2026-03-10T08:50:18.002509+0100", "flow_id": 573726164552397, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:50:18.002509+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6514,1773129018.003142119,'{"timestamp": "2026-03-10T08:50:18.003142+0100", "flow_id": 576446858689628, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:50:18.003142+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6515,1773129037.109719039,'{"timestamp": "2026-03-10T08:50:37.109719+0100", "flow_id": 1597139780114639, "event_type": "alert", "src_ip": "64.62.156.224", "src_port": 44624, "dest_ip": "134.19.61.215", "dest_port": 13046, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-10T08:50:37.109719+0100", "src_ip": "64.62.156.224", "dest_ip": "134.19.61.215", "src_port": 44624, "dest_port": 13046}}'); INSERT INTO alerts VALUES(6516,1773129041.155347109,'{"timestamp": "2026-03-10T08:50:41.155347+0100", "flow_id": 385736014913666, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:50:41.155347+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6517,1773129041.155347109,'{"timestamp": "2026-03-10T08:50:41.155347+0100", "flow_id": 385739263535366, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:50:41.155347+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6518,1773129041.155347109,'{"timestamp": "2026-03-10T08:50:41.155347+0100", "flow_id": 385736202043104, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:50:41.155347+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6519,1773129049.300287008,'{"timestamp": "2026-03-10T08:50:49.300287+0100", "flow_id": 445298052467405, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:50:49.300287+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6520,1773129049.300287008,'{"timestamp": "2026-03-10T08:50:49.300287+0100", "flow_id": 445300032306268, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:50:49.300287+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6521,1773129059.326514005,'{"timestamp": "2026-03-10T08:50:59.326514+0100", "flow_id": 1120894863901998, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33442, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37684, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:50:59.326514+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33442, "dest_port": 53}}'); INSERT INTO alerts VALUES(6522,1773129059.326514005,'{"timestamp": "2026-03-10T08:50:59.326514+0100", "flow_id": 1120892783915179, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 46105, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13803, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:50:59.326514+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 46105, "dest_port": 53}}'); INSERT INTO alerts VALUES(6523,1773129067.507555961,'{"timestamp": "2026-03-10T08:51:07.507556+0100", "flow_id": 1054037465920575, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40247, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48336, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T08:51:07.507556+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40247, "dest_port": 53}}'); INSERT INTO alerts VALUES(6524,1773129067.507556915,'{"timestamp": "2026-03-10T08:51:07.507557+0100", "flow_id": 1054043968969016, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 41006, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18908, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T08:51:07.507557+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 41006, "dest_port": 53}}'); INSERT INTO alerts VALUES(6525,1773129067.507556915,'{"timestamp": "2026-03-10T08:51:07.507557+0100", "flow_id": 1054042858508737, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40663, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16647, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T08:51:07.507557+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40663, "dest_port": 53}}'); INSERT INTO alerts VALUES(6526,1773129068.089360952,'{"timestamp": "2026-03-10T08:51:08.089361+0100", "flow_id": 1228230529725273, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 33805, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1658, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cloudflare-dns.com", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-10T08:51:08.089361+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 33805, "dest_port": 53}}'); INSERT INTO alerts VALUES(6527,1773129072.614053011,'{"timestamp": "2026-03-10T08:51:12.614053+0100", "flow_id": 104063469707394, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:51:12.614053+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6528,1773129072.614053011,'{"timestamp": "2026-03-10T08:51:12.614053+0100", "flow_id": 104066718329094, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:51:12.614053+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6529,1773129072.614053964,'{"timestamp": "2026-03-10T08:51:12.614054+0100", "flow_id": 104067951804128, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:51:12.614054+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6530,1773129077.731971026,'{"timestamp": "2026-03-10T08:51:17.731971+0100", "flow_id": 1454945907186098, "event_type": "alert", "src_ip": "147.185.132.138", "src_port": 51124, "dest_ip": "134.19.61.215", "dest_port": 11495, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:51:17.731971+0100", "src_ip": "147.185.132.138", "dest_ip": "134.19.61.215", "src_port": 51124, "dest_port": 11495}}'); INSERT INTO alerts VALUES(6531,1773129080.007168054,'{"timestamp": "2026-03-10T08:51:20.007168+0100", "flow_id": 30786463763149, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:51:20.007168+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6532,1773129080.007169009,'{"timestamp": "2026-03-10T08:51:20.007169+0100", "flow_id": 30792738569308, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:51:20.007169+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6533,1773129092.175560952,'{"timestamp": "2026-03-10T08:51:32.175561+0100", "flow_id": 1316981424263222, "event_type": "alert", "src_ip": "205.210.31.66", "src_port": 50665, "dest_ip": "134.19.61.215", "dest_port": 60000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:51:32.175561+0100", "src_ip": "205.210.31.66", "dest_ip": "134.19.61.215", "src_port": 50665, "dest_port": 60000}}'); INSERT INTO alerts VALUES(6534,1773129103.606839895,'{"timestamp": "2026-03-10T08:51:43.606840+0100", "flow_id": 2043408707575938, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:51:43.606840+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6535,1773129103.606839895,'{"timestamp": "2026-03-10T08:51:43.606840+0100", "flow_id": 2043411956197638, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:51:43.606840+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6536,1773129103.606841088,'{"timestamp": "2026-03-10T08:51:43.606841+0100", "flow_id": 2043413189672672, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:51:43.606841+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6537,1773129111.451344966,'{"timestamp": "2026-03-10T08:51:51.451345+0100", "flow_id": 2219987129109197, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:51:51.451345+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6538,1773129111.451344966,'{"timestamp": "2026-03-10T08:51:51.451345+0100", "flow_id": 2219989108948060, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:51:51.451345+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6539,1773129114.406896115,'{"timestamp": "2026-03-10T08:51:54.406896+0100", "flow_id": 621709313926873, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60906, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 47944, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T08:51:54.406896+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60906, "dest_port": 53}}'); INSERT INTO alerts VALUES(6540,1773129118.901407958,'{"timestamp": "2026-03-10T08:51:58.901408+0100", "flow_id": 1901197243420180, "event_type": "alert", "src_ip": "167.94.138.159", "src_port": 11446, "dest_ip": "134.19.61.215", "dest_port": 2079, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-10T08:51:58.901408+0100", "src_ip": "167.94.138.159", "dest_ip": "134.19.61.215", "src_port": 11446, "dest_port": 2079}}'); INSERT INTO alerts VALUES(6541,1773129119.895256997,'{"timestamp": "2026-03-10T08:51:59.895257+0100", "flow_id": 2156250582778231, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52566, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26487, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:51:59.895257+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52566, "dest_port": 53}}'); INSERT INTO alerts VALUES(6542,1773129119.895257949,'{"timestamp": "2026-03-10T08:51:59.895258+0100", "flow_id": 2156255160481215, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50477, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37510, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:51:59.895258+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50477, "dest_port": 53}}'); INSERT INTO alerts VALUES(6543,1773129133.893629075,'{"timestamp": "2026-03-10T08:52:13.893629+0100", "flow_id": 1586308223164546, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:52:13.893629+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6544,1773129133.893629075,'{"timestamp": "2026-03-10T08:52:13.893629+0100", "flow_id": 1586311471786246, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:52:13.893629+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6545,1773129133.893630027,'{"timestamp": "2026-03-10T08:52:13.893630+0100", "flow_id": 1586312705261280, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:52:13.893630+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6546,1773129150.413898945,'{"timestamp": "2026-03-10T08:52:30.413899+0100", "flow_id": 1777686937179493, "event_type": "alert", "src_ip": "92.63.197.180", "src_port": 44082, "dest_ip": "134.19.61.215", "dest_port": 44347, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400014, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 15", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:52:30.413899+0100", "src_ip": "92.63.197.180", "dest_ip": "134.19.61.215", "src_port": 44082, "dest_port": 44347}}'); INSERT INTO alerts VALUES(6547,1773129164.560137987,'{"timestamp": "2026-03-10T08:52:44.560138+0100", "flow_id": 1279875191496834, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:52:44.560138+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6548,1773129164.560137987,'{"timestamp": "2026-03-10T08:52:44.560138+0100", "flow_id": 1279878440118534, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:52:44.560138+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6549,1773129164.560137987,'{"timestamp": "2026-03-10T08:52:44.560138+0100", "flow_id": 1279875378626272, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:52:44.560138+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6550,1773129178.136502027,'{"timestamp": "2026-03-10T08:52:58.136502+0100", "flow_id": 586271764024013, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:52:58.136502+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6551,1773129178.136502027,'{"timestamp": "2026-03-10T08:52:58.136502+0100", "flow_id": 586273743862876, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:52:58.136502+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6552,1773129178.771559,'{"timestamp": "2026-03-10T08:52:58.771559+0100", "flow_id": 780548647549091, "event_type": "alert", "src_ip": "65.49.1.74", "src_port": 51002, "dest_ip": "134.19.61.215", "dest_port": 85, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:52:58.771559+0100", "src_ip": "65.49.1.74", "dest_ip": "134.19.61.215", "src_port": 51002, "dest_port": 85}}'); INSERT INTO alerts VALUES(6553,1773129187.1030159,'{"timestamp": "2026-03-10T08:53:07.103016+0100", "flow_id": 1005401229706203, "event_type": "alert", "src_ip": "205.210.31.80", "src_port": 54418, "dest_ip": "134.19.61.215", "dest_port": 52311, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:53:07.103016+0100", "src_ip": "205.210.31.80", "dest_ip": "134.19.61.215", "src_port": 54418, "dest_port": 52311}}'); INSERT INTO alerts VALUES(6554,1773129195.050512076,'{"timestamp": "2026-03-10T08:53:15.050512+0100", "flow_id": 1061373025280130, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:53:15.050512+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6555,1773129195.050856114,'{"timestamp": "2026-03-10T08:53:15.050856+0100", "flow_id": 1062853742651654, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:53:15.050856+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6556,1773129195.050857067,'{"timestamp": "2026-03-10T08:53:15.050857+0100", "flow_id": 1062854976126688, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:53:15.050857+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6557,1773129198.869206905,'{"timestamp": "2026-03-10T08:53:18.869207+0100", "flow_id": 1946710437849102, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 38744, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T08:53:18.846469+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 38744, "dest_port": 853}}'); INSERT INTO alerts VALUES(6558,1773129199.451086045,'{"timestamp": "2026-03-10T08:53:19.451086+0100", "flow_id": 2218876032306497, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40221, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63928, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:53:19.451086+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40221, "dest_port": 53}}'); INSERT INTO alerts VALUES(6559,1773129199.451086045,'{"timestamp": "2026-03-10T08:53:19.451086+0100", "flow_id": 2218876232273384, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40350, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26416, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:53:19.451086+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40350, "dest_port": 53}}'); INSERT INTO alerts VALUES(6560,1773129219.877787114,'{"timestamp": "2026-03-10T08:53:39.877787+0100", "flow_id": 955318444256798, "event_type": "alert", "src_ip": "64.62.156.67", "src_port": 43323, "dest_ip": "134.19.61.215", "dest_port": 87, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:53:39.877787+0100", "src_ip": "64.62.156.67", "dest_ip": "134.19.61.215", "src_port": 43323, "dest_port": 87}}'); INSERT INTO alerts VALUES(6561,1773129225.614272117,'{"timestamp": "2026-03-10T08:53:45.614272+0100", "flow_id": 386479044255874, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:53:45.614272+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6562,1773129225.614273071,'{"timestamp": "2026-03-10T08:53:45.614273+0100", "flow_id": 386486587844870, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:53:45.614273+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6563,1773129225.614273071,'{"timestamp": "2026-03-10T08:53:45.614273+0100", "flow_id": 386483526352608, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:53:45.614273+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6564,1773129239.449942111,'{"timestamp": "2026-03-10T08:53:59.449942+0100", "flow_id": 2213961289992909, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:53:59.449942+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6565,1773129239.450946092,'{"timestamp": "2026-03-10T08:53:59.450946+0100", "flow_id": 2218275416996956, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:53:59.450946+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6566,1773129241.869383097,'{"timestamp": "2026-03-10T08:54:01.869383+0100", "flow_id": 356275812805043, "event_type": "alert", "src_ip": "147.185.132.246", "src_port": 12182, "dest_ip": "134.19.61.215", "dest_port": 13746, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-10T08:54:01.869383+0100", "src_ip": "147.185.132.246", "dest_ip": "134.19.61.215", "src_port": 12182, "dest_port": 