AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or redundant rules and validate whether security controls are working as intended.
The capability covers stateful rules in both custom and managed rule groups, while stateless rules are not supported.
The feature is enabled by default and comes at no additional Network Firewall cost, although standard charges still apply for storing and querying log data. Rule hit counts are available in all AWS Regions where AWS Network Firewall is supported, except Middle East (UAE and Bahrain).
“With this data, you can identify and remove unused rules, accelerate incident response, and validate security control effectiveness for compliance,” the authors said.
AWS Network Firewall protects Amazon Virtual Private Clouds (VPCs) with automated, intelligence-driven network security. Customers can create granular rules to…
https://www.helpnetsecurity.com/2026/08/24/aws-network-firewall-rule-hit-count-capability/



