AWS Resource Explorer now provides immediate access to resource search and discovery capabilities in a Region. With this launch, you no longer need to activate Resource Explorer to discover your resources. Learn more
Resource types you can search for with Resource Explorer
Resource Explorer supports resource types across numerous AWS services. Resource discovery happens
automatically when you access Resource Explorer with appropriate permissions. If you have, at minimum,
the permissions in the AWSResourceExplorerReadOnlyAccess managed policy, you can
immediately search all tagged resources and supported untagged resources created after the
immediate resource discovery release. For complete resource discovery with automatic updates, you'll
also need the iam:CreateServiceLinkedRole permission (included in the AWSResourceExplorerFullAccess managed policy). After the service-linked role is
created in your account by any user, subsequent users need only the permissions in the
AWSResourceExplorerReadOnlyAccess managed policy to get complete
results.
Topics
Some resource types are identified by Amazon resource name (ARN) strings that share a common format with another resource type. When this happens, Resource Explorer can report such resources as that other resource type. For list of resource types affected by this issue, see Resource types that appear as other types.
At this time, tags attached to AWS Identity and Access Management (IAM) resources, such as roles or users, can't be used for searching.
If you have encrypted access to some of your resources, Resource Explorer is unable to discover them. You will not see these resources in your search results.
The following tables list the resource types that are supported for searching in AWS Resource Explorer.
Note
As of October 13, 2025, Resource Explorer no longer supports the following resource types:
-
Amazon CloudWatch Evidently—
evidently:project -
Amazon CloudWatch Evidently—
evidently:project/experiment -
Amazon CloudWatch Evidently—
evidently:project/feature -
Amazon CloudWatch Evidently—
evidently:project/launch
As of October 1, 2025, Resource Explorer no longer supports the following resource types:
-
Amazon Quantum Ledger Database (Amazon QLDB) —
qldb:ledger -
Amazon Quantum Ledger Database (Amazon QLDB) —
qldb:stream
As of July 9, 2024, Resource Explorer no longer supports the following resource types:
-
Amazon Elastic Container Service —
ecs:task -
AWS Systems Manager —
ssm:automation-execution -
AWS Systems Manager —
ssm:patchbaseline
You can still use these resource types in their own services, but they are no longer indexed or searchable in Resource Explorer.
Supported services and resource types
Supported AWS services
Amazon API Gateway
-
apigateway:apis -
apigateway:apis/routes -
apigateway:apis/stages -
apigateway:restapis -
apigateway:restapis/deployments -
apigateway:restapis/resources -
apigateway:restapis/resources/methods -
apigateway:restapis/stages -
apigateway:vpclinks
AWS Amplify
-
amplify:apps/branches -
amplify:apps/domains
AWS App Runner
-
apprunner:autoscalingconfiguration -
apprunner:connection -
apprunner:service -
apprunner:vpcconnector
AWS AppConfig
-
appconfig:application -
appconfig:deploymentstrategy
Amazon AppFlow
-
appflow:flow
AppIntegrations
-
app-integrations:event-integration
AWS App Mesh
-
appmesh:mesh -
appmesh:mesh/virtualGateway -
appmesh:mesh/virtualGateway/gatewayRoute -
appmesh:mesh/virtualNode -
appmesh:mesh/virtualRouter -
appmesh:mesh/virtualRouter/route -
appmesh:mesh/virtualService
Amazon AppStream
-
appstream:app-block -
appstream:application -
appstream:fleet -
appstream:image-builder -
appstream:stack
AWS AppSync
-
appsync:apis
AWS Application Discovery Service
-
ds:directory
Amazon Application Recovery Controller (ARC)
-
route53-recovery-control:cluster -
route53-recovery-control:controlpanel/safetyrule
Amazon Athena
-
athena:datacatalog -
athena:workgroup
AWS Audit Manager
-
