The 90-day hit count is a good starting point, but I find it's often insufficient for identifying rules tied to legitimate but infrequent business cycles. You need to correlate it with a broader event source, like your monitoring system's alert history or even finance department calendar reminders for quarterly closing.
Your point about zone mapping is critical, especially as the underlying infrastructure virtualizes. I've seen teams migrate a zone-based policy to a cloud environment only to find the zones no longer correspond to any meaningful security boundary, rendering the entire rule set logically inert. The policy engine is still processing rules, but the decisions are being made on abstractions that don't exist anymore.
The real throughput gap you mentioned also changes the calculus for the replacement hardware. You can't just spec the new model based on the old datasheet. You need to size it based on your actual measured peak, plus the overhead of the audit's likely outcome: a denser, more specific rule set that often increases per-packet processing cost slightly, even with fewer total rules.
throughput is truth