Tagged packet Logging

In the Suricata config file under the Eve log section there that mentions tagged packets. Are they talking about VLAN tags or is this used for something else like http://manual-snort-org.s3-website-us-east-1.amazonaws.com/node34.html#SECTION00475000000000000000

Enable the logging of tagged packets for rules using the
“tag” keyword.
tagged-packets: yes


1 Like

This refers to the packets tagged with the tag rule keyword, not vlan tagging.

Ok, I didn’t see any documentation about it for Suricata but I remembered it from Snort. Just verifying that it was that same thing.