Skip to main content
Cortex connects to many third-party vendors whose system interfaces frequently change. As a result, integration behavior or configuration steps may shift without notice. If you encounter unexpected issues, check with your system administrator or refer to the vendor’s documentation for the most current information. Additionally, integration sync times vary and are subject to scheduling overrides and timing variance.
This article explains how to use the integration for AWS. For configuration instructions, see Configuring the integration for AWS. For instructions on connecting GCP to entities, see Connecting entities to AWS.
Cortex conducts a sync of integration details daily at 10 a.m. UTC.

Viewing AWS data on an entity

The Cloud > AWS section of an entity’s details sidebar shows Amazon Elastic Container Service (ECS) data for the ECS services linked to that entity. Only ECS services populate this section. Cortex reads the entity’s x-cortex-infra block, keeps any entries of type AWS::ECS::Service, and builds the view from those:
A few things to keep in mind:
  • AWS::ECS::Service is the only type that populates this section. Other AWS types, including AWS::ECS::Cluster, don’t populate it, even when they’re linked to the entity correctly.
  • Links defined with x-cortex-relationships don’t populate this section. To see data here, link the ECS service in the entity’s x-cortex-infra block.
  • If an entity has no linked ECS service, the Cloud > AWS section doesn’t appear in its details sidebar.
To work with other AWS resource types in Cortex, import them as entities, then connect them to related entities using relationships. You can also query their metadata with the aws.details() function in CQL.

Searching AWS entities in Cortex

The following keys are supported when searching for your AWS entities in Cortex.
  • aws-account-id - Account ID number
  • aws-account-name - Account alias
  • aws-region - AWS region of the resource
  • aws-type - AWS type of the resource
  • aws-name - AWS name of the resource
  • aws-identifier - The primary identifier of a resource
  • aws-secondary-identifier - The secondary identifier of a resource
  • aws-arn - Searches for an Amazon Resource Name (ARN). This is not supported for Cloud Control types.
To search for entities:
  1. From the main sidebar, expand Catalogs, then select All entities.
  2. Do one of the following:
    • Select the All tab to search and filter across all of your organization’s entities.
    • Select the Mine tab to search and filter only the entities you own.
    • Note that Cortex saves your selection and restores it the next time you open this page.
  3. In the upper-right corner, enter your search parameters in the Search bar.

Example search queries

  • aws-type:"AWS::EC2" AND aws-region:"us-west" - Searches for entities of category EC2 in the any of us-west regions
  • aws-account-id: "234512324" - Searches for all entities from the account 234512324
  • aws-name:"aws-identifier-of-resource" AND aws-account-name:"test-account" - Searches for entities with the identifier aws-identifier-of-resource in the account with alias test-account

Creating Scorecard rules and writing CQL queries with the AWS integration

With the AWS integration, you can create Scorecard rules and write CQL queries based on AWS resources. See more examples in the CQL Explorer in Cortex.
Get the AWS details for an entityDefinition - aws.details(): ObjectExampleIn a Scorecard, you can create a rule to verify that an entity of type lamda has a correct function name:
You could also create a rule to verify that an entity is not using deprecated runtimes:

Viewing AWS integration logs

This feature is available in Cortex cloud.
While viewing an integration’s settings page, select the Error logs tab to view errors from the last 7 days. You can filter the logs list by configuration and by operation (for example, you could filter to view errors surfaced only via Scorecards).
The 'Logs' tab on an integration's settings page shows error information over the past 7 days.
Click into a row to get more information, including time stamp, status code, full error, and request path.

Troubleshooting and FAQ

See frequently asked questions below.
If you want to remove any of the cloud control types after importing them: Disable the automatic import setting, remove the cloud control types from your AWS integration settings, then enable auto-archival. This will cause the removed cloud control types to be archived during the next sync.
We’ve recently added support for pulling in the AWS account alias. The required permission is iam:ListAccountAliases (see the AWS documentation here). Once this permission is added, the we will persist the account alias everywhere instead of the ID.
That section only appears on entities that have an AWS::ECS::Service resource linked in their x-cortex-infra block. If the entity has no linked ECS service, or is linked to a different AWS type such as AWS::ECS::Cluster, Cortex hides the section instead of showing an empty page. See Viewing AWS data on an entity.
Cortex conducts the following daily syncs for AWS:
  • Integration details daily at 10 a.m. UTC
  • Ownership sync daily at 6 a.m. UTC
  • AWS tag sync (dependencies) daily at 8 a.m. UTC

Last modified on September 25, 2026