13746}}'); INSERT INTO alerts VALUES(6567,1773129243.297430038,'{"timestamp": "2026-03-10T08:54:03.297430+0100", "flow_id": 995979285957874, "event_type": "alert", "src_ip": "198.235.24.213", "src_port": 52648, "dest_ip": "134.19.61.215", "dest_port": 3391, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 95, "bytes_toclient": 0, "start": "2026-03-10T08:54:03.297430+0100", "src_ip": "198.235.24.213", "dest_ip": "134.19.61.215", "src_port": 52648, "dest_port": 3391}}'); INSERT INTO alerts VALUES(6568,1773129246.505728006,'{"timestamp": "2026-03-10T08:54:06.505728+0100", "flow_id": 1890611015480743, "event_type": "alert", "src_ip": "198.235.24.124", "src_port": 50192, "dest_ip": "134.19.61.215", "dest_port": 23756, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:54:06.505728+0100", "src_ip": "198.235.24.124", "dest_ip": "134.19.61.215", "src_port": 50192, "dest_port": 23756}}'); INSERT INTO alerts VALUES(6569,1773129255.859462976,'{"timestamp": "2026-03-10T08:54:15.859463+0100", "flow_id": 2002516323950722, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:54:15.859463+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6570,1773129255.859462976,'{"timestamp": "2026-03-10T08:54:15.859463+0100", "flow_id": 2002519572572422, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:54:15.859463+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6571,1773129255.859462976,'{"timestamp": "2026-03-10T08:54:15.859463+0100", "flow_id": 2002516511080160, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:54:15.859463+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6572,1773129256.304908991,'{"timestamp": "2026-03-10T08:54:16.304909+0100", "flow_id": 183675551682046, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 64301, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 31179, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:54:16.304909+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 64301, "dest_port": 53}}'); INSERT INTO alerts VALUES(6573,1773129256.304908991,'{"timestamp": "2026-03-10T08:54:16.304909+0100", "flow_id": 183675833276162, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 65196, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9441, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:54:16.304909+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 65196, "dest_port": 53}}'); INSERT INTO alerts VALUES(6574,1773129257.197932005,'{"timestamp": "2026-03-10T08:54:17.197932+0100", "flow_id": 287162402670599, "event_type": "alert", "src_ip": "103.4.167.13", "src_port": 57546, "dest_ip": "134.19.61.215", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:54:17.197932+0100", "src_ip": "103.4.167.13", "dest_ip": "134.19.61.215", "src_port": 57546, "dest_port": 1433}}'); INSERT INTO alerts VALUES(6575,1773129260.194806098,'{"timestamp": "2026-03-10T08:54:20.194806+0100", "flow_id": 287162402670599, "event_type": "alert", "src_ip": "103.4.167.13", "src_port": 57546, "dest_ip": "134.19.61.215", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 2, "pkts_toclient": 0, "bytes_toserver": 104, "bytes_toclient": 0, "start": "2026-03-10T08:54:17.197932+0100", "src_ip": "103.4.167.13", "dest_ip": "134.19.61.215", "src_port": 57546, "dest_port": 1433}}'); INSERT INTO alerts VALUES(6576,1773129269.873249053,'{"timestamp": "2026-03-10T08:54:29.873249+0100", "flow_id": 1498776220764877, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:54:29.873249+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6577,1773129269.874680043,'{"timestamp": "2026-03-10T08:54:29.874680+0100", "flow_id": 1504924298804316, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:54:29.874680+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6578,1773129293.041572094,'{"timestamp": "2026-03-10T08:54:53.041572+0100", "flow_id": 1585927634379430, "event_type": "alert", "src_ip": "130.12.180.95", "src_port": 60666, "dest_ip": "134.19.61.215", "dest_port": 49765, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:54:53.041572+0100", "src_ip": "130.12.180.95", "dest_ip": "134.19.61.215", "src_port": 60666, "dest_port": 49765}}'); INSERT INTO alerts VALUES(6579,1773129293.041572094,'{"timestamp": "2026-03-10T08:54:53.041572+0100", "flow_id": 1585927634379430, "event_type": "alert", "src_ip": "130.12.180.95", "src_port": 60666, "dest_ip": "134.19.61.215", "dest_port": 49765, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:54:53.041572+0100", "src_ip": "130.12.180.95", "dest_ip": "134.19.61.215", "src_port": 60666, "dest_port": 49765}}'); INSERT INTO alerts VALUES(6580,1773129293.041572094,'{"timestamp": "2026-03-10T08:54:53.041572+0100", "flow_id": 1585927634379430, "event_type": "alert", "src_ip": "130.12.180.95", "src_port": 60666, "dest_ip": "134.19.61.215", "dest_port": 49765, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500006, "rev": 7556, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:54:53.041572+0100", "src_ip": "130.12.180.95", "dest_ip": "134.19.61.215", "src_port": 60666, "dest_port": 49765}}'); INSERT INTO alerts VALUES(6581,1773129300.576113939,'{"timestamp": "2026-03-10T08:55:00.576114+0100", "flow_id": 1348491020110541, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:55:00.576114+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6582,1773129300.576114893,'{"timestamp": "2026-03-10T08:55:00.576115+0100", "flow_id": 1348497294916700, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:55:00.576115+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6583,1773129300.830794095,'{"timestamp": "2026-03-10T08:55:00.830794+0100", "flow_id": 1316436663738924, "event_type": "alert", "src_ip": "205.210.31.211", "src_port": 51756, "dest_ip": "134.19.61.215", "dest_port": 427, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:55:00.830794+0100", "src_ip": "205.210.31.211", "dest_ip": "134.19.61.215", "src_port": 51756, "dest_port": 427}}'); INSERT INTO alerts VALUES(6584,1773129311.171226978,'{"timestamp": "2026-03-10T08:55:11.171227+0100", "flow_id": 2142792184982717, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 50415, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56950, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:55:11.171227+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 50415, "dest_port": 53}}'); INSERT INTO alerts VALUES(6585,1773129331.99197507,'{"timestamp": "2026-03-10T08:55:31.991975+0100", "flow_id": 882800601107149, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:55:31.991975+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6586,1773129331.992752076,'{"timestamp": "2026-03-10T08:55:31.992752+0100", "flow_id": 886139770535004, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:55:31.992752+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6587,1773129337.328349114,'{"timestamp": "2026-03-10T08:55:37.328349+0100", "flow_id": 284348674918285, "event_type": "alert", "src_ip": "65.49.1.189", "src_port": 44300, "dest_ip": "134.19.61.215", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:55:37.328349+0100", "src_ip": "65.49.1.189", "dest_ip": "134.19.61.215", "src_port": 44300, "dest_port": 8888}}'); INSERT INTO alerts VALUES(6588,1773129339.533224106,'{"timestamp": "2026-03-10T08:55:39.533224+0100", "flow_id": 882805470775864, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50694, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44560, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:55:39.533224+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50694, "dest_port": 53}}'); INSERT INTO alerts VALUES(6589,1773129339.550848007,'{"timestamp": "2026-03-10T08:55:39.550848+0100", "flow_id": 958499925849131, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 48208, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58552, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:55:39.550848+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 48208, "dest_port": 53}}'); INSERT INTO alerts VALUES(6590,1773129351.303811073,'{"timestamp": "2026-03-10T08:55:51.303811+0100", "flow_id": 2149283510803126, "event_type": "alert", "src_ip": "167.94.145.24", "src_port": 54476, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-10T08:55:51.303811+0100", "src_ip": "167.94.145.24", "dest_ip": "134.19.61.215", "src_port": 54476, "dest_port": 3306}}'); INSERT INTO alerts VALUES(6591,1773129353.875546932,'{"timestamp": "2026-03-10T08:55:53.875547+0100", "flow_id": 382746727763348, "event_type": "alert", "src_ip": "176.65.149.234", "src_port": 32899, "dest_ip": "134.19.61.215", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:55:53.875547+0100", "src_ip": "176.65.149.234", "dest_ip": "134.19.61.215", "src_port": 32899, "dest_port": 80}}'); INSERT INTO alerts VALUES(6592,1773129353.875546932,'{"timestamp": "2026-03-10T08:55:53.875547+0100", "flow_id": 382746727763348, "event_type": "alert", "src_ip": "176.65.149.234", "src_port": 32899, "dest_ip": "134.19.61.215", "dest_port": 80, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:55:53.875547+0100", "src_ip": "176.65.149.234", "dest_ip": "134.19.61.215", "src_port": 32899, "dest_port": 80}}'); INSERT INTO alerts VALUES(6593,1773129359.911772012,'{"timestamp": "2026-03-10T08:55:59.911772+0100", "flow_id": 2227182250407359, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50477, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 37510, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:55:59.911772+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50477, "dest_port": 53}}'); INSERT INTO alerts VALUES(6594,1773129359.911772012,'{"timestamp": "2026-03-10T08:55:59.911772+0100", "flow_id": 2227185332090501, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59060, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14506, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:55:59.911772+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59060, "dest_port": 53}}'); INSERT INTO alerts VALUES(6595,1773129363.133801938,'{"timestamp": "2026-03-10T08:56:03.133802+0100", "flow_id": 856150329035469, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:56:03.133802+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6596,1773129363.134748935,'{"timestamp": "2026-03-10T08:56:03.134749+0100", "flow_id": 860219642903644, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:56:03.134749+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6597,1773129380.184684038,'{"timestamp": "2026-03-10T08:56:20.184684+0100", "flow_id": 1356163657958081, "event_type": "alert", "src_ip": "176.65.148.52", "src_port": 32854, "dest_ip": "134.19.61.215", "dest_port": 8080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:56:20.184684+0100", "src_ip": "176.65.148.52", "dest_ip": "134.19.61.215", "src_port": 32854, "dest_port": 8080}}'); INSERT INTO alerts VALUES(6598,1773129394.382394076,'{"timestamp": "2026-03-10T08:56:34.382394+0100", "flow_id": 797944932240077, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:56:34.382394+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6599,1773129394.382394076,'{"timestamp": "2026-03-10T08:56:34.382394+0100", "flow_id": 797946912078940, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:56:34.382394+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6600,1773129395.877120972,'{"timestamp": "2026-03-10T08:56:35.877121+0100", "flow_id": 952456949620866, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:56:35.877121+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6601,1773129395.877121926,'{"timestamp": "2026-03-10T08:56:35.877122+0100", "flow_id": 952464493209862, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:56:35.877122+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6602,1773129395.877121926,'{"timestamp": "2026-03-10T08:56:35.877122+0100", "flow_id": 952461431717600, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:56:35.877122+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6603,1773129410.636352062,'{"timestamp": "2026-03-10T08:56:50.636352+0100", "flow_id": 762789704466819, "event_type": "alert", "src_ip": "64.62.156.110", "src_port": 60308, "dest_ip": "134.19.61.215", "dest_port": 8888, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:56:50.636352+0100", "src_ip": "64.62.156.110", "dest_ip": "134.19.61.215", "src_port": 60308, "dest_port": 8888}}'); INSERT INTO alerts VALUES(6604,1773129425.829853058,'{"timestamp": "2026-03-10T08:57:05.829853+0100", "flow_id": 467966889855693, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:57:05.829853+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6605,1773129425.829854011,'{"timestamp": "2026-03-10T08:57:05.829854+0100", "flow_id": 467973164661852, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:57:05.829854+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6606,1773129425.87818098,'{"timestamp": "2026-03-10T08:57:05.878181+0100", "flow_id": 394059661533314, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:57:05.878181+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6607,1773129425.878181934,'{"timestamp": "2026-03-10T08:57:05.878182+0100", "flow_id": 394067205122310, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:57:05.878182+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6608,1773129426.16928792,'{"timestamp": "2026-03-10T08:57:06.169288+0100", "flow_id": 727087317827296, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:57:06.169288+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6609,1773129435.813384056,'{"timestamp": "2026-03-10T08:57:15.813384+0100", "flow_id": 960186997015208, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50094, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61353, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "setup.