# Packetless Application layer interface

**URL:** <https://forum.suricata.io/t/packetless-application-layer-interface/6477>\
**Category:** Developers\
**Tags:** community, rules, suricata\
**Created:** [September 30, 2026, 5:32pm UTC](https://forum.suricata.io/t/packetless-application-layer-interface/6477 "2026-09-30T17:32:40Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![cvontela\_microsoft](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/cvontela_microsoft/32/3973_2.png) [@cvontela\_microsoft](https://forum.suricata.io/u/cvontela_microsoft)\
**Post date:** [September 30, 2026, 5:32pm UTC](https://forum.suricata.io/t/packetless-application-layer-interface/6477/1 "2026-09-30T17:32:40Z")

</div>

Hi Developers,

I am evaluating Suricata to provide IDPS for traffic from L3-L7 and I see the drawback is it only accepts packet level input. In our scenario where TLS termination happens later after L3/4 inspection and proxy receives already reassembled data, the original IP/TCP packet level info is no longer available.

Does Suricata or libsuricata currently provide or plan to provide an interface where an application can submit byte streams or transactions for L7 IDPS inspection? We would like Suricata to perform its normal application protocol detection, L7 parsing, transaction tracking and signature evaluation without requiring raw IP packets or Suricata’s TCP reassembly path.

Thank you in advance for your time and guidance!
