← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

AWS Network Firewall adds rule hit count support for stateful rules

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • AWS Network Firewall now supports rule hit count for stateful rules.
  • The feature tracks traffic matches for custom and managed rule groups.
  • Hit counts increment for rules with alert, drop, or reject actions.
  • Pass rules require an 'alert' keyword to generate hit count metrics.

New Rule Hit Count Feature

AWS Network Firewall has introduced a new capability called rule hit count. This feature provides traffic match data for stateful rules, encompassing both custom and managed rule groups within the firewall service. The addition addresses challenges faced by security teams in managing complex firewall rule sets.

Addressing Operational and Compliance Gaps

Previously, determining which firewall rules were actively matching traffic versus consuming capacity without being triggered required manual log analysis. This lack of visibility created operational inefficiencies and compliance gaps. Organizations with governance policies requiring the removal of dormant rules lacked a mechanism to identify them, and teams responsible for compliance frameworks like Payment Card Industry (PCI) 4.0 and Digital Operational Resilience Act (DORA) struggled to provide evidence of active security controls. The rule hit count feature aims to resolve these issues by providing clear data on rule activity.

How Rule Hit Count Works

Rule hit counts track the frequency with which each stateful rule matches network traffic. The counter increments specifically when a rule match results in an alert log being created. This means rules configured with an 'alert', 'drop', or 'reject' action will increment the hit counter, as these actions generate alert logs. However, rules with a 'pass' action do not generate alert logs by default and therefore will not appear in the rule hit count metric unless modified.

Visibility for Pass Rules

To gain visibility into traffic matching 'pass' rules, users can include the 'alert' keyword within the 'pass' rule configuration. This modification ensures that an alert log is generated, allowing the rule to appear in the hit count metric, while still permitting the traffic to reach its intended destination. This provides a mechanism to monitor all stateful rules for activity.

Metadata and Data Source

The rule hit count feature automatically adds specific metadata to each alert log, without requiring additional configuration. This metadata includes the resource ARN of the stateful rule group. The alert log data, which contains this metadata, serves as the source for the rule hit count metrics, which Network Firewall pushes to customer accounts.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~17 min · 15 stories · Aug 20

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

AWS Network Firewall now includes a rule hit count feature that tracks how often stateful rules match network traffic. This capability helps security teams identify unused rules, improve incident response, and validate security control effectiveness for compliance frameworks like PCI 4.0 and DORA.