aws AWS Security Blog ·

AWS Network Firewall now supports rule hit count for stateful rules

blogsecurityawsgaengineer
feature

AWS Network Firewall now provides a rule hit count capability, tracking how often stateful rules match network traffic. This enhancement improves visibility for security teams, enabling them to identify unused rules, accelerate incident response, and validate security control effectiveness for compliance frameworks. The feature is enabled by default, but requires alert log delivery to CloudWatch Logs or S3 for dashboard integration, and pass rules need the 'alert' keyword to register hits.

Features (1)
  • Rule hit count for stateful firewall rules

    AWS Network Firewall now tracks how often each stateful rule matches network traffic. This new capability helps security teams identify dormant rules, accelerate incident response, and validate security controls by providing traffic match data for custom and managed rule groups. The hit counter increments when a rule action generates an alert log, with metadata included by default in the alert logs.

Read the original announcement →

https://aws.amazon.com/blogs/security/aws-network-firewall-now-supports-rule-hit-count/

Related releases