Currently, the approach used by some users is to reconstruct packets. See this discussion, which links to an open-source implementation that does this, I think: Update on ICAP integration proposal: Working implementation of SSLproxy (icap branch) & icapsuricata (libsuricata service) - #3 by Soner_Tari.
This has come up a few times in the past, so I was surprised we didn’t have a specific feature request for it. I created one here: Feature #9150: libsuricata: support stream input without synthetic packets - Suricata - Open Information Security Foundation
Note that this isn’t on the near-term roadmap.