Does Suricata detect non-decapsulated VXLAN traffic?

We are mirroring traffic to Suricata (5.0.2) via VXLAN. Our rules include detect all non-TLS and detect all UDP. We are seeing alerts for UDP VXLAN traffic.

What is the Suricata behaviour?

  1. Detection rules run only on decapsulated VXLAN traffic
  2. Detection rules run on non-decapsulated VXLAN and decapsulated VXLAN traffic
  3. Detection rules run only on non-decapsulated VXLAN traffic