AWS Network Firewall now reveals exactly how often each rule fires!
Hi, it's me! Today I found a nice update for anyone running network firewalls, so let me introduce it — this one's especially for people managing firewall policies!
AWS What's NewWhat was announced?
AWS announced on What's New that AWS Network Firewall now supports stateful rule hit counts. You can now see how many times each stateful rule in your firewall policy matched network traffic.
Why it matters
AWS Network Firewall is a managed firewall service that inspects and gives visibility into your VPC traffic. But without knowing which rules are actually firing — and how often — it's hard to confirm a policy is working as intended or to clean up rules you no longer need. The more rules you have, the more this blind spot becomes a real operational headache.
What changes
With rule hit counts, you can turn firewall rule activity into actionable intelligence:
- Faster incident response — quickly identify which rules triggered
- Finding policy blind spots — spot shadow, redundant, and obsolete rules
- Validating policy changes — confirm newly deployed rules are matching the traffic you intended
For security engineers and network administrators, this makes auditing and cleaning up rules much easier.
Dive Deep
- Enabled by default across both custom and managed rule groups
- Metrics refresh at intervals as low as 5 minutes, and this is configurable
- No additional charge for the feature itself — standard charges still apply for storing and querying log data
- Available in every region where AWS Network Firewall is supported, except Middle East (UAE) and Middle East (Bahrain)
Wrap-up
- AWS Network Firewall now shows hit counts for stateful rules
- It helps with incident response, spotting policy blind spots, and validating policy changes
- Enabled by default for both custom and managed rule groups, with metrics refreshing as often as every 5 minutes
- No extra charge for the feature (log storage/query costs apply separately); available everywhere except two Middle East regions
- A solid update for security and network engineers who manage firewall policies day to day!