AWS Network Firewall Now Supports Stateful Rule Hit Counts

AWS Network Firewall Updates
AWS Network Firewall now provides rule hit counts for stateful rules, enhancing visibility for network administrators and security engineers. This feature allows you to monitor how often each stateful rule matches network traffic, enabling faster incident response and policy validation.
- New Feature: Rule hit counts for stateful rules
- Benefits: Detect triggered rules, identify policy blind spots, and validate policy changes
- Availability: Enabled by default, metrics refresh as low as every 5 minutes
- Charges: No additional charge for rule hit counts, standard charges apply for log data storage and querying
- Regions: Available in all AWS Regions except Middle East (UAE) and Middle East (Bahrain)
What to do
- Enable rule hit counts in your firewall policy
- Monitor rule activity to accelerate incident response
- Identify and remove redundant or obsolete rules
- Validate policy changes by confirming rule effectiveness
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



