In the Suricata config file under the Eve log section there that mentions tagged packets. Are they talking about VLAN tags or is this used for something else like http://manual-snort-org.s3-website-us-east-1.amazonaws.com/node34.html#SECTION00475000000000000000
Enable the logging of tagged packets for rules using the
“tag” keyword.
tagged-packets: yes
Thanks!