View rule hit counts
Hit count indicates the number of times a policy rule or default action has been matched to a connection. The hit count is incremented only for the first packet of a connection that matches a rule. You can use this information to identify the efficacy of your rules. Hit count information is available only for access control and prefilter rules applied to Firewall Threat Defense devices.
Note |
|
Before you begin
If you use custom user roles, ensure that the roles include these privileges:
-
View Device, to see the hit counts.
-
Modify Device, to refresh the hit counts.
Follow these steps to view rule hit counts:
Procedure
Step 1 | In the access control policy or prefilter policy editor, click on the top-right of the page. | ||
Step 2 | On the Hit Count page, select the device from the Select a device drop-down list. If it is not the first time that you are generating hit counts for this device, the last fetched hit count information appears next to the drop-down box. Also, verify the Last Deployed time to confirm recent policy changes. Select All to see an aggregate of hit counts across all devices assigned to the policy. | ||
Step 3 | If necessary, click Refresh ( In the prefilter policy, you might need to click Fetch Current Hit Count to get initial hit count data. You cannot refresh the hit count while deployment to the device is in progress. | ||
Step 4 | View and analyze the data. You can do these actions:
| ||
Step 5 | Optionally, you can generate a comma-separated values report of the details on the page by clicking Generate CSV on the bottom-left of the page. | ||
Step 6 | Click Close to return to the policy page. |







