AWS Resource Explorer now provides immediate access to resource search and discovery capabilities in a Region. With this launch, you no longer need to activate Resource Explorer to discover your resources. Learn more
Completing setup for Resource Explorer
AWS Resource Explorer automatically enables basic search functionality when you search with appropriate permissions. However, you may need to manually complete setup in specific scenarios, such as when you lack required permissions, have previously deleted an index in a Region, or need to manage existing aggregator configurations. For enhanced functionality like cross-Region search, you can use the Quick setup option or one-click cross-Region banner to create indexes in all AWS Regions that are turned on in your AWS account. When you use the Quick Setup option, Resource Explorer promotes the specified Region to be the aggregator index for the account. If you use the Advanced setup option, you can specify the Regions in which to create indexes.
When you complete setup for Resource Explorer in an AWS Region, the service performs the following actions:
-
When the first user with appropriate permissions accesses Resource Explorer in the first Region in an AWS account, Resource Explorer automatically creates a service-linked role in the account named AWSServiceRoleForResourceExplorer. This role grants permissions for Resource Explorer to discover and index the resources in your account by using services such as AWS CloudTrail and the tagging service. Resource Explorer uses a service-linked channel to receive CloudTrail events on your behalf. Creation of the service-linked role happens only when you register the first AWS Region in the account. Resource Explorer uses the same service-linked role for all additional Regions that you add later.
-
Resource Explorer automatically creates an index in the specified Region to store the details about that Region's resources. Once the service-linked role exists in the account, subsequent Regions are automatically enabled when users with search permissions invoke search operations in those Regions.
-
Resource Explorer begins discovering the resources in the specified Region and adds the information it finds about them to that Region's index.
-
If your account already contains an aggregator index in a different Region, Resource Explorer starts replicating the information from the new Region's index to the aggregator index to support cross-Region search.
When those steps are complete, information about your resources is available to be discovered by users. They can search by using one of the views defined in either the same Region or the Region that contains the aggregator index.
Create a Resource Explorer index in a Region
While Resource Explorer automatically enables basic search functionality, you may need to manually create indexes in specific scenarios. The Resource Explorer console provides banner notifications to guide you through setup completion, and you can access enhanced setup options through the "Complete Setup" option in the left navigation or on the Settings page.
Manual index creation is typically needed when:
-
You lack the required
iam:CreateServiceLinkedRolepermission for automatic setup -
You previously deleted an index in a Region and want to restore full functionality
-
You need to manage existing aggregator configurations or create cross-Region search capabilities
-
You want enhanced control over index configuration and tagging
During manual setup, you may see indexing progress indicators in the console. A blue banner displays "Completing AWS Resource Explorer setup" while indexing is in progress, which changes to a green completion banner when setup is finished.
You can create a Resource Explorer index in an additional AWS Region by using the AWS Management Console, by using commands in the AWS Command Line Interface (AWS CLI), or by using API operations in an AWS SDK. You can create only one index in a Region.
Minimum permissions
To perform the steps in the following procedure, you must have the following permissions:
-
Action:
resource-explorer-2:*– Resource: no specific resource (*) -
Action:
iam:CreateServiceLinkedRole– Resource: no specific resource (*)