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T08:57:15.813384+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50094, "dest_port": 53}}'); INSERT INTO alerts VALUES(6610,1773129451.137300969,'{"timestamp": "2026-03-10T08:57:31.137301+0100", "flow_id": 871182019739778, "event_type": "alert", "src_ip": "46.151.182.45", "src_port": 44677, "dest_ip": "134.19.61.215", "dest_port": 1125, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:57:31.137301+0100", "src_ip": "46.151.182.45", "dest_ip": "134.19.61.215", "src_port": 44677, "dest_port": 1125}}'); INSERT INTO alerts VALUES(6611,1773129457.152066947,'{"timestamp": "2026-03-10T08:57:37.152067+0100", "flow_id": 371648522182786, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:57:37.152067+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6612,1773129457.152535915,'{"timestamp": "2026-03-10T08:57:37.152536+0100", "flow_id": 373666110466310, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:57:37.152536+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6613,1773129457.152535915,'{"timestamp": "2026-03-10T08:57:37.152536+0100", "flow_id": 373663048974048, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:57:37.152536+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6614,1773129474.897882938,'{"timestamp": "2026-03-10T08:57:54.897883+0100", "flow_id": 760155525423552, "event_type": "alert", "src_ip": "198.235.24.203", "src_port": 55733, "dest_ip": "134.19.61.215", "dest_port": 50003, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:57:54.897883+0100", "src_ip": "198.235.24.203", "dest_ip": "134.19.61.215", "src_port": 55733, "dest_port": 50003}}'); INSERT INTO alerts VALUES(6615,1773129478.990345001,'{"timestamp": "2026-03-10T08:57:58.990345+0100", "flow_id": 1720227883498636, "event_type": "alert", "src_ip": "130.12.180.95", "src_port": 40334, "dest_ip": "134.19.61.215", "dest_port": 1011, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2500006, "rev": 7556, "signature": "ET COMPROMISED Known Compromised or Hostile Host Traffic group 4", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2011_04_28"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["COMPROMISED"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T08:57:58.990345+0100", "src_ip": "130.12.180.95", "dest_ip": "134.19.61.215", "src_port": 40334, "dest_port": 1011}}'); INSERT INTO alerts VALUES(6616,1773129479.597493886,'{"timestamp": "2026-03-10T08:57:59.597494+0100", "flow_id": 2003271530697151, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 34849, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 46774, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:57:59.597494+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 34849, "dest_port": 53}}'); INSERT INTO alerts VALUES(6617,1773129479.597493886,'{"timestamp": "2026-03-10T08:57:59.597494+0100", "flow_id": 2003268464756963, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 36059, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 20146, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T08:57:59.597494+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 36059, "dest_port": 53}}'); INSERT INTO alerts VALUES(6618,1773129487.544251918,'{"timestamp": "2026-03-10T08:58:07.544252+0100", "flow_id": 2056070271164546, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:58:07.544252+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6619,1773129487.544253111,'{"timestamp": "2026-03-10T08:58:07.544253+0100", "flow_id": 2056077814753542, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:58:07.544253+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6620,1773129487.544253111,'{"timestamp": "2026-03-10T08:58:07.544253+0100", "flow_id": 2056074753261280, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:58:07.544253+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6621,1773129507.102993011,'{"timestamp": "2026-03-10T08:58:27.102993+0100", "flow_id": 1005304694551149, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55040, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52640, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T08:58:27.102993+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55040, "dest_port": 53}}'); INSERT INTO alerts VALUES(6622,1773129507.106961965,'{"timestamp": "2026-03-10T08:58:27.106962+0100", "flow_id": 1022351686318574, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54688, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29996, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T08:58:27.106962+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54688, "dest_port": 53}}'); INSERT INTO alerts VALUES(6623,1773129511.602008104,'{"timestamp": "2026-03-10T08:58:31.602008+0100", "flow_id": 2022655641627930, "event_type": "alert", "src_ip": "198.235.24.73", "dest_ip": "134.19.61.215", "proto": "ICMP", "ip_v": 4, "icmp_type": 8, "icmp_code": 0, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 48, "bytes_toclient": 0, "start": "2026-03-10T08:58:31.602008+0100", "src_ip": "198.235.24.73", "dest_ip": "134.19.61.215"}}'); INSERT INTO alerts VALUES(6624,1773129518.350172996,'{"timestamp": "2026-03-10T08:58:38.350173+0100", "flow_id": 1785457266745474, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:58:38.350173+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6625,1773129518.350173951,'{"timestamp": "2026-03-10T08:58:38.350174+0100", "flow_id": 1785464810334470, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:58:38.350174+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6626,1773129518.350173951,'{"timestamp": "2026-03-10T08:58:38.350174+0100", "flow_id": 1785461748842208, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:58:38.350174+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6627,1773129536.387370109,'{"timestamp": "2026-03-10T08:58:56.387370+0100", "flow_id": 256369051454463, "event_type": "alert", "src_ip": "66.132.153.144", "src_port": 36461, "dest_ip": "134.19.61.215", "dest_port": 161, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "snmp", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 92, "bytes_toclient": 0, "start": "2026-03-10T08:58:56.387370+0100", "src_ip": "66.132.153.144", "dest_ip": "134.19.61.215", "src_port": 36461, "dest_port": 161}}'); INSERT INTO alerts VALUES(6628,1773129546.995230914,'{"timestamp": "2026-03-10T08:59:06.995231+0100", "flow_id": 615312963638213, "event_type": "alert", "src_ip": "205.210.31.89", "src_port": 56549, "dest_ip": "134.19.61.215", "dest_port": 4567, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T08:59:06.995231+0100", "src_ip": "205.210.31.89", "dest_ip": "134.19.61.215", "src_port": 56549, "dest_port": 4567}}'); INSERT INTO alerts VALUES(6629,1773129570.968399048,'{"timestamp": "2026-03-10T08:59:30.968399+0100", "flow_id": 781542452136653, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:59:30.968399+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6630,1773129570.968400002,'{"timestamp": "2026-03-10T08:59:30.968400+0100", "flow_id": 781548726942812, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T08:59:30.968400+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6631,1773129585.692553997,'{"timestamp": "2026-03-10T08:59:45.692554+0100", "flow_id": 441222037363132, "event_type": "alert", "src_ip": "64.62.156.180", "src_port": 48929, "dest_ip": "134.19.61.215", "dest_port": 2031, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T08:59:45.692554+0100", "src_ip": "64.62.156.180", "dest_ip": "134.19.61.215", "src_port": 48929, "dest_port": 2031}}'); INSERT INTO alerts VALUES(6632,1773129588.110526085,'{"timestamp": "2026-03-10T08:59:48.110526+0100", "flow_id": 1319134418635931, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 58670, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18803, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T08:59:48.110526+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 58670, "dest_port": 53}}'); INSERT INTO alerts VALUES(6633,1773129604.005950928,'{"timestamp": "2026-03-10T09:00:04.005951+0100", "flow_id": 1151459964313730, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:00:04.005951+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6634,1773129604.005951882,'{"timestamp": "2026-03-10T09:00:04.005952+0100", "flow_id": 1151467507902726, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:00:04.005952+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6635,1773129604.005951882,'{"timestamp": "2026-03-10T09:00:04.005952+0100", "flow_id": 1151464446410464, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:00:04.005952+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6636,1773129607.719800949,'{"timestamp": "2026-03-10T09:00:07.719801+0100", "flow_id": 2247100357458597, "event_type": "alert", "src_ip": "147.185.132.118", "src_port": 53582, "dest_ip": "134.19.61.215", "dest_port": 50067, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T09:00:07.719801+0100", "src_ip": "147.185.132.118", "dest_ip": "134.19.61.215", "src_port": 53582, "dest_port": 50067}}'); INSERT INTO alerts VALUES(6637,1773129618.954684972,'{"timestamp": "2026-03-10T09:00:18.954685+0100", "flow_id": 722641824108677, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57347, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 41204, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T09:00:18.954685+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57347, "dest_port": 53}}'); INSERT INTO alerts VALUES(6638,1773129618.954684972,'{"timestamp": "2026-03-10T09:00:18.954685+0100", "flow_id": 722644138944441, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40342, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4652, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T09:00:18.954685+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40342, "dest_port": 53}}'); INSERT INTO alerts VALUES(6639,1773129618.954685927,'{"timestamp": "2026-03-10T09:00:18.954686+0100", "flow_id": 722648519333803, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 35804, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7045, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T09:00:18.954686+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 35804, "dest_port": 53}}'); INSERT INTO alerts VALUES(6640,1773129619.496948003,'{"timestamp": "2026-03-10T09:00:19.496948+0100", "flow_id": 1008477381392018, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57617, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 44511, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cloudflare-dns.com", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-10T09:00:19.496948+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57617, "dest_port": 53}}'); INSERT INTO alerts VALUES(6641,1773129619.680888891,'{"timestamp": "2026-03-10T09:00:19.680889+0100", "flow_id": 954074795331521, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42670, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T09:00:19.680889+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42670, "dest_port": 53}}'); INSERT INTO alerts VALUES(6642,1773129619.680890084,'{"timestamp": "2026-03-10T09:00:19.680890+0100", "flow_id": 954077479314152, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 60500, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5528, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T09:00:19.680890+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 60500, "dest_port": 53}}'); INSERT INTO alerts VALUES(6643,1773129621.327534914,'{"timestamp": "2026-03-10T09:00:21.327535+0100", "flow_id": 1688228168587853, "event_type": "alert", "src_ip": "147.185.132.46", "src_port": 24890, "dest_ip": "134.19.61.215", "dest_port": 17185, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "failed", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 92, "bytes_toclient": 0, "start": "2026-03-10T09:00:21.327535+0100", "src_ip": "147.185.132.46", "dest_ip": "134.19.61.215", "src_port": 24890, "dest_port": 17185}}'); INSERT INTO alerts VALUES(6644,1773129634.783334017,'{"timestamp": "2026-03-10T09:00:34.783334+0100", "flow_id": 831119828541570, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:00:34.783334+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6645,1773129634.783334017,'{"timestamp": "2026-03-10T09:00:34.783334+0100", "flow_id": 831123077163270, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:00:34.783334+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6646,1773129634.783334017,'{"timestamp": "2026-03-10T09:00:34.783334+0100", "flow_id": 831120015671008, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:00:34.783334+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6647,1773129650.822998046,'{"timestamp": "2026-03-10T09:00:50.822998+0100", "flow_id": 720002471937459, "event_type": "alert", "src_ip": "66.132.153.148", "src_port": 15555, "dest_ip": "134.19.61.215", "dest_port": 88, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "app_proto": "krb5", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 142, "bytes_toclient": 0, "start": "2026-03-10T09:00:50.822998+0100", "src_ip": "66.132.153.148", "dest_ip": "134.19.61.215", "src_port": 15555, "dest_port": 88}}'); INSERT INTO alerts VALUES(6648,1773129655.287822961,'{"timestamp": "2026-03-10T09:00:55.287823+0100", "flow_id": 2080615440353997, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:00:55.287823+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6649,1773129655.287822961,'{"timestamp": "2026-03-10T09:00:55.287823+0100", "flow_id": 2080617420192860, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:00:55.287823+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6650,1773129693.801512002,'{"timestamp": "2026-03-10T09:01:33.801512+0100", "flow_id": 1472143079461903, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60082, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63272, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T09:01:33.801512+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60082, "dest_port": 53}}'); INSERT INTO alerts VALUES(6651,1773129698.416331052,'{"timestamp": "2026-03-10T09:01:38.416331+0100", "flow_id": 564569475599637, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 38474, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:01:38.393593+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 38474, "dest_port": 853}}'); INSERT INTO alerts VALUES(6652,1773129701.416115045,'{"timestamp": "2026-03-10T09:01:41.416115+0100", "flow_id": 1417361323103801, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 41454, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:01:41.395541+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 41454, "dest_port": 853}}'); INSERT INTO alerts VALUES(6653,1773129702.118721009,'{"timestamp": "2026-03-10T09:01:42.118721+0100", "flow_id": 1917280679519940, "event_type": "alert", "src_ip": "222.178.189.184", "src_port": 36182, "dest_ip": "134.19.61.215", "dest_port": 1433, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010935, "rev": 3, "signature": "ET SCAN Suspicious inbound to MSSQL port 1433", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 52, "bytes_toclient": 0, "start": "2026-03-10T09:01:42.118721+0100", "src_ip": "222.178.189.184", "dest_ip": "134.19.61.215", "src_port": 36182, "dest_port": 1433}}'); INSERT INTO alerts VALUES(6654,1773129703.321463108,'{"timestamp": "2026-03-10T09:01:43.321463+0100", "flow_id": 2133592150281102, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 38490, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:01:43.300157+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 38490, "dest_port": 853}}'); INSERT INTO alerts VALUES(6655,1773129704.869663954,'{"timestamp": "2026-03-10T09:01:44.869664+0100", "flow_id": 76004448362626, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:01:44.869664+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6656,1773129704.869663954,'{"timestamp": "2026-03-10T09:01:44.869664+0100", "flow_id": 76007696984326, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:01:44.869664+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6657,1773129704.869663954,'{"timestamp": "2026-03-10T09:01:44.869664+0100", "flow_id": 76004635492064, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:01:44.869664+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6658,1773129706.334059001,'{"timestamp": "2026-03-10T09:01:46.334059+0100", "flow_id": 780012111025183, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 38504, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:01:46.312682+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 38504, "dest_port": 853}}'); INSERT INTO alerts VALUES(6659,1773129712.356633901,'{"timestamp": "2026-03-10T09:01:52.356634+0100", "flow_id": 29752675430321, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35140, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:01:52.334607+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 35140, "dest_port": 853}}'); INSERT INTO alerts VALUES(6660,1773129718.372493983,'{"timestamp": "2026-03-10T09:01:58.372494+0100", "flow_id": 1793421134916456, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35332, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:01:58.352027+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 35332, "dest_port": 853}}'); INSERT INTO alerts VALUES(6661,1773129719.15704298,'{"timestamp": "2026-03-10T09:01:59.157043+0100", "flow_id": 1991363074358399, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35334, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:01:59.135970+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 35334, "dest_port": 853}}'); INSERT INTO alerts VALUES(6662,1773129721.376425027,'{"timestamp": "2026-03-10T09:02:01.376425+0100", "flow_id": 403916980851506, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35338, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:02:01.356188+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 35338, "dest_port": 853}}'); INSERT INTO alerts VALUES(6663,1773129724.376996041,'{"timestamp": "2026-03-10T09:02:04.376996+0100", "flow_id": 1250120861096181, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 48962, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:02:04.356602+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 48962, "dest_port": 853}}'); INSERT INTO alerts VALUES(6664,1773129724.380748988,'{"timestamp": "2026-03-10T09:02:04.380749+0100", "flow_id": 1253531485835851, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35346, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:02:04.357396+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 35346, "dest_port": 853}}'); INSERT INTO alerts VALUES(6665,1773129726.816488981,'{"timestamp": "2026-03-10T09:02:06.816489+0100", "flow_id": 1817947887579955, "event_type": "alert", "src_ip": "205.210.31.74", "src_port": 50378, "dest_ip": "134.19.61.215", "dest_port": 5678, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T09:02:06.816489+0100", "src_ip": "205.210.31.74", "dest_ip": "134.19.61.215", "src_port": 50378, "dest_port": 5678}}'); INSERT INTO alerts VALUES(6666,1773129726.901766062,'{"timestamp": "2026-03-10T09:02:06.901766+0100", "flow_id": 1902731607327233, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 59467, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 65266, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmipalservice.