We are getting this message quite often emanating from our DNS servers (they use Google's DNS servers for lookup, 8.8.8.8), not necessarily from particular clients. What IP address does it say that it's contacting? The users could be using custom DNS entries which might be getting tagged as suspicious. I have yet to find any conclusive evidence that this is anything but a 'keep an eye out for some suspicious activity' type of message.
Has anyone else had these messages, or know where we can get more information for Snort events?