Monitoring and reporting in Network Firewall - Amazon Network Firewall
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Monitoring and reporting in Network Firewall

Network Firewall offers multiple in-console options to analyze the network traffic monitored by a firewall. The Monitoring page provides tools for real-time monitoring and retroactive analysis. Your firewall's advanced configuration settings affect which dashboards are populated with data. For information on adjusting your firewall's configuration, see Updating a firewall in Amazon Network Firewall.

Network Firewall provides the following features in the Monitoring section of firewall details:

Monitoring feature

Description

Data source

Enabled by default?

Firewall requests

Provides a graph of the number of packets monitored by the firewall.

  • Stateless engine passed and dropped packets

  • Stateful engine passed, dropped, and rejected packets

  • Stream exception policy packets

Stateless and stateful engine traffic.

Yes

Firewall monitoring dashboard

Provides real-time analysis of flow and alert logs through multiple visualization options.

Amazon S3 and CloudWatch logs.

No. Must be enabled in your firewall's advanced settings.

Traffic analysis mode and reports

Provides retroactive analysis and report generation.

HTTP or HTTPS traffic observed over the last 30 days, starting from when you enable Traffic analysis mode on your firewall.

No. Must be enabled in your firewall's advanced settings.

Access Monitoring in the Network Firewall console

Follow these steps to access the monitoring and observability features for your firewall:

  1. Sign in to the Amazon Web Services Management Console and open the Amazon VPC console at https://console.amazonaws.cn/vpc/.

  2. In the navigation pane, under Network Firewall, choose Firewalls.

  3. In the Firewalls page, choose the name of the firewall that you want to edit. This takes you to the firewall's details page.

  4. In the firewall's details page, choose the Monitoring tab.

Review the topics in this guide to learn about the monitoring options you can enable using the Network Firewall console.