← Back to feed
Policy & RegulationEmerging1 sourceAug 20, 2026 · 18:40via AWS Security Blog

AWS Network Firewall now supports rule hit count

Brief

As firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively matching traffic and which are consuming capacity without being triggered. This lack of visibility creates operational and compliance gaps.

Organizations with governance policies that require removal of dormant rules after a defined period have no mechanism to identify them. Teams responsible for compliance frameworks such as Payment Card Industry (PCI) 4. 0 and Digital Operational Resilience Act (DORA) can’t provide evidence that specific controls are actively functioning.

Central teams managing firewalls on behalf of multiple business units have no way to determine which rules are unused or need updating.

Read more on AWS Security Blog