Cortex connects to many third-party vendors whose system interfaces frequently change. As a result, integration behavior or configuration steps may shift without notice. If you encounter unexpected issues, check with your system administrator or refer to the vendor’s documentation for the most current information. Additionally, integration sync times vary and are subject to scheduling overrides and timing variance.
Cortex conducts a sync of integration details daily at 10 a.m. UTC.
Viewing AWS data on an entity
The Cloud > AWS section of an entity’s details sidebar shows Amazon Elastic Container Service (ECS) data for the ECS services linked to that entity. Only ECS services populate this section. Cortex reads the entity’sx-cortex-infra block, keeps any entries of type AWS::ECS::Service, and builds the view from those:
A few things to keep in mind:
AWS::ECS::Serviceis the only type that populates this section. Other AWS types, includingAWS::ECS::Cluster, don’t populate it, even when they’re linked to the entity correctly.- Links defined with
x-cortex-relationshipsdon’t populate this section. To see data here, link the ECS service in the entity’sx-cortex-infrablock. - If an entity has no linked ECS service, the Cloud > AWS section doesn’t appear in its details sidebar.
aws.details() function in CQL.
Searching AWS entities in Cortex
The following keys are supported when searching for your AWS entities in Cortex.aws-account-id- Account ID numberaws-account-name- Account aliasaws-region- AWS region of the resourceaws-type- AWS type of the resourceaws-name- AWS name of the resourceaws-identifier- The primary identifier of a resourceaws-secondary-identifier- The secondary identifier of a resourceaws-arn- Searches for an Amazon Resource Name (ARN). This is not supported for Cloud Control types.
- From the main sidebar, expand Catalogs, then select All entities.
- Do one of the following:
- Select the All tab to search and filter across all of your organization’s entities.
- Select the Mine tab to search and filter only the entities you own.
- Note that Cortex saves your selection and restores it the next time you open this page.
- In the upper-right corner, enter your search parameters in the Search bar.
Example search queries
aws-type:"AWS::EC2" AND aws-region:"us-west"- Searches for entities of category EC2 in the any of us-west regionsaws-account-id: "234512324"- Searches for all entities from the account 234512324aws-name:"aws-identifier-of-resource" AND aws-account-name:"test-account"- Searches for entities with the identifieraws-identifier-of-resourcein the account with aliastest-account
Creating Scorecard rules and writing CQL queries with the AWS integration
With the AWS integration, you can create Scorecard rules and write CQL queries based on AWS resources. See more examples in the CQL Explorer in Cortex.AWS details
AWS details
Get the AWS details for an entityDefinition - You could also create a rule to verify that an entity is not using deprecated runtimes:
aws.details(): ObjectExampleIn a Scorecard, you can create a rule to verify that an entity of type lamda has a correct function name:Viewing AWS integration logs
This feature is available in Cortex cloud.

Troubleshooting and FAQ
See frequently asked questions below.If I have auto-import enabled, how can I remove cloud control types that I no longer want to be imported?
If I have auto-import enabled, how can I remove cloud control types that I no longer want to be imported?
If you want to remove any of the cloud control types after importing them: Disable the automatic import setting, remove the cloud control types from your AWS integration settings, then enable auto-archival. This will cause the removed cloud control types to be archived during the next sync.
Why am I seeing the AWS account ID instead of the AWS account alias?
Why am I seeing the AWS account ID instead of the AWS account alias?
We’ve recently added support for pulling in the AWS account alias. The required permission is
iam:ListAccountAliases (see the AWS documentation here). Once this permission is added, the we will persist the account alias everywhere instead of the ID.Why don't I see the Cloud > AWS section on an entity?
Why don't I see the Cloud > AWS section on an entity?
That section only appears on entities that have an
AWS::ECS::Service resource linked in their x-cortex-infra block. If the entity has no linked ECS service, or is linked to a different AWS type such as AWS::ECS::Cluster, Cortex hides the section instead of showing an empty page. See Viewing AWS data on an entity.When does Cortex sync AWS resources?
When does Cortex sync AWS resources?
Cortex conducts the following daily syncs for AWS:
- Integration details daily at 10 a.m. UTC
- Ownership sync daily at 6 a.m. UTC
- AWS tag sync (dependencies) daily at 8 a.m. UTC
- This sync can also be triggered manually