Resource types you can search for with Resource Explorer - AWS Resource Explorer

Resource types you can search for with Resource Explorer

Resource Explorer supports resource types across numerous AWS services.

Some resource types are identified by Amazon resource name (ARN) strings that share a common format with another resource type. When this happens, Resource Explorer can report such resources as that other resource type. For list of resource types affected by this issue, see Resource types that appear as other types.

At this time, tags attached to AWS Identity and Access Management (IAM) resources, such as roles or users, can't be used for searching.

If you have encrypted access to some of your resources, Resource Explorer is unable to discover them. You will not see these resources in your search results.

The following tables list the resource types that are supported for searching in AWS Resource Explorer.

Note

As of July 9, 2024, Resource Explorer no longer supports the following resource types:

  • Amazon Elastic Container Serviceecs:task

  • AWS Systems Managerssm:automation-execution

  • AWS Systems Managerssm:patchbaseline

You can still use these resource types in their own services, but they are no longer indexed or searchable in Resource Explorer.

Supported services and resource types

Supported AWS services

Amazon API Gateway

  • apigateway:restapis

AWS App Runner

  • apprunner:vpcconnector

Amazon AppStream 2.0

  • appstream:appblock

  • appstream:application

  • appstream:fleet

  • appstream:stack

AWS AppSync

  • appsync:apis

Amazon Athena

  • athena:datacatalog

  • athena:workgroup

AWS Backup

  • backup:backupplan

AWS Batch

  • batch:computeenvironment

  • batch:jobqueue

  • batch:schedulingpolicy

AWS CloudFormation

  • cloudformation:stack

  • cloudformation:stackset

Amazon CloudFront

  • cloudfront:cache-policy

  • cloudfront:distribution

  • cloudfront:function

  • cloudfront:fieldlevelencryptionconfig

  • cloudfront:fieldlevelencryptionprofile

  • cloudfront:origin-access-identity

  • cloudfront:originaccesscontrol

  • cloudfront:origin-request-policy

  • cloudfront:realtime-log-config

  • cloudfront:response-headers-policy

AWS CloudTrail

  • cloudtrail:trail

Amazon CloudWatch

  • cloudwatch:alarm

  • cloudwatch:dashboard

  • cloudwatch:insight-rule

  • cloudwatch:metric-stream

  • evidently:project

Amazon CloudWatch Evidently

  • evidently:project/experiment

  • evidently:project/feature

  • evidently:project/launch

Amazon CloudWatch Logs

  • logs:destination

  • logs:log-group

AWS CodeArtifact

  • codeartifact:domain

  • codeartifact:repository

AWS CodeBuild

  • codebuild:project

AWS CodeCommit

  • codecommit:repository

Amazon CodeGuru Profiler

  • codeguru-profiler:profilingGroup

AWS CodePipeline

  • codepipeline:pipeline

AWS CodeConnections

  • codestarconnections:connect

Amazon Cognito

  • cognito:identitypool

  • cognito:userpool

Amazon Connect

  • appintegrations:eventintegration

Amazon Connect Wisdom

  • wisdom:assistant

  • wisdom:association

  • wisdom:knowledge-base

Amazon Detective

  • detective:graph

Amazon DynamoDB

  • dynamodb:table

EC2 Image Builder

  • imagebuilder:component

  • imagebuilder:containerrecipe

  • imagebuilder:distributionconfiguration

  • imagebuilder:image

  • imagebuilder:imagepipeline

  • imagebuilder:imagerecipe

  • imagebuilder:infrastructureconfiguration

Amazon ECR Public

  • ecrpublic:repository

AWS Elastic Beanstalk

  • elasticbeanstalk:application

  • elasticbeanstalk:applicationversion

  • elasticbeanstalk:configurationtemplate

  • elasticbeanstalk:environment

Amazon ElastiCache

  • elasticache:cluster

  • elasticache:globalreplicationgroup

  • elasticache:parametergroup

  • elasticache:replicationgroup

  • elasticache:reserved-instance

  • elasticache:snapshot

  • elasticache:subnetgroup

  • elasticache:user

  • elasticache:usergroup

Amazon Elastic Compute Cloud (Amazon EC2)

