AWS Network Firewall now supports rule hit count
Security Blog
AWS Network Firewall now supports rule hit count, enabling security teams to track how often stateful rules match traffic for identifying unused rules, validating compliance controls, and accelerating incident response.
- Rule hit counts track how often each stateful rule matches network traffic and generates alert logs
- Hit counter increments for rules with alert, drop, or reject actions; pass rules require alert keyword to appear in metrics
- Alert logs include AWS metadata with resource ARN for easy rule identification via signature ID and resource ARN combination
- Top Rule Hits dashboard displays aggregated hit counts per firewall across all Availability Zones in a region
- Helps identify unused rules, validate newly deployed security controls, and detect suspicious activity during incident response
- Feature is enabled by default at no additional cost; standard charges apply for log storage and querying
- Available in all AWS Regions where Network Firewall is supported except Middle East (UAE) and Middle East (Bahrain)
Rule hit counts provide visibility into firewall rule utilization and effectiveness, enabling organizations to optimize rule management, ensure compliance, and improve security operations.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2025
2024
2025
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.