> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cortex.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Using the integration for AWS

> How to use the integration for AWS in Cortex

<Info>
  Cortex connects to many third-party vendors whose system interfaces frequently change. As a result, integration behavior or configuration steps may shift without notice. If you encounter unexpected issues, check with your system administrator or refer to the vendor's documentation for the most current information. Additionally, integration sync times vary and are subject to scheduling overrides and timing variance.
</Info>

This article explains how to use the integration for AWS. For configuration instructions, see [Configuring the integration for AWS](/ingesting-data-into-cortex/integrations/aws/using-the-integration-for-aws). For instructions on connecting GCP to entities, see [Connecting entities to AWS](/ingesting-data-into-cortex/integrations/aws/importing-entities-from-aws).

<Info>
  Cortex conducts a sync of integration details daily at 10 a.m. UTC.
</Info>

## Viewing AWS data on an entity

The **Cloud > AWS** section of an entity's details sidebar shows Amazon Elastic Container Service (ECS) data for the ECS services linked to that entity.

Only ECS services populate this section. Cortex reads the entity's `x-cortex-infra` block, keeps any entries of type `AWS::ECS::Service`, and builds the view from those:

```yaml theme={null}
x-cortex-infra:
  aws:
    cloudControl:
    - type: AWS::ECS::Service
      region: us-west-2
      accountId: "123456123456"
      identifier: arn:aws:ecs:us-west-2:123456123456:service/payments-cluster/payments-api
```

| Field | Description | Required |
| - | - | - |
| `type` | The AWS Cloud Control resource type. Only `AWS::ECS::Service` populates the **Cloud > AWS** section. | <Icon icon="check" /> |
| `region` | The AWS region the ECS service runs in, for example `us-west-2`. | <Icon icon="check" /> |
| `accountId` | The ID of the AWS account that owns the service. Wrap the value in quotation marks so leading zeros aren't dropped. | <Icon icon="check" /> |
| `identifier` | The fully-qualified ARN of the ECS service.<br /><br />Note that the `identifier` must be the fully-qualified ARN of the ECS service, not the service name. | <Icon icon="check" /> |

A few things to keep in mind:

* `AWS::ECS::Service` is the only type that populates this section. Other AWS types, including `AWS::ECS::Cluster`, don't populate it, even when they're linked to the entity correctly.
* Links defined with `x-cortex-relationships` don't populate this section. To see data here, link the ECS service in the entity's `x-cortex-infra` block.
* If an entity has no linked ECS service, the **Cloud > AWS** section doesn't appear in its details sidebar.

To work with other AWS resource types in Cortex, [import them as entities](/ingesting-data-into-cortex/integrations/aws/importing-entities-from-aws#connecting-an-entity-to-aws), then connect them to related entities using [relationships](/ingesting-data-into-cortex/entities-overview/entities/defining-relationship-types). You can also query their metadata with the `aws.details()` function in [CQL](/ingesting-data-into-cortex/integrations/aws/using-the-integration-for-aws#scorecards-and-cql).

## Searching AWS entities in Cortex

The following keys are supported when searching for your AWS entities in Cortex.

* `aws-account-id` - Account ID number
* `aws-account-name` - Account alias
* `aws-region` - AWS region of the resource
* `aws-type` - AWS type of the resource
* `aws-name` - AWS name of the resource
* `aws-identifier` - The primary identifier of a resource
* `aws-secondary-identifier` - The secondary identifier of a resource
* `aws-arn` - Searches for an Amazon Resource Name (ARN). This is not supported for Cloud Control types.

**To search for entities**:

1. From the main sidebar, expand **Catalogs**, then select **All entities**.
2. Do one of the following:
   * Select the **All** tab to search and filter across all of your organization's entities.
   * Select the **Mine** tab to search and filter only the entities you own.
   * Note that Cortex saves your selection and restores it the next time you open this page.
3. In the upper-right corner, enter your search parameters in the Search bar.

### Example search queries

* `aws-type:"AWS::EC2" AND aws-region:"us-west"` - Searches for entities of category EC2 in the any of us-west regions
* `aws-account-id: "234512324"` - Searches for all entities from the account 234512324
* `aws-name:"aws-identifier-of-resource" AND aws-account-name:"test-account"` - Searches for entities with the identifier `aws-identifier-of-resource` in the account with alias `test-account`

## Creating Scorecard rules and writing CQL queries with the AWS integration

With the AWS integration, you can create Scorecard rules and write CQL queries based on AWS resources.

