x-cortex-owners blocks correctly.
If you’re new to ownership in Cortex, start with How ownership works. For help choosing a source, see Ownership best practices.
Sources that use x-cortex-owners
For these sources, reference the provider’s team or group in the entity descriptor with type: group:
Workday teams are imported as Cortex teams, so you reference them by their Cortex tag with
provider: CORTEX.Sources that use cloud tags
AWS and Azure Resources don’t usex-cortex-owners. Instead, Cortex reads an ownership tag on each cloud resource and matches its value to a Cortex team’s x-cortex-tag. By default, the tag key is owner, and you can customize it in each integration’s settings. Because the tag points to a Cortex team, you don’t need identity mappings for this step.