AWS Network Firewall Now Supports Stateful Rule Hit Counts
Security teams can use this data to remove obsolete or redundant rules and quickly verify that new security policies are working correctly. This reduces the time needed to respond to incidents by identifying exactly which rules were triggered.
- Provides visibility into how often each stateful rule in the firewall policy matches network traffic
- Helps accelerate incident response and detect shadow, redundant, and obsolete rules
- Enabled by default across custom and managed rule groups with metrics refreshing at intervals as low as 5 minutes
- Available at no additional charge across all supported regions except Middle East (UAE) and Middle East (Bahrain)