  • ec2:capacity-reservation

  • ec2:capacity-reservation-fleet

  • ec2:client-vpn-endpoint

  • ec2:customer-gateway

  • ec2:dedicated-host

  • ec2:dhcp-options

  • ec2:egress-only-internet-gateway

  • ec2:elastic-gpu

  • ec2:elastic-ip

  • ec2:fleet

  • ec2:fpga-image

  • ec2:host-reservation

  • ec2:image

  • ec2:instance

  • ec2:instance-event-window

  • ec2:internet-gateway

  • ec2:ipam

  • ec2:ipam-pool

  • ec2:ipam-scope

  • ec2:ipv4pool-ec2

  • ec2:key-pair

  • ec2:launch-template

  • ec2:natgateway

  • ec2:network-acl

  • ec2:network-insights-access-scope

  • ec2:network-insights-access-scope-analysis

  • ec2:network-insights-analysis

  • ec2:network-insights-path

  • ec2:network-interface

  • ec2:placement-group

  • ec2:prefix-list

  • ec2:reserved-instances

  • ec2:route-table

  • ec2:security-group

  • ec2:security-group-rule

  • ec2:snapshot

  • ec2:spot-fleet-request

  • ec2:spot-instances-request

  • ec2:subnet

  • ec2:subnet-cidr-reservation

  • ec2:traffic-mirror-filter

  • ec2:traffic-mirror-filter-rule

  • ec2:traffic-mirror-session

  • ec2:traffic-mirror-target

  • ec2:transit-gateway

  • ec2:transit-gateway-attachment

  • ec2:transit-gateway-connect-peer

  • ec2:transit-gateway-multicast-domain

  • ec2:transit-gateway-policy-table

  • ec2:transit-gateway-route-table

  • ec2:transitgatewayroutetableannouncement

  • ec2:volume

  • ec2:vpc

  • ec2:vpc-endpoint

  • ec2:vpc-flow-log

  • ec2:vpc-peering-connection

  • ec2:vpn-connection

  • ec2:vpn-gateway

Amazon Elastic Container Registry

  • ecr:repository

Amazon Elastic Container Service

  • ecs:cluster

  • ecs:container-instance

  • ecs:service

  • ecs:task-definition

  • ecs:task-set

Amazon Elastic File System

  • efs:filesystem

  • efs:accesspoint

Elastic Load Balancing

  • elasticloadbalancing:listener

  • elasticloadbalancing:listener-rule

  • elasticloadbalancing:listener-rule/app

  • elasticloadbalancing:listener/app

  • elasticloadbalancing:listener/net

  • elasticloadbalancing:loadbalancer

  • elasticloadbalancing:loadbalancer/app

  • elasticloadbalancing:loadbalancer/net

  • elasticloadbalancing:targetgroup

AWS Elemental MediaPackage

  • mediapackage:channel

  • mediapackage:originendpoint

  • mediapackage-vod:packaging-configurations

  • mediapackage-vod:packaging-groups

AWS Elemental MediaTailor

  • mediatailor:playbackConfiguration

Amazon EMR Serverless

  • emr-serverless:applications

Amazon EventBridge

  • events:event-bus

  • events:rule

AWS Fault Injection Service

  • fis:experimenttemplate

Amazon Forecast

  • forcast:dataset

  • forcast:dataset-group

Amazon Fraud Detector

  • frauddetector:detector

  • frauddetector:entity-type

  • frauddetector:event-type

  • frauddetector:label

  • frauddetector:outcome

  • frauddetector:variable

Amazon GameLift

  • gamelift:alias

AWS Global Accelerator

  • globalaccelerator:accelerator

  • globalaccelerator:accelerator/listener

  • globalaccelerator:accelerator/listener/endpoint-group

AWS Glue

  • glue:database

  • glue:job

  • glue:table

  • glue:trigger

AWS Glue DataBrew

  • databrew:dataset

  • databrew:recipe

  • databrew:ruleset

AWS Identity and Access Management

  • iam:group

  • iam:instance-profile

  • iam:oidc-provider

  • iam:policy

  • iam:role

  • iam:saml-provider

  • iam:server-certificate

  • iam:user

  • iam:virtualmfadevice

Amazon Interactive Video Service

  • ivs:channel

  • ivs:streamkey

AWS IoT

  • iot:authorizer

  • iot:jobtemplate

  • iot:mitigationaction

  • iot:policy

  • iot:provisioningtemplate

  • iot:rolealias

  • iot:securityprofile

  • iot:thing

  • iot:topicrule

AWS IoT Analytics

  • iotanalytics:channel

  • iotanalytics:dataset

  • iotanalytics:datastore

  • iotanalytics:pipeline

AWS IoT Events

  • iotevents:alarmModel

  • iotevents:detectorModel

  • iotevents:input

AWS IoT Greengrass Version 1

  • greengrass:components

  • greengrass:groups

AWS IoT SiteWise

  • iotsitewise:asset

  • iotsitewise:assetmodel

  • iotsitewise:gateway

AWS IoT TwinMaker

  • iottwinmaker:workspace

  • iottwinmaker:workspace/component-type

  • iottwinmaker:workspace/entity

AWS Key Management Service

  • kms:key

Amazon Kinesis

  • kinesis:stream

Amazon Data Firehose

  • kinesisfirehose:deliverystream

Amazon Kinesis Video Streams

  • kinesisvideo:stream

AWS Lambda

  • lambda:code-signing-config

  • lambda:event-source-mapping

  • lambda:function

Amazon Lex

  • lex:bot

Amazon Location Service

  • geo:place-index

  • geo:tracker

Amazon Lookout for Metrics

  • lookoutmetrics:Alert

Amazon Lookout for Vision

  • lookoutvision:project

Amazon Managed Service for Apache Flink

  • kinesisanalytics:application

Amazon Managed Service for Prometheus