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T09:02:06.901766+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 59467, "dest_port": 53}}'); INSERT INTO alerts VALUES(6667,1773129727.863727093,'{"timestamp": "2026-03-10T09:02:07.863727+0100", "flow_id": 2020830780827344, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57350, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33688, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:02:07.863727+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57350, "dest_port": 53}}'); INSERT INTO alerts VALUES(6668,1773129727.863727093,'{"timestamp": "2026-03-10T09:02:07.863727+0100", "flow_id": 2020831596898307, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53690, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 719, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:02:07.863727+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53690, "dest_port": 53}}'); INSERT INTO alerts VALUES(6669,1773129728.202405929,'{"timestamp": "2026-03-10T09:02:08.202406+0100", "flow_id": 24902266122734, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 63754, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28595, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "escrowproxy.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-10T09:02:08.202406+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 63754, "dest_port": 53}}'); INSERT INTO alerts VALUES(6670,1773129734.721353054,'{"timestamp": "2026-03-10T09:02:14.721353+0100", "flow_id": 1690816931264133, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59060, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14506, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:02:14.721353+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59060, "dest_port": 53}}'); INSERT INTO alerts VALUES(6671,1773129734.721353054,'{"timestamp": "2026-03-10T09:02:14.721353+0100", "flow_id": 1690813208099391, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65455, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33765, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:02:14.721353+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65455, "dest_port": 53}}'); INSERT INTO alerts VALUES(6672,1773129734.828607082,'{"timestamp": "2026-03-10T09:02:14.828607+0100", "flow_id": 1869991367899546, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54196, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11202, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:02:14.828607+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54196, "dest_port": 53}}'); INSERT INTO alerts VALUES(6673,1773129734.828608036,'{"timestamp": "2026-03-10T09:02:14.828608+0100", "flow_id": 1869995615119528, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59245, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 1646, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:02:14.828608+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59245, "dest_port": 53}}'); INSERT INTO alerts VALUES(6674,1773129736.998961925,'{"timestamp": "2026-03-10T09:02:16.998962+0100", "flow_id": 68386639417949, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 52011, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43662, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "fmf.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 67, "bytes_toclient": 0, "start": "2026-03-10T09:02:16.998962+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 52011, "dest_port": 53}}'); INSERT INTO alerts VALUES(6675,1773129739.552987099,'{"timestamp": "2026-03-10T09:02:19.552987+0100", "flow_id": 967688182760866, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54441, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T09:02:19.552987+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54441, "dest_port": 53}}'); INSERT INTO alerts VALUES(6676,1773129751.927938938,'{"timestamp": "2026-03-10T09:02:31.927939+0100", "flow_id": 2206460410329985, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 43262, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:02:31.906947+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 43262, "dest_port": 853}}'); INSERT INTO alerts VALUES(6677,1773129759.756372929,'{"timestamp": "2026-03-10T09:02:39.756373+0100", "flow_id": 2122698630849852, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 54001, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18891, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T09:02:39.756373+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 54001, "dest_port": 53}}'); INSERT INTO alerts VALUES(6678,1773129759.756928921,'{"timestamp": "2026-03-10T09:02:39.756929+0100", "flow_id": 2125085858009032, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 52264, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16316, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T09:02:39.756929+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 52264, "dest_port": 53}}'); INSERT INTO alerts VALUES(6679,1773129768.351814985,'{"timestamp": "2026-03-10T09:02:48.351815+0100", "flow_id": 103659742781570, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:02:48.351815+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6680,1773129768.351815938,'{"timestamp": "2026-03-10T09:02:48.351816+0100", "flow_id": 103667286370566, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:02:48.351816+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6681,1773129768.351815938,'{"timestamp": "2026-03-10T09:02:48.351816+0100", "flow_id": 103664224878304, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:02:48.351816+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6682,1773129772.243349075,'{"timestamp": "2026-03-10T09:02:52.243349+0100", "flow_id": 1326654679810152, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 54205, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 52951, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:02:52.243349+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 54205, "dest_port": 53}}'); INSERT INTO alerts VALUES(6683,1773129772.243350028,'{"timestamp": "2026-03-10T09:02:52.243350+0100", "flow_id": 1326656443160628, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58116, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40273, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:02:52.243350+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58116, "dest_port": 53}}'); INSERT INTO alerts VALUES(6684,1773129785.09813404,'{"timestamp": "2026-03-10T09:03:05.098134+0100", "flow_id": 421482458811085, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:03:05.098134+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6685,1773129785.09813404,'{"timestamp": "2026-03-10T09:03:05.098134+0100", "flow_id": 421484438649948, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:03:05.098134+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6686,1773129787.560328006,'{"timestamp": "2026-03-10T09:03:07.560328+0100", "flow_id": 999217541123935, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54720, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7445, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "emea-mask.wrr.me.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 76, "bytes_toclient": 0, "start": "2026-03-10T09:03:07.560328+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54720, "dest_port": 53}}'); INSERT INTO alerts VALUES(6687,1773129813.875327111,'{"timestamp": "2026-03-10T09:03:33.875327+0100", "flow_id": 1507704539974162, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58954, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 13418, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:03:33.875327+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58954, "dest_port": 53}}'); INSERT INTO alerts VALUES(6688,1773129813.875328063,'{"timestamp": "2026-03-10T09:03:33.875328+0100", "flow_id": 1507707960986521, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62214, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 36484, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:03:33.875328+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62214, "dest_port": 53}}'); INSERT INTO alerts VALUES(6689,1773129814.878082037,'{"timestamp": "2026-03-10T09:03:34.878082+0100", "flow_id": 1801010392072038, "event_type": "alert", "src_ip": "176.65.139.41", "src_port": 50000, "dest_ip": "134.19.61.215", "dest_port": 3000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400032, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 33", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T09:03:34.878082+0100", "src_ip": "176.65.139.41", "dest_ip": "134.19.61.215", "src_port": 50000, "dest_port": 3000}}'); INSERT INTO alerts VALUES(6690,1773129816.221709013,'{"timestamp": "2026-03-10T09:03:36.221709+0100", "flow_id": 107808112282317, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:03:36.221709+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6691,1773129816.221709967,'{"timestamp": "2026-03-10T09:03:36.221710+0100", "flow_id": 107814387088476, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:03:36.221710+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6692,1773129830.705440044,'{"timestamp": "2026-03-10T09:03:50.705440+0100", "flow_id": 1903945014158785, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 62564, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28956, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:03:50.705440+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 62564, "dest_port": 53}}'); INSERT INTO alerts VALUES(6693,1773129833.157802104,'{"timestamp": "2026-03-10T09:03:53.157802+0100", "flow_id": 396280956216895, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 60994, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40138, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T09:03:53.157802+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 60994, "dest_port": 53}}'); INSERT INTO alerts VALUES(6694,1773129833.158816099,'{"timestamp": "2026-03-10T09:03:53.158816+0100", "flow_id": 400636419489169, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 57387, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64481, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask-api.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 72, "bytes_toclient": 0, "start": "2026-03-10T09:03:53.158816+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 57387, "dest_port": 53}}'); INSERT INTO alerts VALUES(6695,1773129847.460789919,'{"timestamp": "2026-03-10T09:04:07.460790+0100", "flow_id": 1979078118509261, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:04:07.460790+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6696,1773129847.460789919,'{"timestamp": "2026-03-10T09:04:07.460790+0100", "flow_id": 1979080098348124, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:04:07.460790+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6697,1773129859.389636994,'{"timestamp": "2026-03-10T09:04:19.389637+0100", "flow_id": 1110528925982850, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:04:19.389637+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6698,1773129859.389636994,'{"timestamp": "2026-03-10T09:04:19.389637+0100", "flow_id": 1110532174604550, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:04:19.389637+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6699,1773129859.389637947,'{"timestamp": "2026-03-10T09:04:19.389638+0100", "flow_id": 1110533408079584, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:04:19.389638+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6700,1773129862.242371082,'{"timestamp": "2026-03-10T09:04:22.242371+0100", "flow_id": 1885402995393116, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 50012, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 42704, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:04:22.242371+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 50012, "dest_port": 53}}'); INSERT INTO alerts VALUES(6701,1773129862.242371082,'{"timestamp": "2026-03-10T09:04:22.242371+0100", "flow_id": 1885403586836457, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56586, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 64284, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:04:22.242371+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56586, "dest_port": 53}}'); INSERT INTO alerts VALUES(6702,1773129878.91104889,'{"timestamp": "2026-03-10T09:04:38.911049+0100", "flow_id": 1942600961264333, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:04:38.911049+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6703,1773129878.91104889,'{"timestamp": "2026-03-10T09:04:38.911049+0100", "flow_id": 1942602941103196, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:04:38.911049+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6704,1773129880.505865098,'{"timestamp": "2026-03-10T09:04:40.505865+0100", "flow_id": 202351352286641, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 42685, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400006, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 7", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:04:40.505865+0100", "src_ip": "45.153.34.32", "dest_ip": "134.19.61.215", "src_port": 42685, "dest_port": 3306}}'); INSERT INTO alerts VALUES(6705,1773129880.505865098,'{"timestamp": "2026-03-10T09:04:40.505865+0100", "flow_id": 202351352286641, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 42685, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:04:40.505865+0100", "src_ip": "45.153.34.32", "dest_ip": "134.19.61.215", "src_port": 42685, "dest_port": 3306}}'); INSERT INTO alerts VALUES(6706,1773129880.505865098,'{"timestamp": "2026-03-10T09:04:40.505865+0100", "flow_id": 202351352286641, "event_type": "alert", "src_ip": "45.153.34.32", "src_port": 42685, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:04:40.505865+0100", "src_ip": "45.153.34.32", "dest_ip": "134.19.61.215", "src_port": 42685, "dest_port": 3306}}'); INSERT INTO alerts VALUES(6707,1773129910.026242018,'{"timestamp": "2026-03-10T09:05:10.026242+0100", "flow_id": 1801558530230989, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:05:10.026242+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6708,1773129910.026242018,'{"timestamp": "2026-03-10T09:05:10.026242+0100", "flow_id": 1801560510069852, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:05:10.026242+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6709,1773129925.21308589,'{"timestamp": "2026-03-10T09:05:25.213086+0100", "flow_id": 1478148596398579, "event_type": "alert", "src_ip": "193.163.125.113", "src_port": 39059, "dest_ip": "134.19.61.215", "dest_port": 