See more examples in the [CQL Explorer](https://app.getcortexapp.com/admin/cql-explorer) in Cortex.

<Accordion title="AWS details">
  Get the AWS details for an entity

  **Definition** - `aws.details(): Object`

  **Example**

  In a Scorecard, you can create a rule to verify that an entity of type `lamda` has a correct function name:

  ```
  aws.details().resources.filter((resource) => resource.typeName == "AWS::Lambda::Function").length > 0
  ```

  You could also create a rule to verify that an entity is not using deprecated runtimes:

  ```
  aws.details().resources.filter((resource) => resource.typeName == "AWS::Lambda::Function" and resource?.metadata?.get("Runtime")?.matchesIn("(python3\\.6|python2\\.7|dotnetcore2\\.1|ruby2\\.5|nodejs12\\.|nodejs10\\.|nodejs8\\.10|nodejs4\\.3|nodejs6\\.10|dotnetcore1\\.0|dotnetcore2\\.0|nodejs4\\.3-edge|nodejs$)")).length == 0    
  ```
</Accordion>

## Viewing AWS integration logs

<Info>
  This feature is available in Cortex cloud.
</Info>

While viewing an integration's settings page, select the **Error logs** tab to view errors from the last 7 days. You can filter the logs list by configuration and by operation (for example, you could filter to view errors surfaced only via Scorecards).

<Frame>
  <img src="https://mintcdn.com/cortex-290c0c42/ovmDVVMNC2L6Yw7I/images/integration-error-logs.png?fit=max&auto=format&n=ovmDVVMNC2L6Yw7I&q=85&s=dffdc901a9ce0232aedd090bb3a4531c" alt="The 'Logs' tab on an integration's settings page shows error information over the past 7 days." title="Integration Error Logs" className="mr-auto" width="1532" height="203" data-path="images/integration-error-logs.png" />
</Frame>

Click into a row to get more information, including time stamp, status code, full error, and request path.

## Troubleshooting and FAQ

See frequently asked questions below.

<AccordionGroup>
  <Accordion title="If I have auto-import enabled, how can I remove cloud control types that I no longer want to be imported?">
    If you want to remove any of the cloud control types after importing them: Disable the [automatic import](/ingesting-data-into-cortex/integrations/aws/using-the-integration-for-aws#enable-automatic-import-of-aws-entities) setting, remove the cloud control types from your [AWS integration settings](/ingesting-data-into-cortex/integrations/aws/using-the-integration-for-aws#step-5-select-aws-resource-types), then enable [auto-archival](/ingesting-data-into-cortex/entities-overview/entities/archiving-entities/auto-archive). This will cause the removed cloud control types to be archived during the next sync.
  </Accordion>

  <Accordion title="Why am I seeing the AWS account ID instead of the AWS account alias?">
    We've recently added support for pulling in the AWS account alias. The required permission is `iam:ListAccountAliases` (see the AWS documentation [here](https://000001.awsstudygroup.com/1-create-new-aws-account/1.3-aws-account-alias/#create-or-edit-an-account-alias)). Once this permission is added, the we will persist the account alias everywhere instead of the ID.
  </Accordion>

  <Accordion title="Why don't I see the Cloud > AWS section on an entity?">
    That section only appears on entities that have an `AWS::ECS::Service` resource linked in their `x-cortex-infra` block. If the entity has no linked ECS service, or is linked to a different AWS type such as `AWS::ECS::Cluster`, Cortex hides the section instead of showing an empty page. See [Viewing AWS data on an entity](/ingesting-data-into-cortex/integrations/aws/using-the-integration-for-aws#viewing-aws-data-on-an-entity).
  </Accordion>

  <Accordion title="When does Cortex sync AWS resources?">
    Cortex conducts the following daily syncs for AWS:

    * Integration details daily at 10 a.m. UTC
    * Ownership sync daily at 6 a.m. UTC
    * AWS tag sync (dependencies) daily at 8 a.m. UTC
      * This sync can also be [triggered manually](/ingesting-data-into-cortex/integrations/aws/importing-entities-from-aws#discovering-dependencies-automatically)
  </Accordion>
</AccordionGroup>

<br />


## Related topics

- [Importing entities from AWS](/ingesting-data-into-cortex/integrations/aws/importing-entities-from-aws.md)
- [AWS](/ingesting-data-into-cortex/integrations/aws.md)
- [Humanitec](/ingesting-data-into-cortex/integrations/humanitec.md)