  • aps:rulegroupsnamespace

  • aps:workspace

Amazon Managed Service for Prometheus

  • memorydb:cluster

  • memorydb:parametergroup

  • memorydb:user

Amazon Managed Streaming for Apache Kafka

  • kafka:cluster

  • kafka:configuration

AWS Migration Hub Refactor Spaces

  • refactor-spaces:environment

  • refactor-spaces:environment/application

  • refactor-spaces:environment/application/route

  • refactor-spaces:environment/application/service

AWS Network Firewall

  • network-firewall:firewall-policy

AWS Network Manager

  • networkmanager:core-network

  • networkmanager:device

  • networkmanager:global-network

  • networkmanager:link

Amazon OpenSearch Service

  • es:domain

AWS Panorama

  • panorama:package

Amazon Personalize

  • personalize:dataset

  • personalize:dataset-group

  • personalize:schema

AWS Private Certificate Authority

  • acmpca:certificateauthority

Amazon QLDB

  • qldb:ledger

  • qldb:stream

Amazon Redshift

  • redshift:cluster

  • redshift:eventsubscription

  • redshift:parametergroup

  • redshift:snapshot

  • redshift:snapshotcopygrant

  • redshift:snapshotschedule

  • redshift:subnetgroup

  • redshift:usagelimit

Amazon Rekognition

  • rekognition:project

Amazon Relational Database Service (Amazon RDS)

  • rds:auto-backup

  • rds:cev

  • rds:cluster

  • rds:cluster-endpoint

  • rds:cluster-pg

  • rds:cluster-snapshot

  • rds:db

  • rds:db-proxy

  • rds:db-proxy-endpoint

  • rds:deployment

  • rds:es

  • rds:global-cluster

  • rds:og

  • rds:pg

  • rds:ri

  • rds:secgrp

  • rds:snapshot

  • rds:subgrp

AWS Resilience Hub

  • resiliencehub:resiliencypolicy

AWS Resource Groups

  • resourcegroups:group

AWS Resource Explorer

  • resource-explorer-2:index

  • resource-explorer-2:view

Amazon Route 53

  • route53:healthcheck

  • route53:hostedzone

Amazon Route 53 Recovery Readiness

  • route53-recover-readiness:recovery-group

  • route53-recover-readiness:resource-set

Amazon Route 53 Resolver

  • route53resolver:firewalldomainlist

  • route53resolver:firewallrulegroup

  • route53resolver:resolverendpoint

  • route53resolver:resolverrule

Amazon SageMaker

  • sagemaker:model

  • sagemaker:notebookinstance

AWS Secrets Manager

  • secretsmanager:secret

AWS Service Catalog

  • servicecatalog:applications

  • servicecatalog:attribute-groups

Amazon Simple Notification Service

  • sns:topic

Amazon Simple Queue Service

  • sqs:queue

Amazon Simple Storage Service (Amazon S3)

  • s3:accesspoint

  • s3:bucket

  • s3:storage-lens

AWS Step Functions

  • states:statemachine

  • stepfunctions:activity

AWS Systems Manager

  • ssm:association

  • ssm:document

  • ssm:maintenancewindow

  • ssm:managed-instance

  • ssm:parameter

  • ssm:resourcedatasync

  • ssm:windowtarget

  • ssm:windowtask

AWS Verified Access

  • ec2:verifiedaccessendpoint

  • ec2:verifiedaccessgroup

  • ec2:verifiedaccessinstance

  • ec2:verifiedaccesstrustprovider

AWS Wavelength

  • ec2:carriergateway

Programmatically accessing the list of supported resource types

To access the list of supported resource types from code, you can invoke the ListSupportedResourceTypes operation from any AWS SDK.

For example, you can run the list-supported-resource-types AWS Command Line Interface (AWS CLI) command, as shown in the following example.

$ aws resource-explorer-2 list-supported-resource-types { "ResourceTypes": [ { "ResourceType": "acm-pca:certificate-authority", "Service": "acm-pca" }, { "ResourceType": "airflow:environment", "Service": "airflow" }, { "ResourceType": "amplify:branches", "Service": "amplify" }, ... truncated for brevity ...

Resource types that appear as other types

Some resource types are identified by Amazon resource name (ARN) strings that share a common format with another resource type. When this happens, Resource Explorer can report such resources as that other resource type. This affects the resource types in the following table.

Actual resource type Reported as resource type

ec2:securitygroupegress

ec2:securitygroupingress

ec2:security-group-rule

elasticloadbalancingv2:loadbalancer

elasticloadbalancing:loadbalancer

docdb:dbcluster

neptune:dbcluster

rds:dbcluster

rds:cluster

docdb:dbclusterparametergroup

neptune:dbclusterparametergroup

rds:dbclusterparametergroup

rds:cluster-pg

docdb:clustersnapshot

neptune:dbclustersnapshot

rds:clustersnapshot

rds:cluster-snapshot

docdb:dbinstance

neptune:dbinstance

rds:dbinstance

rds:db

docdb:eventsubscription

neptune:eventsubscription

rds:eventsubscription

rds:es

docdb:globalcluster

rds:globalcluster

rds:global-cluster

neptune:dbparametergroup

rds:dbparametergroup

rds:pg

docdb:dbsubnetgroup

neptune:dbsubnetgroup

rds:dbsubnetgroup

rds:subgrp