9898, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T09:05:25.213086+0100", "src_ip": "193.163.125.113", "dest_ip": "134.19.61.215", "src_port": 39059, "dest_port": 9898}}'); INSERT INTO alerts VALUES(6710,1773129933.951733112,'{"timestamp": "2026-03-10T09:05:33.951733+0100", "flow_id": 1554388026220674, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:05:33.951733+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6711,1773129933.951734066,'{"timestamp": "2026-03-10T09:05:33.951734+0100", "flow_id": 1554395569809670, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:05:33.951734+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6712,1773129933.951734066,'{"timestamp": "2026-03-10T09:05:33.951734+0100", "flow_id": 1554392508317408, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:05:33.951734+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6713,1773129941.525047063,'{"timestamp": "2026-03-10T09:05:41.525047+0100", "flow_id": 1410634901916365, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:05:41.525047+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6714,1773129941.525047063,'{"timestamp": "2026-03-10T09:05:41.525047+0100", "flow_id": 1410636881755228, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:05:41.525047+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6715,1773129965.203221082,'{"timestamp": "2026-03-10T09:06:05.203221+0100", "flow_id": 1435778209374338, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:06:05.203221+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6716,1773129965.203222036,'{"timestamp": "2026-03-10T09:06:05.203222+0100", "flow_id": 1435785752963334, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:06:05.203222+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6717,1773129965.203222036,'{"timestamp": "2026-03-10T09:06:05.203222+0100", "flow_id": 1435782691471072, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:06:05.203222+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6718,1773129973.023657083,'{"timestamp": "2026-03-10T09:06:13.023657+0100", "flow_id": 1508981063060173, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:06:13.023657+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6719,1773129973.024959087,'{"timestamp": "2026-03-10T09:06:13.024959+0100", "flow_id": 1514575090318428, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:06:13.024959+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6720,1773129996.266886949,'{"timestamp": "2026-03-10T09:06:36.266887+0100", "flow_id": 1146274852762378, "event_type": "alert", "src_ip": "91.224.92.125", "src_port": 48894, "dest_ip": "134.19.61.215", "dest_port": 6036, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400013, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 14", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:06:36.266887+0100", "src_ip": "91.224.92.125", "dest_ip": "134.19.61.215", "src_port": 48894, "dest_port": 6036}}'); INSERT INTO alerts VALUES(6721,1773130003.369534015,'{"timestamp": "2026-03-10T09:06:43.369534+0100", "flow_id": 1024186629524173, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:06:43.369534+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6722,1773130003.369534015,'{"timestamp": "2026-03-10T09:06:43.369534+0100", "flow_id": 1024188609363036, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:06:43.369534+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6723,1773130033.649597884,'{"timestamp": "2026-03-10T09:07:13.649598+0100", "flow_id": 538202490047181, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:07:13.649598+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6724,1773130033.649597884,'{"timestamp": "2026-03-10T09:07:13.649598+0100", "flow_id": 538204469886044, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:07:13.649598+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6725,1773130035.362405062,'{"timestamp": "2026-03-10T09:07:15.362405+0100", "flow_id": 993569996495294, "event_type": "alert", "src_ip": "65.49.1.41", "src_port": 52858, "dest_ip": "134.19.61.215", "dest_port": 6080, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:07:15.362405+0100", "src_ip": "65.49.1.41", "dest_ip": "134.19.61.215", "src_port": 52858, "dest_port": 6080}}'); INSERT INTO alerts VALUES(6726,1773130047.120340109,'{"timestamp": "2026-03-10T09:07:27.120340+0100", "flow_id": 2121808574430779, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 45488, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:07:27.100806+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 45488, "dest_port": 853}}'); INSERT INTO alerts VALUES(6727,1773130048.26905489,'{"timestamp": "2026-03-10T09:07:28.269055+0100", "flow_id": 29683226075266, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:07:28.269055+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6728,1773130048.269056081,'{"timestamp": "2026-03-10T09:07:28.269056+0100", "flow_id": 29690769664262, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:07:28.269056+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6729,1773130048.269056081,'{"timestamp": "2026-03-10T09:07:28.269056+0100", "flow_id": 29687708172000, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:07:28.269056+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6730,1773130069.064454079,'{"timestamp": "2026-03-10T09:07:49.064454+0100", "flow_id": 1684203253430847, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 65455, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33765, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:07:49.064454+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 65455, "dest_port": 53}}'); INSERT INTO alerts VALUES(6731,1773130069.064454079,'{"timestamp": "2026-03-10T09:07:49.064454+0100", "flow_id": 1684205191836666, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50608, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48376, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:07:49.064454+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50608, "dest_port": 53}}'); INSERT INTO alerts VALUES(6732,1773130069.064455032,'{"timestamp": "2026-03-10T09:07:49.064455+0100", "flow_id": 1684208900693495, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 52977, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21763, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:07:49.064455+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 52977, "dest_port": 53}}'); INSERT INTO alerts VALUES(6733,1773130069.064455032,'{"timestamp": "2026-03-10T09:07:49.064455+0100", "flow_id": 1684209073006147, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 54165, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 4457, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:07:49.064455+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 54165, "dest_port": 53}}'); INSERT INTO alerts VALUES(6734,1773130079.353389979,'{"timestamp": "2026-03-10T09:07:59.353390+0100", "flow_id": 2080749153247362, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:07:59.353390+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6735,1773130079.353390932,'{"timestamp": "2026-03-10T09:07:59.353391+0100", "flow_id": 2080756696836358, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:07:59.353391+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6736,1773130079.353390932,'{"timestamp": "2026-03-10T09:07:59.353391+0100", "flow_id": 2080753635344096, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:07:59.353391+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6737,1773130089.870848894,'{"timestamp": "2026-03-10T09:08:09.870849+0100", "flow_id": 362572264433262, "event_type": "alert", "src_ip": "66.132.153.154", "src_port": 9865, "dest_ip": "134.19.61.215", "dest_port": 831, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-10T09:08:09.870849+0100", "src_ip": "66.132.153.154", "dest_ip": "134.19.61.215", "src_port": 9865, "dest_port": 831}}'); INSERT INTO alerts VALUES(6738,1773130091.44916606,'{"timestamp": "2026-03-10T09:08:11.449166+0100", "flow_id": 1084730177919890, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 56225, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53149, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:08:11.449166+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 56225, "dest_port": 53}}'); INSERT INTO alerts VALUES(6739,1773130093.120407104,'{"timestamp": "2026-03-10T09:08:13.120407+0100", "flow_id": 1643048011473609, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 58088, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 56106, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:08:13.120407+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 58088, "dest_port": 53}}'); INSERT INTO alerts VALUES(6740,1773130093.124279023,'{"timestamp": "2026-03-10T09:08:13.124279+0100", "flow_id": 1659675500776343, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 51725, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 43993, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:08:13.124279+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 51725, "dest_port": 53}}'); INSERT INTO alerts VALUES(6741,1773130113.41672206,'{"timestamp": "2026-03-10T09:08:33.416722+0100", "flow_id": 382432616155853, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:08:33.416722+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6742,1773130113.41672206,'{"timestamp": "2026-03-10T09:08:33.416722+0100", "flow_id": 382434595994716, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:08:33.416722+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6743,1773130137.980199099,'{"timestamp": "2026-03-10T09:08:57.980199+0100", "flow_id": 550751819151615, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 64558, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48228, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:08:57.980199+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 64558, "dest_port": 53}}'); INSERT INTO alerts VALUES(6744,1773130140.316853046,'{"timestamp": "2026-03-10T09:09:00.316853+0100", "flow_id": 1360873774369381, "event_type": "alert", "src_ip": "64.89.160.135", "src_port": 58000, "dest_ip": "134.19.61.215", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400007, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 8", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:09:00.316853+0100", "src_ip": "64.89.160.135", "dest_ip": "134.19.61.215", "src_port": 58000, "dest_port": 22}}'); INSERT INTO alerts VALUES(6745,1773130147.127007962,'{"timestamp": "2026-03-10T09:09:07.127008+0100", "flow_id": 1108445297937101, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 60876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14005, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:09:07.127008+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 60876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6746,1773130147.127008915,'{"timestamp": "2026-03-10T09:09:07.127009+0100", "flow_id": 1108451572743260, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 63111, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 61867, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:09:07.127009+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 63111, "dest_port": 53}}'); INSERT INTO alerts VALUES(6747,1773130147.127008915,'{"timestamp": "2026-03-10T09:09:07.127009+0100", "flow_id": 1108450837783954, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 57181, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8966, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:09:07.127009+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 57181, "dest_port": 53}}'); INSERT INTO alerts VALUES(6748,1773130147.127008915,'{"timestamp": "2026-03-10T09:09:07.127009+0100", "flow_id": 1108453276379401, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59607, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 14918, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:09:07.127009+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59607, "dest_port": 53}}'); INSERT INTO alerts VALUES(6749,1773130161.957896948,'{"timestamp": "2026-03-10T09:09:21.957897+0100", "flow_id": 358764992490158, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35328, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:09:21.935499+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 35328, "dest_port": 853}}'); INSERT INTO alerts VALUES(6750,1773130164.957326889,'{"timestamp": "2026-03-10T09:09:24.957327+0100", "flow_id": 1207081188100492, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35330, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:09:24.936405+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 35330, "dest_port": 853}}'); INSERT INTO alerts VALUES(6751,1773130167.96614194,'{"timestamp": "2026-03-10T09:09:27.966142+0100", "flow_id": 2090483864063313, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 58156, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:09:27.945480+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 58156, "dest_port": 853}}'); INSERT INTO alerts VALUES(6752,1773130170.977680921,'{"timestamp": "2026-03-10T09:09:30.977681+0100", "flow_id": 733191965736449, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35634, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:09:30.957141+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 35634, "dest_port": 853}}'); INSERT INTO alerts VALUES(6753,1773130172.906378985,'{"timestamp": "2026-03-10T09:09:32.906379+0100", "flow_id": 1359595364387981, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59860, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16582, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:09:32.906379+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59860, "dest_port": 53}}'); INSERT INTO alerts VALUES(6754,1773130172.907433032,'{"timestamp": "2026-03-10T09:09:32.907433+0100", "flow_id": 1364123457015319, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56498, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51278, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:09:32.907433+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56498, "dest_port": 53}}'); INSERT INTO alerts VALUES(6755,1773130174.870012998,'{"timestamp": "2026-03-10T09:09:34.870013+0100", "flow_id": 1948475303777897, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 35642, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:09:34.846880+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 35642, "dest_port": 853}}'); INSERT INTO alerts VALUES(6756,1773130176.998037099,'{"timestamp": "2026-03-10T09:09:36.998037+0100", "flow_id": 256660986436522, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 42910, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:09:36.977262+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 42910, "dest_port": 853}}'); INSERT INTO alerts VALUES(6757,1773130180.886507034,'{"timestamp": "2026-03-10T09:09:40.886507+0100", "flow_id": 1178713233169226, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 56542, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:09:40.864264+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 56542, "dest_port": 853}}'); INSERT INTO alerts VALUES(6758,1773130183.018657923,'{"timestamp": "2026-03-10T09:09:43.018658+0100", "flow_id": 1735499000620332, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 44452, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:09:42.993901+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 44452, "dest_port": 853}}'); INSERT INTO alerts VALUES(6759,1773130186.905602931,'{"timestamp": "2026-03-10T09:09:46.905603+0100", "flow_id": 696457954857978, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 56558, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:09:46.883052+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 56558, "dest_port": 853}}'); INSERT INTO alerts VALUES(6760,1773130198.939964057,'{"timestamp": "2026-03-10T09:09:58.939964+0100", "flow_id": 