I know that ERSpan Type 1 is enabled by default in Suricata 6.0.9.
Does the decoder statement still need to be in suricata.yaml?
This command returns an empty line currently:
grep decoder.erspan stats.log
I guess because the line does not appear in the file at this time.
If it should I’ll add it.
If it is no longer necessary, is there a way to get erspan stats?