Simply forwarding 10Gb/s is a tall order. Decapsulating 10Gb/s of l2tp I think is probably some way off. Doing all that plus logging full packets, nope.
What do you actually need to log? Full packets? Flows? Sampled packets? Can the traffic be split up to multiple machines?