New feature

AWS Network Firewall Now Supports Stateful Rule Hit Counts

AWS Network Firewall introduces hit counts for stateful rules, enabling network administrators to monitor rule activity and improve policy visibility

AWS Network Firewall now includes hit counts for stateful rules, allowing administrators to see how often each rule matches traffic. This feature helps identify active rules, uncover policy gaps, and verify new rule deployments. Hit counts are enabled by default for both custom and managed rule groups, with metrics updating every five minutes. The capability is provided at no extra charge, though standard logging costs apply. It is available in all supported AWS regions except the Middle East (UAE) and Middle East (Bahrain) regions

Why it matters

This update targets network administrators and security engineers, helping them monitor firewall policy effectiveness and identify issues

Read the original AWS announcement