AWS Network Firewall Stateful (Suricata) rules not working - Pass TLS only

No, that is not possible with Suricata. The TCP session needs to be established before the TLS session starts its establishment process.