Hello Suricata Community,
I am currently using Suricata version 7.0.1 and running it in DPDK mode. I have encountered an issue where all the logs in
eve.json are missing VLAN id information. I have tried configuring the
vlan: use-for-tracking setting in
suricata.yaml both to
false, but neither configuration seems to resolve the issue.
Additionally, it’s important to note that the traffic I am capturing includes both single-layer and double-layer VLAN tagged traffic. Despite this, no VLAN tags are being logged in
Could someone please help me understand why the VLAN tags are not being captured in the logs? Is there a specific configuration I am missing, or is this a known issue with running Suricata in DPDK mode?
Any insights or suggestions would be greatly appreciated.
Thank you in advance for your assistance.