Hello Suricata Community,
I am currently using Suricata version 7.0.1 and running it in DPDK mode. I have encountered an issue where all the logs in eve.json are missing VLAN id information. I have tried configuring the vlan: use-for-tracking setting in suricata.yaml both to true and false, but neither configuration seems to resolve the issue.
Additionally, it’s important to note that the traffic I am capturing includes both single-layer and double-layer VLAN tagged traffic. Despite this, no VLAN tags are being logged in eve.json.
Could someone please help me understand why the VLAN tags are not being captured in the logs? Is there a specific configuration I am missing, or is this a known issue with running Suricata in DPDK mode?
Any insights or suggestions would be greatly appreciated.
Thank you in advance for your assistance.