AWS Security ChangesHomeSearch

AWS elasticloadbalancing: Reorganize NLB CloudWatch metrics into categories

Service: elasticloadbalancing · 2026-09-27 · Documentation low

File: elasticloadbalancing/latest/network/load-balancer-cloudwatch-metrics.md

Summary

Restructures the AWS/NetworkELB CloudWatch metrics documentation into grouped sections (Flows, Throughput, Connections and resets, TLS, Security groups, LCUs, Target group health) and reorders existing metric entries without changing their meaning.

Security assessment

The diff is a pure documentation reorganization that adds category headings and moves existing metric descriptions (including TLS and security group metrics) into those sections. No new security feature, vulnerability fix, or advisory is introduced; the 'security groups' heading merely groups pre-existing metrics.

Evidence

+The `AWS/NetworkELB` namespace includes the following metrics for security groups.

Diff

diff --git a/elasticloadbalancing/latest/network/load-balancer-cloudwatch-metrics.md b/elasticloadbalancing/latest/network/load-balancer-cloudwatch-metrics.md
index ed867bf98..388c11b3e 100644
--- a//elasticloadbalancing/latest/network/load-balancer-cloudwatch-metrics.md
+++ b//elasticloadbalancing/latest/network/load-balancer-cloudwatch-metrics.md
@@ -34 +34,18 @@ For more information, see the [Amazon CloudWatch User Guide](https://docs.aws.am
-The `AWS/NetworkELB` namespace includes the following metrics.
+  * Flows
+
+  * Throughput
+
+  * Connections and resets
+
+  * TLS
+
+  * Security groups
+
+  * LCUs
+
+  * Target group health
+
+
+
+
+The `AWS/NetworkELB` namespace includes the following metrics for flows.
@@ -74,9 +91 @@ Metric | Description
-`ActiveZonalShiftHostCount` |  The number of targets that are actively participating in zonal shift currently. **Reporting criteria** : Reported when the load balancer is opt-in for zonal shift. **Statistics** : The most useful statistics are `Maximum`, and `Minimum`.
-
-###### Dimensions
-
-  * `LoadBalancer`, `TargetGroup`
-  * `AvailabilityZone`, `LoadBalancer`, `TargetGroup`
-
-  
-`ClientTLSNegotiationErrorCount` |  The total number of TLS handshakes that failed during negotiation between a client and a TLS listener. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
+`NewFlowCount` |  The total number of new flows (or connections) established from clients to targets in the time period. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
@@ -86,0 +96,2 @@ Metric | Description
+  * `AvailabilityZone`, `LoadBalancer`
+  * `TargetGroup`
@@ -89 +100 @@ Metric | Description
-`ConsumedLCUs` |  The number of load balancer capacity units (LCU) used by your load balancer. You pay for the number of LCUs that you use per hour. For more information, see [Elastic Load Balancing Pricing](https://aws.amazon.com/elasticloadbalancing/pricing/). **Reporting criteria** : Always reported. **Statistics** : All
+`NewFlowCount_TCP` |  The total number of new TCP flows (or connections) established from clients to targets in the time period. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
@@ -93,0 +105,2 @@ Metric | Description
+  * `AvailabilityZone`, `LoadBalancer`
+  * `TargetGroup`
@@ -96 +109 @@ Metric | Description
-`ConsumedLCUs_TCP` |  The number of load balancer capacity units (LCU) used by your load balancer for TCP. You pay for the number of LCUs that you use per hour. For more information, see [Elastic Load Balancing Pricing](https://aws.amazon.com/elasticloadbalancing/pricing/). **Reporting criteria** : There is a nonzero value. **Statistics** : All
+`NewFlowCount_TLS` |  The total number of new TLS flows (or connections) established from clients to targets in the time period. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
@@ -100,0 +114,2 @@ Metric | Description
+  * `AvailabilityZone`, `LoadBalancer`
+  * `TargetGroup`
@@ -103 +118 @@ Metric | Description
-`ConsumedLCUs_TLS` |  The number of load balancer capacity units (LCU) used by your load balancer for TLS. You pay for the number of LCUs that you use per hour. For more information, see [Elastic Load Balancing Pricing](https://aws.amazon.com/elasticloadbalancing/pricing/). **Reporting criteria** : There is a nonzero value. **Statistics** : All
+`NewFlowCount_UDP` |  The total number of new UDP flows (or connections) established from clients to targets in the time period. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
@@ -107,0 +123,2 @@ Metric | Description
+  * `AvailabilityZone`, `LoadBalancer`
+  * `TargetGroup`
@@ -110 +127 @@ Metric | Description
-`ConsumedLCUs_UDP` |  The number of load balancer capacity units (LCU) used by your load balancer for UDP. You pay for the number of LCUs that you use per hour. For more information, see [Elastic Load Balancing Pricing](https://aws.amazon.com/elasticloadbalancing/pricing/). **Reporting criteria** : There is a nonzero value. **Statistics** : All