auditmanager:assessment
AWS Backup
-
backup:backup-plan -
backup:backup-vault -
backup:report-plan
AWS Backup gateway
-
backup-gateway:hypervisor
AWS Batch
-
batch:compute-environment -
batch:job-definition -
batch:job-queue -
batch:scheduling-policy
Amazon Bedrock
-
bedrock:agent -
bedrock:application-inference-profile -
bedrock:data-automation-project -
bedrock:flow -
bedrock:guardrail -
bedrock:knowledge-base -
bedrock:prompt -
bedrock:prompt-router
AWS Certificate Manager
-
acm:certificate
Amazon Chime
-
chime:app-instance -
chime:app-instance/bot -
chime:app-instance/user -
chime:media-insights-pipeline-configuration -
chime:media-pipeline -
chime:media-pipeline-kinesis-video-stream-pool -
chime:sma -
chime:vc
AWS Cloud Map
-
servicediscovery:service
AWS Cloud9
-
cloud9:environment
AWS CloudFormation
-
cloudformation:stack -
cloudformation:stackset
Amazon CloudFront
-
cloudfront:cache-policy -
cloudfront:continuous-deployment-policy -
cloudfront:distribution -
cloudfront:field-level-encryption-config -
cloudfront:field-level-encryption-profile -
cloudfront:function -
cloudfront:origin-access-control -
cloudfront:origin-access-identity -
cloudfront:origin-request-policy -
cloudfront:realtime-log-config -
cloudfront:response-headers-policy
AWS CloudTrail
-
cloudtrail:channel -
cloudtrail:eventdatastore -
cloudtrail:trail
Amazon CloudWatch
-
cloudwatch:alarm -
cloudwatch:dashboard -
cloudwatch:insight-rule -
cloudwatch:metric-stream
Amazon CloudWatch Logs
-
logs:destination -
logs:log-group
Amazon CloudWatch Observability Access Manager
-
oam:sink
Amazon CloudWatch RUM
-
rum:appmonitor
Amazon CloudWatch Synthetics
-
synthetics:canary -
synthetics:group
AWS CodeArtifact
-
codeartifact:domain -
codeartifact:repository
AWS CodeBuild
-
codebuild:project
AWS CodeCommit
-
codecommit:repository
AWS CodeConnections
-
codeconnections:connection
AWS CodeDeploy
-
codedeploy:application -
codedeploy:deploymentconfig
Amazon CodeGuru Profiler
-
codeguru-profiler:profilingGroup
Amazon CodeGuru Reviewer
-
codeguru-reviewer:association
AWS CodePipeline
-
codepipeline:pipeline -
codepipeline:webhook
AWS CodeStar Connections
-
codestar-connections:connection
Amazon Cognito Identity
-
cognito-identity:identitypool
Amazon Cognito IdentityPool
-
cognito-idp:userpool
Amazon Comprehend
-
comprehend:document-classifier -
comprehend:entity-recognizer
AWS Config
-
config:config-rule
Amazon Connect
-
connect:instance -
connect:instance/agent -
connect:instance/operating-hours -
connect:instance/rule -
connect:instance/task-template -
connect:instance/transfer-destination -
connect:phone-number
Amazon Connect Customer Profiles
-
profile:domains
Amazon Connect Wisdom
-
wisdom:assistant -
wisdom:association -
wisdom:knowledge-base
AWS Cost Explorer
-
ce:anomalymonitor -
ce:anomalysubscription
AWS Data Exchange
-
dataexchange:data-sets
AWS Data Pipeline
-
datapipeline:pipeline
AWS DataSync
-
datasync:location -
datasync:task
AWS Database Migration Service
-
dms:cert -
dms:endpoint -
dms:es -
dms:rep -
dms:subgrp -
dms:task
Amazon Detective
-
detective:graph
AWS Device Farm
-
devicefarm:project -
devicefarm:testgrid-project
Amazon DynamoDB
-
dynamodb:table
DynamoDB Accelerator
-
dax:cache
Amazon EC2 Auto Scaling
-
autoscaling:autoScalingGroup
EC2 Image Builder
-
imagebuilder:component -
imagebuilder:container-recipe -
imagebuilder:distribution-configuration -
imagebuilder:image -
imagebuilder:image-pipeline -
imagebuilder:image-recipe -
imagebuilder:infrastructure-configuration
Amazon EMR
-
elasticmapreduce:cluster
Amazon EMR Serverless
-
emr-serverless:applications
Amazon EMR on EKS
-
emr-containers:jobtemplates -
emr-containers:securityconfigurations -
emr-containers:virtualclusters -
emr-containers:virtualclusters/endpoints
Amazon ElastiCache
-
elasticache:cluster -
elasticache:globalreplicationgroup -
elasticache:parametergroup -
elasticache:replicationgroup -
elasticache:reserved-instance -
elasticache:snapshot -