1696203159204169, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 49666, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:09:58.919216+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 49666, "dest_port": 853}}'); INSERT INTO alerts VALUES(6761,1773130199.216773034,'{"timestamp": "2026-03-10T09:09:59.216773+0100", "flow_id": 2056935220779475, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 55112, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 8179, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:09:59.216773+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 55112, "dest_port": 53}}'); INSERT INTO alerts VALUES(6762,1773130199.218318939,'{"timestamp": "2026-03-10T09:09:59.218319+0100", "flow_id": 2063576293206707, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49490, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 26512, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:09:59.218319+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49490, "dest_port": 53}}'); INSERT INTO alerts VALUES(6763,1773130215.523600102,'{"timestamp": "2026-03-10T09:10:15.523600+0100", "flow_id": 2248846992672575, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 55165, "dest_ip": "134.19.61.215", "dest_port": 9000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400011, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 12", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:10:15.523600+0100", "src_ip": "87.121.84.57", "dest_ip": "134.19.61.215", "src_port": 55165, "dest_port": 9000}}'); INSERT INTO alerts VALUES(6764,1773130215.523600102,'{"timestamp": "2026-03-10T09:10:15.523600+0100", "flow_id": 2248846992672575, "event_type": "alert", "src_ip": "87.121.84.57", "src_port": 55165, "dest_ip": "134.19.61.215", "dest_port": 9000, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:10:15.523600+0100", "src_ip": "87.121.84.57", "dest_ip": "134.19.61.215", "src_port": 55165, "dest_port": 9000}}'); INSERT INTO alerts VALUES(6765,1773130223.008675098,'{"timestamp": "2026-03-10T09:10:23.008675+0100", "flow_id": 1711243096352485, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 56198, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:10:22.988253+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 56198, "dest_port": 853}}'); INSERT INTO alerts VALUES(6766,1773130235.923640967,'{"timestamp": "2026-03-10T09:10:35.923641+0100", "flow_id": 870783851520130, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:10:35.923641+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6767,1773130235.92364192,'{"timestamp": "2026-03-10T09:10:35.923642+0100", "flow_id": 870791395109126, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:10:35.923642+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6768,1773130235.92364192,'{"timestamp": "2026-03-10T09:10:35.923642+0100", "flow_id": 870788333616864, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:10:35.923642+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6769,1773130247.078691006,'{"timestamp": "2026-03-10T09:10:47.078691+0100", "flow_id": 2211275646462893, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 56554, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:10:47.056100+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 56554, "dest_port": 853}}'); INSERT INTO alerts VALUES(6770,1773130266.647742033,'{"timestamp": "2026-03-10T09:11:06.647742+0100", "flow_id": 811706576363650, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:11:06.647742+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6771,1773130266.647742033,'{"timestamp": "2026-03-10T09:11:06.647742+0100", "flow_id": 811709824985350, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:11:06.647742+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6772,1773130266.647742986,'{"timestamp": "2026-03-10T09:11:06.647743+0100", "flow_id": 811711058460384, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:11:06.647743+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6773,1773130295.208525896,'{"timestamp": "2026-03-10T09:11:35.208526+0100", "flow_id": 2215365235199071, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 38938, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:11:35.188124+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 38938, "dest_port": 853}}'); INSERT INTO alerts VALUES(6774,1773130298.078771115,'{"timestamp": "2026-03-10T09:11:38.078771+0100", "flow_id": 619794552676482, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:11:38.078771+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6775,1773130298.078771115,'{"timestamp": "2026-03-10T09:11:38.078771+0100", "flow_id": 619797801298182, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:11:38.078771+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6776,1773130298.078771115,'{"timestamp": "2026-03-10T09:11:38.078771+0100", "flow_id": 619794739805920, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:11:38.078771+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6777,1773130308.778656005,'{"timestamp": "2026-03-10T09:11:48.778656+0100", "flow_id": 1373979704046586, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50608, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 48376, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:11:48.778656+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50608, "dest_port": 53}}'); INSERT INTO alerts VALUES(6778,1773130308.778656005,'{"timestamp": "2026-03-10T09:11:48.778656+0100", "flow_id": 1373980531103357, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 64233, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 63723, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:11:48.778656+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 64233, "dest_port": 53}}'); INSERT INTO alerts VALUES(6779,1773130308.778656005,'{"timestamp": "2026-03-10T09:11:48.778656+0100", "flow_id": 1373977615718694, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 53555, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45898, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:11:48.778656+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 53555, "dest_port": 53}}'); INSERT INTO alerts VALUES(6780,1773130308.778656005,'{"timestamp": "2026-03-10T09:11:48.778656+0100", "flow_id": 1373978780511246, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 63953, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 40179, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:11:48.778656+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 63953, "dest_port": 53}}'); INSERT INTO alerts VALUES(6781,1773130309.41980195,'{"timestamp": "2026-03-10T09:11:49.419802+0100", "flow_id": 1521564251361480, "event_type": "alert", "src_ip": "193.163.125.115", "src_port": 58232, "dest_ip": "134.19.61.215", "dest_port": 2096, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T09:11:49.419802+0100", "src_ip": "193.163.125.115", "dest_ip": "134.19.61.215", "src_port": 58232, "dest_port": 2096}}'); INSERT INTO alerts VALUES(6782,1773130318.601603985,'{"timestamp": "2026-03-10T09:11:58.601604+0100", "flow_id": 1739447381971983, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 56792, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 25056, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:11:58.601604+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 56792, "dest_port": 53}}'); INSERT INTO alerts VALUES(6783,1773130322.523426055,'{"timestamp": "2026-03-10T09:12:02.523426+0100", "flow_id": 840725548373948, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 56999, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53727, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T09:12:02.523426+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 56999, "dest_port": 53}}'); INSERT INTO alerts VALUES(6784,1773130327.128000975,'{"timestamp": "2026-03-10T09:12:07.128001+0100", "flow_id": 2238610515908162, "event_type": "alert", "src_ip": "79.124.62.134", "src_port": 48673, "dest_ip": "134.19.61.215", "dest_port": 32164, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400009, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 10", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:12:07.128001+0100", "src_ip": "79.124.62.134", "dest_ip": "134.19.61.215", "src_port": 48673, "dest_port": 32164}}'); INSERT INTO alerts VALUES(6785,1773130329.362839938,'{"timestamp": "2026-03-10T09:12:09.362840+0100", "flow_id": 432486733930626, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:12:09.362840+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6786,1773130329.362839938,'{"timestamp": "2026-03-10T09:12:09.362840+0100", "flow_id": 432489982552326, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:12:09.362840+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6787,1773130329.362839938,'{"timestamp": "2026-03-10T09:12:09.362840+0100", "flow_id": 432486921060064, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:12:09.362840+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6788,1773130331.587332011,'{"timestamp": "2026-03-10T09:12:11.587332+0100", "flow_id": 1115199971774129, "event_type": "alert", "src_ip": "185.242.226.87", "src_port": 45546, "dest_ip": "134.19.61.215", "dest_port": 9005, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T09:12:11.587332+0100", "src_ip": "185.242.226.87", "dest_ip": "134.19.61.215", "src_port": 45546, "dest_port": 9005}}'); INSERT INTO alerts VALUES(6789,1773130343.339607955,'{"timestamp": "2026-03-10T09:12:23.339608+0100", "flow_id": 2213805928121622, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 52408, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:12:23.318833+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 52408, "dest_port": 853}}'); INSERT INTO alerts VALUES(6790,1773130360.612483025,'{"timestamp": "2026-03-10T09:12:40.612483+0100", "flow_id": 97320371052674, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:12:40.612483+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6791,1773130360.612483025,'{"timestamp": "2026-03-10T09:12:40.612483+0100", "flow_id": 97323619674374, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:12:40.612483+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6792,1773130360.612483025,'{"timestamp": "2026-03-10T09:12:40.612483+0100", "flow_id": 97320558182112, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:12:40.612483+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6793,1773130370.399389982,'{"timestamp": "2026-03-10T09:12:50.399390+0100", "flow_id": 589469073509517, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59860, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 16582, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:12:50.399390+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59860, "dest_port": 53}}'); INSERT INTO alerts VALUES(6794,1773130370.399389982,'{"timestamp": "2026-03-10T09:12:50.399390+0100", "flow_id": 589470270606871, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 56498, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 51278, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:12:50.399390+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 56498, "dest_port": 53}}'); INSERT INTO alerts VALUES(6795,1773130370.399390936,'{"timestamp": "2026-03-10T09:12:50.399391+0100", "flow_id": 589472332699053, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55531, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58298, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:12:50.399391+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55531, "dest_port": 53}}'); INSERT INTO alerts VALUES(6796,1773130370.399390936,'{"timestamp": "2026-03-10T09:12:50.399391+0100", "flow_id": 589473383418822, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53653, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32007, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:12:50.399391+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53653, "dest_port": 53}}'); INSERT INTO alerts VALUES(6797,1773130375.844271898,'{"timestamp": "2026-03-10T09:12:55.844272+0100", "flow_id": 2218749175732462, "event_type": "alert", "src_ip": "205.210.31.255", "src_port": 57057, "dest_ip": "134.19.61.215", "dest_port": 55918, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 44, "bytes_toclient": 0, "start": "2026-03-10T09:12:55.844272+0100", "src_ip": "205.210.31.255", "dest_ip": "134.19.61.215", "src_port": 57057, "dest_port": 55918}}'); INSERT INTO alerts VALUES(6798,1773130376.877465963,'{"timestamp": "2026-03-10T09:12:56.877466+0100", "flow_id": 109516642135545, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 64899, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5448, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:12:56.877466+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 64899, "dest_port": 53}}'); INSERT INTO alerts VALUES(6799,1773130376.877465963,'{"timestamp": "2026-03-10T09:12:56.877466+0100", "flow_id": 109516534659252, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 61176, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 10160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:12:56.877466+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 61176, "dest_port": 53}}'); INSERT INTO alerts VALUES(6800,1773130392.016988992,'{"timestamp": "2026-03-10T09:13:12.016989+0100", "flow_id": 72967906484354, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:13:12.016989+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6801,1773130392.016988992,'{"timestamp": "2026-03-10T09:13:12.016989+0100", "flow_id": 72971155106054, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:13:12.016989+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6802,1773130392.018348933,'{"timestamp": "2026-03-10T09:13:12.018349+0100", "flow_id": 78809249136352, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:13:12.018349+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6803,1773130400.217150927,'{"timestamp": "2026-03-10T09:13:20.217151+0100", "flow_id": 88234456098554, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.61.215", "dest_port": 42392, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:13:20.217151+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.61.215", "src_port": 52302, "dest_port": 42392}}'); INSERT INTO alerts VALUES(6804,1773130400.217150927,'{"timestamp": "2026-03-10T09:13:20.217151+0100", "flow_id": 88234456098554, "event_type": "alert", "src_ip": "130.12.180.88", "src_port": 52302, "dest_ip": "134.19.61.215", "dest_port": 42392, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:13:20.217151+0100", "src_ip": "130.12.180.88", "dest_ip": "134.19.61.215", "src_port": 52302, "dest_port": 42392}}'); INSERT INTO alerts VALUES(6805,1773130422.708589076,'{"timestamp": "2026-03-10T09:13:42.708589+0100", "flow_id": 1917467381555330, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:13:42.708589+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6806,1773130422.708589076,'{"timestamp": "2026-03-10T09:13:42.708589+0100", "flow_id": 1917470630177030, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:13:42.708589+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6807,1773130422.708590031,'{"timestamp": "2026-03-10T09:13:42.708590+0100", "flow_id": 1917471863652064, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:13:42.708590+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6808,1773130439.598429919,'{"timestamp": "2026-03-10T09:13:59.598430+0100", "flow_id": 2198728860345808, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 41364, "dest_ip": "185.95.218.42", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:13:59.577467+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.42", "src_port": 41364, "dest_port": 853}}'); INSERT INTO alerts VALUES(6809,1773130454.203072071,'{"timestamp": "2026-03-10T09:14:14.203072+0100", "flow_id": 