Hello Suricata Community,
I am currently using Suricata version 7.0.1 and running it in DPDK mode. I have encountered an issue where all the logs in eve.json
are missing VLAN id information. I have tried configuring the vlan: use-for-tracking
setting in suricata.yaml
both to true
and false
, but neither configuration seems to resolve the issue.
Additionally, it’s important to note that the traffic I am capturing includes both single-layer and double-layer VLAN tagged traffic. Despite this, no VLAN tags are being logged in eve.json
.
Could someone please help me understand why the VLAN tags are not being captured in the logs? Is there a specific configuration I am missing, or is this a known issue with running Suricata in DPDK mode?
Any insights or suggestions would be greatly appreciated.
Thank you in advance for your assistance.