AWS Network Firewall Now Supports Stateful Rule Hit Counts
AWS Network Firewall introduces hit counts for stateful rules, enabling network administrators to monitor rule activity and improve policy visibility
AWS Network Firewall now includes hit counts for stateful rules, allowing administrators to see how often each rule matches traffic. This feature helps identify active rules, uncover policy gaps, and verify new rule deployments. Hit counts are enabled by default for both custom and managed rule groups, with metrics updating every five minutes. The capability is provided at no extra charge, though standard logging costs apply. It is available in all supported AWS regions except the Middle East (UAE) and Middle East (Bahrain) regions
Why it matters
This update targets network administrators and security engineers, helping them monitor firewall policy effectiveness and identify issues