+`NewFlowCount_QUIC` |  The total number of UDP datagrams that required a routing decision in the time period. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
@@ -114,0 +132 @@ Metric | Description
+  * `AvailabilityZone`, `LoadBalancer`
@@ -117,9 +135 @@ Metric | Description
-`HealthyHostCount` |  The number of targets that are considered healthy. This metric does not include any Application Load Balancers registered as targets. **Reporting criteria** : Reported if there are registered targets. **Statistics** : The most useful statistics are `Maximum` and `Minimum`.
-
-###### Dimensions
-
-  * `LoadBalancer`, `TargetGroup`
-  * `AvailabilityZone`, `LoadBalancer`, `TargetGroup`
-
-  
-`NewFlowCount` |  The total number of new flows (or connections) established from clients to targets in the time period. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
+`RejectedFlowCount` |  The total number of flows (or connections) rejected by the load balancer. **Reporting criteria** : Always reported. **Statistics** : The most useful statistics are `Average`, `Maximum`, and `Minimum`.
@@ -131 +140,0 @@ Metric | Description
-  * `TargetGroup`
@@ -134 +143 @@ Metric | Description
-`NewFlowCount_TCP` |  The total number of new TCP flows (or connections) established from clients to targets in the time period. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
+`RejectedFlowCount_TCP` |  The number of TCP flows (or connections) rejected by the load balancer. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
@@ -140 +148,0 @@ Metric | Description
-  * `TargetGroup`
@@ -143 +151,2 @@ Metric | Description
-`NewFlowCount_TLS` |  The total number of new TLS flows (or connections) established from clients to targets in the time period. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
+`UnhealthyRoutingFlowCount` |  The number of flows (or connections) that are routed using the routing failover action (fail open). This metric is not supported for TLS listeners. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.  
+`QUIC_Unknown_Server_ID_Packet_Drop_Count` |  The number of UDP datagrams dropped which contain a server ID not associated with a target in the Network Load Balancer. **Reporting criteria** : Reported only for QUIC listeners. **Statistics** : The most useful statistic is `Sum`.
@@ -149 +157,0 @@ Metric | Description
-  * `TargetGroup`
@@ -152 +160,6 @@ Metric | Description
-`NewFlowCount_UDP` |  The total number of new UDP flows (or connections) established from clients to targets in the time period. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
+  
+The `AWS/NetworkELB` namespace includes the following metrics for throughput.
+
+Metric | Description  
+---|---  
+`ProcessedBytes` |  The total number of bytes processed by the load balancer, including TCP/IP headers. This count includes traffic to and from targets, minus health check traffic. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
@@ -158 +170,0 @@ Metric | Description
-  * `TargetGroup`
@@ -161 +173 @@ Metric | Description
-`NewFlowCount_QUIC` |  The total number of UDP datagrams that required a routing decision in the time period. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
+`ProcessedBytes_TCP` |  The total number of bytes processed by TCP listeners. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
@@ -169 +181 @@ Metric | Description
-`PeakBytesPerSecond` |  The highest average bytes processed per second, calculated every 10 seconds during the sampling window. This metric does not include health check traffic. **Reporting criteria** : Always reported **Statistics** : The most useful statistic is `Maximum`.
+`ProcessedBytes_TLS` |  The total number of bytes processed by TLS listeners. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
@@ -177 +189 @@ Metric | Description
-`PeakPacketsPerSecond` |  Highest average packet rate (packets processed per second), calculated every 10 seconds during the sampling window. This metric includes health check traffic. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Maximum`.
+`ProcessedBytes_UDP` |  The total number of bytes processed by UDP listeners. **Reporting criteria** : There is a nonzero value **Statistics** : The most useful statistic is `Sum`.
@@ -185 +197 @@ Metric | Description
-`PortAllocationErrorCount` |  The total number of ephemeral port allocation errors during a client IP translation operation. A non-zero value indicates dropped client connections.  Note: Network Load Balancers support 55,000 simultaneous connections or about 55,000 connections per minute to each unique target (IP address and port) when performing client address translation. To fix port allocation errors, add more targets to the target group. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
+`ProcessedBytes_QUIC` |  The total number of bytes processed by QUIC listeners. **Reporting criteria** : There is a nonzero value **Statistics** : The most useful statistic is `Sum`.
