Chris
class=SNORT "-" groupby:sig_msg ("10.2.x.x" or "10.27.*.*" or "10.28.*.*" or "10.30.*.*" or "10.31.6.*" or "10.4.*.*")
class=BRO_DNS dstport="53" groupby:query_class ("10.2.x.x" or "10.27.*.*" or "10.28.*.*" or "10.30.*.*" or "10.31.6.*" or "10.4.*.*")