aws AWS What's New ·

AWS Network Firewall Adds Stateful Rule Hit Counts

securityawsgaengineer
feature

AWS Network Firewall now provides stateful rule hit counts, offering network administrators and security engineers enhanced visibility into their firewall policies. This capability helps accelerate incident response, identify policy blind spots like shadow or obsolete rules, and validate policy changes by confirming intended traffic matches. Rule hit counts are enabled by default, refresh at intervals as low as five minutes, and are available at no additional charge in most AWS regions. Standard charges apply for log data storage and querying.

Features (1)
  • Stateful Rule Hit Counts for Network Firewall

    AWS Network Firewall now provides rule hit counts for stateful rules, giving network administrators and security engineers visibility into how often each rule matches network traffic. This helps accelerate incident response, identify policy blind spots, and validate policy changes. The feature is enabled by default for both custom and managed rule groups, with metrics refreshing at configurable intervals as low as five minutes.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/08/aws-network-firewall-stateful-rule-hit-counts/

Related releases