AWS Network Firewall has introduced a new capability called rule hit count. This feature provides traffic match data for stateful rules, encompassing both custom and managed rule groups within the firewall service. The addition addresses challenges faced by security teams in managing complex firewall rule sets.
Previously, determining which firewall rules were actively matching traffic versus consuming capacity without being triggered required manual log analysis. This lack of visibility created operational inefficiencies and compliance gaps. Organizations with governance policies requiring the removal of dormant rules lacked a mechanism to identify them, and teams responsible for compliance frameworks like Payment Card Industry (PCI) 4.0 and Digital Operational Resilience Act (DORA) struggled to provide evidence of active security controls. The rule hit count feature aims to resolve these issues by providing clear data on rule activity.
Rule hit counts track the frequency with which each stateful rule matches network traffic. The counter increments specifically when a rule match results in an alert log being created. This means rules configured with an 'alert', 'drop', or 'reject' action will increment the hit counter, as these actions generate alert logs. However, rules with a 'pass' action do not generate alert logs by default and therefore will not appear in the rule hit count metric unless modified.
To gain visibility into traffic matching 'pass' rules, users can include the 'alert' keyword within the 'pass' rule configuration. This modification ensures that an alert log is generated, allowing the rule to appear in the hit count metric, while still permitting the traffic to reach its intended destination. This provides a mechanism to monitor all stateful rules for activity.
The rule hit count feature automatically adds specific metadata to each alert log, without requiring additional configuration. This metadata includes the resource ARN of the stateful rule group. The alert log data, which contains this metadata, serves as the source for the rule hit count metrics, which Network Firewall pushes to customer accounts.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
AWS Network Firewall now includes a rule hit count feature that tracks how often stateful rules match network traffic. This capability helps security teams identify unused rules, improve incident response, and validate security control effectiveness for compliance frameworks like PCI 4.0 and DORA.