AWS Network Firewall adds rule hit count visibility
🔒 This post announces a new AWS Network Firewall capability—rule hit count—that provides visibility into how often stateful rules match network traffic across custom and managed rule groups. Rule hit counts increment when matches produce alert logs (alert, drop, reject), and pass rules can be tracked by adding the alert keyword. Alert logs include aws_metadata with resource ARN and signature ID, are delivered to CloudWatch Logs or S3, and drive the Top Rule Hits dashboard for monitoring and compliance validation.