1716613235957890, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:14:14.203072+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6810,1773130454.203072071,'{"timestamp": "2026-03-10T09:14:14.203072+0100", "flow_id": 1716616484579590, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:14:14.203072+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6811,1773130454.203072071,'{"timestamp": "2026-03-10T09:14:14.203072+0100", "flow_id": 1716613423087328, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:14:14.203072+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6812,1773130514.785893917,'{"timestamp": "2026-03-10T09:15:14.785894+0100", "flow_id": 842114944819330, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:15:14.785894+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6813,1773130514.78589511,'{"timestamp": "2026-03-10T09:15:14.785895+0100", "flow_id": 842122488408326, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:15:14.785895+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6814,1773130514.78589511,'{"timestamp": "2026-03-10T09:15:14.785895+0100", "flow_id": 842119426916064, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:15:14.785895+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6815,1773130528.267486096,'{"timestamp": "2026-03-10T09:15:28.267486+0100", "flow_id": 22944671520173, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 55531, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 58298, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:15:28.267486+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 55531, "dest_port": 53}}'); INSERT INTO alerts VALUES(6816,1773130528.274674893,'{"timestamp": "2026-03-10T09:15:28.274675+0100", "flow_id": 53822242130886, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 53653, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32007, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:15:28.274675+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 53653, "dest_port": 53}}'); INSERT INTO alerts VALUES(6817,1773130528.282535077,'{"timestamp": "2026-03-10T09:15:28.282535+0100", "flow_id": 87580055559462, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 59257, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38726, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:15:28.282535+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 59257, "dest_port": 53}}'); INSERT INTO alerts VALUES(6818,1773130528.29010892,'{"timestamp": "2026-03-10T09:15:28.290109+0100", "flow_id": 120110173897387, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 50550, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 30911, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:15:28.290109+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 50550, "dest_port": 53}}'); INSERT INTO alerts VALUES(6819,1773130528.958287001,'{"timestamp": "2026-03-10T09:15:28.958287+0100", "flow_id": 175162176212396, "event_type": "alert", "src_ip": "192.168.2.37", "src_port": 54089, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22978, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:15:28.958287+0100", "src_ip": "192.168.2.37", "dest_ip": "192.168.2.1", "src_port": 54089, "dest_port": 53}}'); INSERT INTO alerts VALUES(6820,1773130535.859323978,'{"timestamp": "2026-03-10T09:15:35.859324+0100", "flow_id": 2191096744028207, "event_type": "alert", "src_ip": "134.19.61.215", "src_port": 57368, "dest_ip": "185.95.218.43", "dest_port": 853, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786435, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked TLS Connection", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "ts_progress": "client_hello_done", "tc_progress": "server_in_progress", "tls": {"sni": "dns.digitale-gesellschaft.ch", "version": "TLS 1.3", "ja3": {"hash": "d5fc4cb6dc9483feba85243354b4bc25", "string": "771,4866-4867-4865-49196-49200-159-52393-52392-52394-49195-49199-158-49188-49192-107-49187-49191-103-49162-49172-57-49161-49171-51-157-156-61-60-53-47,65281-0-11-10-35-22-23-13-43-45-51-27,4588-29-23-30-24-25-256-257,0"}, "ja4": "t13d301200_1d37bd780c83_ecd0401ec68b"}, "app_proto": "tls", "direction": "to_server", "flow": {"pkts_toserver": 4, "pkts_toclient": 1, "bytes_toserver": 1782, "bytes_toclient": 60, "start": "2026-03-10T09:15:35.837834+0100", "src_ip": "134.19.61.215", "dest_ip": "185.95.218.43", "src_port": 57368, "dest_port": 853}}'); INSERT INTO alerts VALUES(6821,1773130545.167774916,'{"timestamp": "2026-03-10T09:15:45.167775+0100", "flow_id": 439113868468354, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:15:45.167775+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6822,1773130545.167774916,'{"timestamp": "2026-03-10T09:15:45.167775+0100", "flow_id": 439117117090054, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:15:45.167775+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6823,1773130545.167776107,'{"timestamp": "2026-03-10T09:15:45.167776+0100", "flow_id": 439118350565088, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:15:45.167776+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6824,1773130551.817559958,'{"timestamp": "2026-03-10T09:15:51.817560+0100", "flow_id": 2104020334619299, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 49555, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 9758, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T09:15:51.817560+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 49555, "dest_port": 53}}'); INSERT INTO alerts VALUES(6825,1773130551.817560911,'{"timestamp": "2026-03-10T09:15:51.817561+0100", "flow_id": 2104023177143515, "event_type": "alert", "src_ip": "192.168.2.20", "src_port": 53084, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22244, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "quota.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 69, "bytes_toclient": 0, "start": "2026-03-10T09:15:51.817561+0100", "src_ip": "192.168.2.20", "dest_ip": "192.168.2.1", "src_port": 53084, "dest_port": 53}}'); INSERT INTO alerts VALUES(6826,1773130575.177978992,'{"timestamp": "2026-03-10T09:16:15.177979+0100", "flow_id": 2171789575020674, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:16:15.177979+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6827,1773130575.178363085,'{"timestamp": "2026-03-10T09:16:15.178363+0100", "flow_id": 2173442091084038, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:16:15.178363+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6828,1773130575.178363085,'{"timestamp": "2026-03-10T09:16:15.178363+0100", "flow_id": 2173439029591776, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:16:15.178363+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6829,1773130589.630126,'{"timestamp": "2026-03-10T09:16:29.630126+0100", "flow_id": 1580473754588108, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39596, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17278, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T09:16:29.630126+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39596, "dest_port": 53}}'); INSERT INTO alerts VALUES(6830,1773130589.630126,'{"timestamp": "2026-03-10T09:16:29.630126+0100", "flow_id": 1580473861801265, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 47789, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 18277, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T09:16:29.630126+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 47789, "dest_port": 53}}'); INSERT INTO alerts VALUES(6831,1773130592.350847005,'{"timestamp": "2026-03-10T09:16:32.350847+0100", "flow_id": 99502175588935, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 50699, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 11484, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T09:16:32.350847+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 50699, "dest_port": 53}}'); INSERT INTO alerts VALUES(6832,1773130592.350847005,'{"timestamp": "2026-03-10T09:16:32.350847+0100", "flow_id": 99501785548089, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51183, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 62322, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T09:16:32.350847+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51183, "dest_port": 53}}'); INSERT INTO alerts VALUES(6833,1773130592.350847005,'{"timestamp": "2026-03-10T09:16:32.350847+0100", "flow_id": 99504552040331, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 57568, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 23991, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T09:16:32.350847+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 57568, "dest_port": 53}}'); INSERT INTO alerts VALUES(6834,1773130592.681603908,'{"timestamp": "2026-03-10T09:16:32.681604+0100", "flow_id": 112717269507011, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51641, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 22298, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cloudflare-dns.com", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-10T09:16:32.681604+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51641, "dest_port": 53}}'); INSERT INTO alerts VALUES(6835,1773130606.031980992,'{"timestamp": "2026-03-10T09:16:46.031981+0100", "flow_id": 1826209896850302, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60507, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 28233, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:16:46.031981+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60507, "dest_port": 53}}'); INSERT INTO alerts VALUES(6836,1773130625.608035087,'{"timestamp": "2026-03-10T09:17:05.608035+0100", "flow_id": 359693272089428, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 57515, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 32956, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:17:05.608035+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 57515, "dest_port": 53}}'); INSERT INTO alerts VALUES(6837,1773130641.095458985,'{"timestamp": "2026-03-10T09:17:21.095459+0100", "flow_id": 409995012332332, "event_type": "alert", "src_ip": "64.62.197.24", "src_port": 55842, "dest_ip": "134.19.61.215", "dest_port": 9001, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:17:21.095459+0100", "src_ip": "64.62.197.24", "dest_ip": "134.19.61.215", "src_port": 55842, "dest_port": 9001}}'); INSERT INTO alerts VALUES(6838,1773130668.418802022,'{"timestamp": "2026-03-10T09:17:48.418802+0100", "flow_id": 1235791647170690, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:17:48.418802+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6839,1773130668.418802022,'{"timestamp": "2026-03-10T09:17:48.418802+0100", "flow_id": 1235794895792390, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:17:48.418802+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6840,1773130668.418802022,'{"timestamp": "2026-03-10T09:17:48.418802+0100", "flow_id": 1235791834300128, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:17:48.418802+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6841,1773130683.239104987,'{"timestamp": "2026-03-10T09:18:03.239105+0100", "flow_id": 1026949070830233, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59367, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59707, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:18:03.239105+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59367, "dest_port": 53}}'); INSERT INTO alerts VALUES(6842,1773130689.563421964,'{"timestamp": "2026-03-10T09:18:09.563422+0100", "flow_id": 449554771713047, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61294, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 17743, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:18:09.563422+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61294, "dest_port": 53}}'); INSERT INTO alerts VALUES(6843,1773130693.537764073,'{"timestamp": "2026-03-10T09:18:13.537764+0100", "flow_id": 1465255861463102, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59859, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53885, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:18:13.537764+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59859, "dest_port": 53}}'); INSERT INTO alerts VALUES(6844,1773130699.657367945,'{"timestamp": "2026-03-10T09:18:19.657368+0100", "flow_id": 853049931554946, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:18:19.657368+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6845,1773130699.657368898,'{"timestamp": "2026-03-10T09:18:19.657369+0100", "flow_id": 853057475143942, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:18:19.657369+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6846,1773130699.657368898,'{"timestamp": "2026-03-10T09:18:19.657369+0100", "flow_id": 853054413651680, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:18:19.657369+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6847,1773130701.652896881,'{"timestamp": "2026-03-10T09:18:21.652897+0100", "flow_id": 1678274207964948, "event_type": "alert", "src_ip": "199.45.154.190", "src_port": 57745, "dest_ip": "134.19.61.215", "dest_port": 3306, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2010937, "rev": 3, "signature": "ET SCAN Suspicious inbound to mySQL port 3306", "category": "Potentially Bad Traffic", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-10T09:18:21.652897+0100", "src_ip": "199.45.154.190", "dest_ip": "134.19.61.215", "src_port": 57745, "dest_port": 3306}}'); INSERT INTO alerts VALUES(6848,1773130711.742228031,'{"timestamp": "2026-03-10T09:18:31.742228+0100", "flow_id": 2061946637768277, "event_type": "alert", "src_ip": "64.62.197.188", "src_port": 32981, "dest_ip": "134.19.61.215", "dest_port": 8123, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:18:31.742228+0100", "src_ip": "64.62.197.188", "dest_ip": "134.19.61.215", "src_port": 32981, "dest_port": 8123}}'); INSERT INTO alerts VALUES(6849,1773130728.180862904,'{"timestamp": "2026-03-10T09:18:48.180863+0100", "flow_id": 213852651503108, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 48337, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 54469, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T09:18:48.180863+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 48337, "dest_port": 53}}'); INSERT INTO alerts VALUES(6850,1773130728.180862904,'{"timestamp": "2026-03-10T09:18:48.180863+0100", "flow_id": 213851802240478, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 47447, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 50155, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T09:18:48.180863+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 47447, "dest_port": 53}}'); INSERT INTO alerts VALUES(6851,1773130728.181868076,'{"timestamp": "2026-03-10T09:18:48.181868+0100", "flow_id": 218170331217833, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 37496, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 59966, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T09:18:48.181868+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 37496, "dest_port": 53}}'); INSERT INTO alerts VALUES(6852,1773130728.724102021,'{"timestamp": "2026-03-10T09:18:48.724102+0100", "flow_id": 13771685657304, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 40553, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 39525, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cloudflare-dns.com", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-10T09:18:48.724102+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 40553, "dest_port": 53}}'); INSERT INTO alerts VALUES(6853,1773130729.677009106,'{"timestamp": "2026-03-10T09:18:49.677009+0100", "flow_id": 374457430794370, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:18:49.677009+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6854,1773130729.677009106,'{"timestamp": "2026-03-10T09:18:49.677009+0100", "flow_id": 