elasticache:subnetgroup -
elasticache:user -
elasticache:usergroup
AWS Elastic Beanstalk
-
elasticbeanstalk:application -
elasticbeanstalk:applicationversion -
elasticbeanstalk:configurationtemplate -
elasticbeanstalk:environment
Amazon Elastic Compute Cloud (Amazon EC2)
-
ec2:capacity-reservation -
ec2:capacity-reservation-fleet -
ec2:carrier-gateway -
ec2:client-vpn-endpoint -
ec2:customer-gateway -
ec2:dedicated-host -
ec2:dhcp-options -
ec2:egress-only-internet-gateway -
ec2:elastic-ip -
ec2:fleet -
ec2:fpga-image -
ec2:host-reservation -
ec2:image -
ec2:instance -
ec2:instance-event-window -
ec2:internet-gateway -
ec2:ipam -
ec2:ipam-pool -
ec2:ipam-resource-discovery -
ec2:ipam-resource-discovery-association -
ec2:ipam-scope -
ec2:ipv4pool-ec2 -
ec2:key-pair -
ec2:launch-template -
ec2:natgateway -
ec2:network-acl -
ec2:network-insights-access-scope -
ec2:network-insights-access-scope-analysis -
ec2:network-insights-analysis -
ec2:network-insights-path -
ec2:network-interface -
ec2:placement-group -
ec2:prefix-list -
ec2:reserved-instances -
ec2:route-table -
ec2:security-group -
ec2:security-group-rule -
ec2:snapshot -
ec2:spot-fleet-request -
ec2:spot-instances-request -
ec2:subnet -
ec2:subnet-cidr-reservation -
ec2:traffic-mirror-filter -
ec2:traffic-mirror-filter-rule -
ec2:traffic-mirror-session -
ec2:traffic-mirror-target -
ec2:transit-gateway -
ec2:transit-gateway-attachment -
ec2:transit-gateway-connect-peer -
ec2:transit-gateway-multicast-domain -
ec2:transit-gateway-policy-table -
ec2:transit-gateway-route-table -
ec2:transit-gateway-route-table-announcement -
ec2:verified-access-endpoint -
ec2:verified-access-group -
ec2:verified-access-instance -
ec2:verified-access-trust-provider -
ec2:volume -
ec2:vpc -
ec2:vpc-endpoint -
ec2:vpc-flow-log -
ec2:vpc-peering-connection -
ec2:vpn-connection -
ec2:vpn-gateway
Amazon Elastic Container Registry
-
ecr:repository
Amazon Elastic Container Registry Public
-
ecr-public:repository
Amazon Elastic Container Service
-
ecs:capacity-provider -
ecs:cluster -
ecs:container-instance -
ecs:service -
ecs:task-definition -
ecs:task-set
Amazon Elastic File System
-
elasticfilesystem:access-point -
elasticfilesystem:file-system
Amazon Elastic Kubernetes Service (Amazon EKS)
-
eks:cluster -
eks:eks-anywhere-subscription -
eks:podidentityassociation
Elastic Load Balancing
-
elasticloadbalancing:listener-rule/app -
elasticloadbalancing:listener/app -
elasticloadbalancing:listener/net -
elasticloadbalancing:loadbalancer -
elasticloadbalancing:loadbalancer/app -
elasticloadbalancing:loadbalancer/net -
elasticloadbalancing:targetgroup
AWS Elemental MediaPackage
-
mediapackage:channels -
mediapackage:origin_endpoints
AWS Elemental MediaPackage VoD
-
mediapackage-vod:assets -
mediapackage-vod:packaging-configurations -
mediapackage-vod:packaging-groups
AWS Elemental MediaStore
-
mediastore:container
AWS Elemental MediaTailor
-
mediatailor:channel -
mediatailor:liveSource -
mediatailor:playbackConfiguration
Amazon CloudWatch Events
-
events:api-destination -
events:archive -
events:connection -
events:endpoint -
events:event-bus -
events:rule
Amazon EventBridge Pipes
-
pipes:pipe
Amazon EventBridge Scheduler
-
scheduler:schedule-group
Amazon EventBridge Schemas
-
schemas:discoverer
Amazon FSx
-
fsx:file-system
AWS Fault Injection Service
-
fis:experiment-template
Amazon FinSpace
-
finspace:environment
Firehose
-
firehose:deliverystream
Fleet Hub for AWS IoT Device Management
-
iotfleethub:application
Amazon Forecast
-
forecast:dataset -
forecast:dataset-group -
forecast:dataset-import-job -
forecast:forecast -
forecast:forecast-export-job -
forecast:predictor -
forecast:predictor-backtest-export-job
Amazon Fraud Detector
-
frauddetector:detector -
frauddetector:entity-type -
frauddetector:event-type -
frauddetector:external-model -
frauddetector:label -
frauddetector:model -
frauddetector:outcome -
frauddetector:variable
Amazon GameLift Servers
-
