AWS Network Firewall now supports rule hit count for stateful rules
AWS Network Firewall now provides a rule hit count capability, tracking how often stateful rules match network traffic. This enhancement improves visibility for security teams, enabling them to identify unused rules, accelerate incident response, and validate security control effectiveness for compliance frameworks. The feature is enabled by default, but requires alert log delivery to CloudWatch Logs or S3 for dashboard integration, and pass rules need the 'alert' keyword to register hits.
Features (1) ›
- Rule hit count for stateful firewall rules
AWS Network Firewall now tracks how often each stateful rule matches network traffic. This new capability helps security teams identify dormant rules, accelerate incident response, and validate security controls by providing traffic match data for custom and managed rule groups. The hit counter increments when a rule action generates an alert log, with metadata included by default in the alert logs.
https://aws.amazon.com/blogs/security/aws-network-firewall-now-supports-rule-hit-count/
Related releases
- Amazon EC2 Marks 20 Years of Cloud Compute Innovation AWS News Blog ·
- GPU-accelerated Apache Spark on Amazon EMR with EC2 G7 instances runs up to 3.7x faster AWS Big Data Blog ·
- AWS Lambda functions now support full IAM resource-based policies AWS What's New ·
- Amazon MSK 3.7 reaches end of life in 7 days endoflife.date ·
- Amazon ECS adds automated agent connectivity detection and repair AWS What's New ·
- AWS Neuron 2.32 Enhances NKI, MXFP8 Training, and Variable-Size Collectives AWS What's New ·