Why would a crawler coming from Google netblock show up as malevolent?
Playing with snort and get this:
TCP Detection of a Network Scan SRC 188.8.131.52 Dest IP X.X.X.X Port 80 1:2015527 ET WEB_SERVER Fake Googlebot UA 2 Inbound
But it seems that this space in 66.249.x.x is a known Google block.
I am using Community & Emerging
Disable the broken rule. And while at it, disable 1:2015526, same idiocy.