@@ -193 +205 @@ Metric | Description
-`ProcessedBytes` |  The total number of bytes processed by the load balancer, including TCP/IP headers. This count includes traffic to and from targets, minus health check traffic. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
+`ProcessedPackets` |  The total number of packets processed by the load balancer. This count includes traffic to and from targets, including health check traffic. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
@@ -201 +213 @@ Metric | Description
-`ProcessedBytes_TCP` |  The total number of bytes processed by TCP listeners. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
+`PeakBytesPerSecond` |  The highest average bytes processed per second, calculated every 10 seconds during the sampling window. This metric does not include health check traffic. **Reporting criteria** : Always reported **Statistics** : The most useful statistic is `Maximum`.
@@ -209 +221 @@ Metric | Description
-`ProcessedBytes_TLS` |  The total number of bytes processed by TLS listeners. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
+`PeakPacketsPerSecond` |  Highest average packet rate (packets processed per second), calculated every 10 seconds during the sampling window. This metric includes health check traffic. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Maximum`.
@@ -217 +229,6 @@ Metric | Description
-`ProcessedBytes_UDP` |  The total number of bytes processed by UDP listeners. **Reporting criteria** : There is a nonzero value **Statistics** : The most useful statistic is `Sum`.
+  
+The `AWS/NetworkELB` namespace includes the following metrics for connections and resets.
+
+Metric | Description  
+---|---  
+`TCP_Client_Reset_Count` |  The total number of reset (RST) packets sent from a client to a target. These resets are generated by the client and forwarded by the load balancer. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
@@ -225 +242 @@ Metric | Description
-`ProcessedBytes_QUIC` |  The total number of bytes processed by QUIC listeners. **Reporting criteria** : There is a nonzero value **Statistics** : The most useful statistic is `Sum`.
+`TCP_ELB_Reset_Count` |  The total number of reset (RST) packets generated by the load balancer. For more information, see [Troubleshooting](./load-balancer-troubleshooting.html#elb-reset-count-metric). **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
@@ -233 +250 @@ Metric | Description
-`ProcessedPackets` |  The total number of packets processed by the load balancer. This count includes traffic to and from targets, including health check traffic. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
+`TCP_Target_Reset_Count` |  The total number of reset (RST) packets sent from a target to a client. These resets are generated by the target and forwarded by the load balancer. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
@@ -241 +258 @@ Metric | Description
-`RejectedFlowCount` |  The total number of flows (or connections) rejected by the load balancer. **Reporting criteria** : Always reported. **Statistics** : The most useful statistics are `Average`, `Maximum`, and `Minimum`.
+`PortAllocationErrorCount` |  The total number of ephemeral port allocation errors during a client IP translation operation. A non-zero value indicates dropped client connections.  Note: Network Load Balancers support 55,000 simultaneous connections or about 55,000 connections per minute to each unique target (IP address and port) when performing client address translation. To fix port allocation errors, add more targets to the target group. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
@@ -249 +266,6 @@ Metric | Description
-`RejectedFlowCount_TCP` |  The number of TCP flows (or connections) rejected by the load balancer. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
+  
+The `AWS/NetworkELB` namespace includes the following metrics for TLS.
+
+Metric | Description  
+---|---  
+`ClientTLSNegotiationErrorCount` |  The total number of TLS handshakes that failed during negotiation between a client and a TLS listener. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
@@ -254 +275,0 @@ Metric | Description
-  * `AvailabilityZone`, `LoadBalancer`
@@ -257 +278 @@ Metric | Description
-`ReservedLCUs` |  The number of load balancer capacity units (LCUs) reserved for your load balancer using LCU Reservation. **Reporting criteria** : There is a nonzero value **Statistics** : All
+`TargetTLSNegotiationErrorCount` |  The total number of TLS handshakes that failed during negotiation between a TLS listener and a target. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
@@ -263,0 +285,5 @@ Metric | Description
+  
+The `AWS/NetworkELB` namespace includes the following metrics for security groups.
+
+Metric | Description  
+---|---  
@@ -312 +338,6 @@ Metric | Description
