Suricata and TLS Termination: how to log the original src and dst

Well if you have Suricata positioned after the tls termination happened and the connection is just seen between those two 127.x.y.z IPs without the initial SRC in the package, I see no way how Suricata would magically know the initial SRC IP.

Do you see the initial SRC IP within the pcap?