GRE de - encapsulation
Virtualisation is a very common approach in data centers, but for monitoring purposes it is somehow not so easy, because the network communication within the hyper visor is not transported over the physical NIC in the server, it is transported over the virtual switch. Thus, there is no access to this traffic.
It is common to use virtual taps to solve this issue. But this virtual taps can not send out the traffic straight, they use in most cases a GRE tunnel.
GRE is a L2 transparent tunnel.