-`TargetTLSNegotiationErrorCount` |  The total number of TLS handshakes that failed during negotiation between a TLS listener and a target. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.
+  
+The `AWS/NetworkELB` namespace includes the following metrics for load balancer capacity units (LCU).
+
+Metric | Description  
+---|---  
+`ConsumedLCUs` |  The number of load balancer capacity units (LCU) used by your load balancer. You pay for the number of LCUs that you use per hour. For more information, see [Elastic Load Balancing Pricing](https://aws.amazon.com/elasticloadbalancing/pricing/). **Reporting criteria** : Always reported. **Statistics** : All
@@ -319 +350 @@ Metric | Description
-`TCP_Client_Reset_Count` |  The total number of reset (RST) packets sent from a client to a target. These resets are generated by the client and forwarded by the load balancer. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
+`ConsumedLCUs_TCP` |  The number of load balancer capacity units (LCU) used by your load balancer for TCP. You pay for the number of LCUs that you use per hour. For more information, see [Elastic Load Balancing Pricing](https://aws.amazon.com/elasticloadbalancing/pricing/). **Reporting criteria** : There is a nonzero value. **Statistics** : All
@@ -324 +354,0 @@ Metric | Description
-  * `AvailabilityZone`, `LoadBalancer`
@@ -327 +357 @@ Metric | Description
-`TCP_ELB_Reset_Count` |  The total number of reset (RST) packets generated by the load balancer. For more information, see [Troubleshooting](./load-balancer-troubleshooting.html#elb-reset-count-metric). **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
+`ConsumedLCUs_TLS` |  The number of load balancer capacity units (LCU) used by your load balancer for TLS. You pay for the number of LCUs that you use per hour. For more information, see [Elastic Load Balancing Pricing](https://aws.amazon.com/elasticloadbalancing/pricing/). **Reporting criteria** : There is a nonzero value. **Statistics** : All
@@ -332 +361,0 @@ Metric | Description
-  * `AvailabilityZone`, `LoadBalancer`
@@ -335 +364 @@ Metric | Description
-`TCP_Target_Reset_Count` |  The total number of reset (RST) packets sent from a target to a client. These resets are generated by the target and forwarded by the load balancer. **Reporting criteria** : Always reported. **Statistics** : The most useful statistic is `Sum`.
+`ConsumedLCUs_UDP` |  The number of load balancer capacity units (LCU) used by your load balancer for UDP. You pay for the number of LCUs that you use per hour. For more information, see [Elastic Load Balancing Pricing](https://aws.amazon.com/elasticloadbalancing/pricing/). **Reporting criteria** : There is a nonzero value. **Statistics** : All
@@ -340 +368,0 @@ Metric | Description
-  * `AvailabilityZone`, `LoadBalancer`
@@ -343 +371,13 @@ Metric | Description
-`UnHealthyHostCount` |  The number of targets that are considered unhealthy. This metric does not include any Application Load Balancers registered as targets. **Reporting criteria** : Reported if there are registered targets. **Statistics** : The most useful statistics are `Maximum` and `Minimum`.
+`ReservedLCUs` |  The number of load balancer capacity units (LCUs) reserved for your load balancer using LCU Reservation. **Reporting criteria** : There is a nonzero value. **Statistics** : All
+
+###### Dimensions
+
+  * `LoadBalancer`
+
+  
+  
+The `AWS/NetworkELB` namespace includes the following metrics for target group health.
+
+Metric | Description  
+---|---  
+`ActiveZonalShiftHostCount` |  The number of targets that are actively participating in zonal shift currently. **Reporting criteria** : Reported when the load balancer is opt-in for zonal shift. **Statistics** : The most useful statistics are `Maximum`, and `Minimum`.
@@ -351,2 +391 @@ Metric | Description
-`UnhealthyRoutingFlowCount` |  The number of flows (or connections) that are routed using the routing failover action (fail open). This metric is not supported for TLS listeners. **Reporting criteria** : There is a nonzero value. **Statistics** : The most useful statistic is `Sum`.  
-`ZonalHealthStatus` |  The number of Availability Zones that the load balancer considers healthy. The load balancer emits a 1 for each healthy Availability Zone and a 0 for each unhealthy Availability Zone. **Reporting criteria** : Reported if health checks are enabled. **Statistics** : The most useful statistics are `Maximum` and `Minimum`.
+`HealthyHostCount` |  The number of targets that are considered healthy. This metric does not include any Application Load Balancers registered as targets. **Reporting criteria** : Reported if there are registered targets. **Statistics** : The most useful statistics are `Maximum` and `Minimum`.
@@ -356,2 +395,2 @@ Metric | Description
-  * `LoadBalancer`
-  * `AvailabilityZone`, `LoadBalancer`
+  * `LoadBalancer`, `TargetGroup`
+  * `AvailabilityZone`, `LoadBalancer`, `TargetGroup`
@@ -360 +399,9 @@ Metric | Description