374460679416070, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:18:49.677009+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6855,1773130729.67701006,'{"timestamp": "2026-03-10T09:18:49.677010+0100", "flow_id": 374461912891104, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:18:49.677010+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6856,1773130730.64508295,'{"timestamp": "2026-03-10T09:18:50.645083+0100", "flow_id": 800287586014686, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 55049, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 29647, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T09:18:50.645083+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 55049, "dest_port": 53}}'); INSERT INTO alerts VALUES(6857,1773130730.64508295,'{"timestamp": "2026-03-10T09:18:50.645083+0100", "flow_id": 800289061149552, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 51278, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 5149, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T09:18:50.645083+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 51278, "dest_port": 53}}'); INSERT INTO alerts VALUES(6858,1773130752.461539031,'{"timestamp": "2026-03-10T09:19:12.461539+0100", "flow_id": 11971140454304, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61466, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7408, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:19:12.461539+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61466, "dest_port": 53}}'); INSERT INTO alerts VALUES(6859,1773130759.698059082,'{"timestamp": "2026-03-10T09:19:19.698059+0100", "flow_id": 2153716352639106, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:19:19.698059+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6860,1773130759.698060035,'{"timestamp": "2026-03-10T09:19:19.698060+0100", "flow_id": 2153723896228102, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:19:19.698060+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6861,1773130759.699029923,'{"timestamp": "2026-03-10T09:19:19.699030+0100", "flow_id": 2157886953012960, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:19:19.699030+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6862,1773130777.755337954,'{"timestamp": "2026-03-10T09:19:37.755338+0100", "flow_id": 429404238948414, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59859, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 53885, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:19:37.755338+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59859, "dest_port": 53}}'); INSERT INTO alerts VALUES(6863,1773130777.755338908,'{"timestamp": "2026-03-10T09:19:37.755339+0100", "flow_id": 429410414041402, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 59876, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 27491, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:19:37.755339+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 59876, "dest_port": 53}}'); INSERT INTO alerts VALUES(6864,1773130790.854603052,'{"timestamp": "2026-03-10T09:19:50.854603+0100", "flow_id": 1700167806181506, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:19:50.854603+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6865,1773130790.854603052,'{"timestamp": "2026-03-10T09:19:50.854603+0100", "flow_id": 1700171054803206, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:19:50.854603+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6866,1773130790.854604006,'{"timestamp": "2026-03-10T09:19:50.854604+0100", "flow_id": 1700172288278240, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:19:50.854604+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6867,1773130812.559479952,'{"timestamp": "2026-03-10T09:20:12.559480+0100", "flow_id": 1277048848995277, "event_type": "alert", "src_ip": "192.168.2.36", "src_port": 50998, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 19035, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:20:12.559480+0100", "src_ip": "192.168.2.36", "dest_ip": "192.168.2.1", "src_port": 50998, "dest_port": 53}}'); INSERT INTO alerts VALUES(6868,1773130816.706566096,'{"timestamp": "2026-03-10T09:20:16.706566+0100", "flow_id": 219928765016178, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 65324, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 45716, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:20:16.706566+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 65324, "dest_port": 53}}'); INSERT INTO alerts VALUES(6869,1773130852.652714968,'{"timestamp": "2026-03-10T09:20:52.652715+0100", "flow_id": 1396016379815306, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43202, "dest_ip": "192.168.1.66", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2001219, "rev": 20, "signature": "ET SCAN Potential SSH Scan", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-10T09:20:52.652715+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.1.66", "src_port": 43202, "dest_port": 22}}'); INSERT INTO alerts VALUES(6870,1773130852.652714968,'{"timestamp": "2026-03-10T09:20:52.652715+0100", "flow_id": 1396016379815306, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43202, "dest_ip": "192.168.1.66", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2003068, "rev": 7, "signature": "ET SCAN Potential SSH Scan OUTBOUND", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 60, "bytes_toclient": 0, "start": "2026-03-10T09:20:52.652715+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.1.66", "src_port": 43202, "dest_port": 22}}'); INSERT INTO alerts VALUES(6871,1773130855.966507912,'{"timestamp": "2026-03-10T09:20:55.966508+0100", "flow_id": 2180796121440386, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:20:55.966508+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6872,1773130855.966507912,'{"timestamp": "2026-03-10T09:20:55.966508+0100", "flow_id": 2180799370062086, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:20:55.966508+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6873,1773130855.966507912,'{"timestamp": "2026-03-10T09:20:55.966508+0100", "flow_id": 2180796308569824, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:20:55.966508+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6874,1773130857.791728973,'{"timestamp": "2026-03-10T09:20:57.791729+0100", "flow_id": 1396016379815306, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43202, "dest_ip": "192.168.1.66", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2003068, "rev": 7, "signature": "ET SCAN Potential SSH Scan OUTBOUND", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 6, "pkts_toclient": 0, "bytes_toserver": 360, "bytes_toclient": 0, "start": "2026-03-10T09:20:52.652715+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.1.66", "src_port": 43202, "dest_port": 22}}'); INSERT INTO alerts VALUES(6875,1773130864.864748002,'{"timestamp": "2026-03-10T09:21:04.864748+0100", "flow_id": 54890910737883, "event_type": "alert", "src_ip": "130.12.180.175", "src_port": 45092, "dest_ip": "134.19.61.215", "dest_port": 767, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2400023, "rev": 4641, "signature": "ET DROP Spamhaus DROP Listed Traffic Inbound group 24", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Minor"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:21:04.864748+0100", "src_ip": "130.12.180.175", "dest_ip": "134.19.61.215", "src_port": 45092, "dest_port": 767}}'); INSERT INTO alerts VALUES(6876,1773130864.864748002,'{"timestamp": "2026-03-10T09:21:04.864748+0100", "flow_id": 54890910737883, "event_type": "alert", "src_ip": "130.12.180.175", "src_port": 45092, "dest_ip": "134.19.61.215", "dest_port": 767, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DROPIP", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:21:04.864748+0100", "src_ip": "130.12.180.175", "dest_ip": "134.19.61.215", "src_port": 45092, "dest_port": 767}}'); INSERT INTO alerts VALUES(6877,1773130867.231817961,'{"timestamp": "2026-03-10T09:21:07.231818+0100", "flow_id": 995651635323574, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 39361, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 60160, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T09:21:07.231818+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 39361, "dest_port": 53}}'); INSERT INTO alerts VALUES(6878,1773130867.231868982,'{"timestamp": "2026-03-10T09:21:07.231869+0100", "flow_id": 995871532676771, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42215, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 49169, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T09:21:07.231869+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42215, "dest_port": 53}}'); INSERT INTO alerts VALUES(6879,1773130867.231919051,'{"timestamp": "2026-03-10T09:21:07.231919+0100", "flow_id": 996087430925648, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43210, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2051767, "rev": 1, "signature": "ET INFO Observed DNS Query to Cloudflare Developer Domain (workers .dev)", "category": "Misc activity", "severity": 3, "metadata": {"affected_product": ["Any"], "attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_03_22"], "deployment": ["Perimeter"], "malware_family": ["Cloudflare_Workers"], "performance_impact": ["Low"], "signature_severity": ["Informational"], "tag": ["Cloudflare_Workers"], "updated_at": ["2026_03_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 21512, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "json-update-button.eytvd.workers.dev", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 93, "bytes_toclient": 0, "start": "2026-03-10T09:21:07.231919+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 43210, "dest_port": 53}}'); INSERT INTO alerts VALUES(6880,1773130867.57770896,'{"timestamp": "2026-03-10T09:21:07.577709+0100", "flow_id": 1073867778510605, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 55392, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 7017, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "cloudflare-dns.com", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 75, "bytes_toclient": 0, "start": "2026-03-10T09:21:07.577709+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 55392, "dest_port": 53}}'); INSERT INTO alerts VALUES(6881,1773130870.598510027,'{"timestamp": "2026-03-10T09:21:10.598510+0100", "flow_id": 1726156462996212, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 42606, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 24688, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T09:21:10.598510+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 42606, "dest_port": 53}}'); INSERT INTO alerts VALUES(6882,1773130870.598510027,'{"timestamp": "2026-03-10T09:21:10.598510+0100", "flow_id": 1726158793978125, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 44677, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 2053281, "rev": 1, "signature": "ET INFO Commonly Actor Abused Online Service Domain (syncthing .net)", "category": "Misc activity", "severity": 3, "metadata": {"attack_target": ["Client_Endpoint"], "confidence": ["High"], "created_at": ["2024_06_06"], "deployment": ["Perimeter"], "signature_severity": ["Informational"], "tag": ["Description_Generated_By_Proofpoint_Nexus"], "updated_at": ["2024_06_06"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34036, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "relays.syncthing.net", "rrtype": "AAAA"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 77, "bytes_toclient": 0, "start": "2026-03-10T09:21:10.598510+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.2.1", "src_port": 44677, "dest_port": 53}}'); INSERT INTO alerts VALUES(6883,1773130875.710808993,'{"timestamp": "2026-03-10T09:21:15.710809+0100", "flow_id": 1082577405599421, "event_type": "alert", "src_ip": "64.62.197.52", "src_port": 54668, "dest_ip": "134.19.61.215", "dest_port": 8088, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "metadata": {"flowbits": ["ET.Evil", "ET.DshieldIP"]}, "alert": {"action": "blocked", "gid": 1, "signature_id": 2402000, "rev": 7673, "signature": "ET DROP Dshield Block Listed Source group 1", "category": "Misc Attack", "severity": 2, "metadata": {"affected_product": ["Any"], "attack_target": ["Any"], "created_at": ["2010_12_30"], "deployment": ["Perimeter"], "signature_severity": ["Major"], "tag": ["Dshield"], "updated_at": ["2026_03_09"]}}, "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 40, "bytes_toclient": 0, "start": "2026-03-10T09:21:15.710809+0100", "src_ip": "64.62.197.52", "dest_ip": "134.19.61.215", "src_port": 54668, "dest_port": 8088}}'); INSERT INTO alerts VALUES(6884,1773130879.688082934,'{"timestamp": "2026-03-10T09:21:19.688083+0100", "flow_id": 2110869456606844, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 61633, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 38804, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:21:19.688083+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 61633, "dest_port": 53}}'); INSERT INTO alerts VALUES(6885,1773130919.811302901,'{"timestamp": "2026-03-10T09:21:59.811303+0100", "flow_id": 2077145675686018, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 53728, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 33078, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "gateway.fe2.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 71, "bytes_toclient": 0, "start": "2026-03-10T09:21:59.811303+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 53728, "dest_port": 53}}'); INSERT INTO alerts VALUES(6886,1773130919.811302901,'{"timestamp": "2026-03-10T09:21:59.811303+0100", "flow_id": 2077148924307718, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 60395, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 914, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "HTTPS"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:21:59.811303+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 60395, "dest_port": 53}}'); INSERT INTO alerts VALUES(6887,1773130919.811302901,'{"timestamp": "2026-03-10T09:21:59.811303+0100", "flow_id": 2077145862815456, "event_type": "alert", "src_ip": "192.168.2.22", "src_port": 54556, "dest_ip": "192.168.2.1", "dest_port": 53, "proto": "UDP", "ip_v": 4, "pkt_src": "wire/pcap", "tx_id": 0, "alert": {"action": "blocked", "gid": 1, "signature_id": 406786433, "rev": 1, "signature": "IPFire DBL [DNS-over-HTTPS] Blocked DNS Query", "category": "Potential Corporate Privacy Violation", "severity": 2, "metadata": {"dbl": ["doh.dbl.ipfire.org"]}}, "dns": {"version": 3, "type": "request", "tx_id": 0, "id": 34926, "flags": "100", "rd": true, "opcode": 0, "rcode": "NOERROR", "queries": [{"rrname": "mask.apple-dns.net", "rrtype": "A"}]}, "app_proto": "dns", "direction": "to_server", "flow": {"pkts_toserver": 1, "pkts_toclient": 0, "bytes_toserver": 64, "bytes_toclient": 0, "start": "2026-03-10T09:21:59.811303+0100", "src_ip": "192.168.2.22", "dest_ip": "192.168.2.1", "src_port": 54556, "dest_port": 53}}'); INSERT INTO alerts VALUES(6888,1773130920.832602977,'{"timestamp": "2026-03-10T09:22:00.832603+0100", "flow_id": 1396016379815306, "event_type": "alert", "src_ip": "192.168.2.16", "src_port": 43202, "dest_ip": "192.168.1.66", "dest_port": 22, "proto": "TCP", "ip_v": 4, "pkt_src": "wire/pcap", "alert": {"action": "blocked", "gid": 1, "signature_id": 2003068, "rev": 7, "signature": "ET SCAN Potential SSH Scan OUTBOUND", "category": "Attempted Information Leak", "severity": 2, "metadata": {"confidence": ["Medium"], "created_at": ["2010_07_30"], "signature_severity": ["Informational"], "updated_at": ["2019_07_26"]}}, "direction": "to_server", "flow": {"pkts_toserver": 11, "pkts_toclient": 0, "bytes_toserver": 660, "bytes_toclient": 0, "start": "2026-03-10T09:20:52.652715+0100", "src_ip": "192.168.2.16", "dest_ip": "192.168.1.66", "src_port": 43202, "dest_port": 22}}'); ANALYZE sqlite_schema; INSERT INTO sqlite_stat1 VALUES('alerts','alerts_timestamp','359 2'); CREATE INDEX alerts_timestamp ON alerts(timestamp); COMMIT;