AWS Network Firewall adds rule hit counts, turning dormant-rule cleanup into a query
Hit counts give firewall teams proof that a control actually fires. The catch is that pass rules stay invisible unless you edit them, so a zero is not the same as unused.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives78
- Confidence52