gamelift:alias -
gamelift:build -
gamelift:gamesessionqueue -
gamelift:location -
gamelift:matchmakingconfiguration -
gamelift:matchmakingruleset -
gamelift:script
AWS Global Accelerator
-
globalaccelerator:accelerator -
globalaccelerator:accelerator/listener -
globalaccelerator:accelerator/listener/endpoint-group
AWS Glue
-
glue:crawler -
glue:database -
glue:job -
glue:mlTransform -
glue:table -
glue:trigger
AWS Glue DataBrew
-
databrew:dataset -
databrew:job -
databrew:project -
databrew:recipe -
databrew:ruleset -
databrew:schedule
AWS Ground Station
-
groundstation:config -
groundstation:dataflow-endpoint-group -
groundstation:mission-profile
Amazon GuardDuty
-
guardduty:detector -
guardduty:detector/filter -
guardduty:detector/ipset -
guardduty:detector/publishingDestination -
guardduty:detector/threatintelset -
guardduty:malware-protection-plan
AWS HealthLake
-
healthlake:datastore/fhir
AWS HealthOmics
-
omics:referenceStore -
omics:runGroup -
omics:workflow
IAM Access Analyzer
-
access-analyzer:analyzer
Amazon IVS
-
ivschat:logging-configuration -
ivschat:room
AWS Identity and Access Management
-
iam:group -
iam:instance-profile -
iam:mfa -
iam:oidc-provider -
iam:policy -
iam:role -
iam:saml-provider -
iam:server-certificate -
iam:user
Amazon Inspector
-
inspector:target/template -
inspector2:filter
Amazon Interactive Video Service
-
ivs:channel -
ivs:playback-key -
ivs:recording-configuration -
ivs:stream-key
AWS IoT
-
iot:authorizer -
iot:billinggroup -
iot:cacert -
iot:cert -
iot:fleetmetric -
iot:jobtemplate -
iot:mitigationaction -
iot:policy -
iot:provisioningtemplate -
iot:rolealias -
iot:rule -
iot:ruledestination -
iot:scheduledaudit -
iot:securityprofile -
iot:thing -
iot:thinggroup -
iot:thingtype
AWS IoT Analytics
-
iotanalytics:channel -
iotanalytics:dataset -
iotanalytics:datastore -
iotanalytics:pipeline
AWS IoT Core Device Advisor
-
iotdeviceadvisor:suitedefinition
AWS IoT Events
-
iotevents:alarmModel -
iotevents:detectorModel -
iotevents:input
AWS IoT FleetWise
-
iotfleetwise:decoder-manifest -
iotfleetwise:model-manifest -
iotfleetwise:signal-catalog -
iotfleetwise:vehicle
AWS IoT Greengrass
-
greengrass:components:versions -
greengrass:connectorsDefinition -
greengrass:coresDefinition -
greengrass:devicesDefinition -
greengrass:functionsDefinition -
greengrass:groups -
greengrass:loggersDefinition -
greengrass:resourcesDefinition -
greengrass:subscriptionsDefinition
AWS IoT SiteWise
-
iotsitewise:access-policy -
iotsitewise:asset -
iotsitewise:asset-model -
iotsitewise:dashboard -
iotsitewise:gateway -
iotsitewise:portal -
iotsitewise:project
AWS IoT TwinMaker
-
iottwinmaker:workspace -
iottwinmaker:workspace/component-type -
iottwinmaker:workspace/entity
AWS IoT Wireless
-
iotwireless:Destination -
iotwireless:DeviceProfile -
iotwireless:FuotaTask -
iotwireless:MulticastGroup -
iotwireless:ServiceProfile -
iotwireless:SidewalkAccount -
iotwireless:WirelessDevice -
iotwireless:WirelessGateway -
iotwireless:WirelessGatewayTaskDefinition
Amazon Kendra
-
kendra:index -
kendra:index/access-control-configuration -
kendra:index/data-source -
kendra:index/experience -
kendra:index/faq -
kendra:index/featured-results-set -
kendra:index/query-suggestions-block-list -
kendra:index/thesaurus
AWS Key Management Service
-
kms:key
Amazon Kinesis
-
kinesis:stream
Amazon Managed Service for Apache Flink
-
kinesisanalytics:application
Amazon Kinesis Video Streams
-
kinesisvideo:channel -
kinesisvideo:stream
AWS Lambda
-
lambda:code-signing-config -
lambda:event-source-mapping -
lambda:function
Amazon Lex
-
lex:bot-alias
AWS License Manager
-
license-manager:grant
Amazon Location Service
-
geo:map -
geo:place-index -
geo:tracker
Amazon Lookout for Metrics
-
lookoutmetrics:Alert -
lookoutmetrics:AnomalyDetector
Amazon Lookout for Vision
-
lookoutvision:project
Amazon MQ
-
mq:broker -
mq:configuration
AWS Mainframe Modernization
-
m2:env
Amazon Managed Blockchain
-
managedblockchain:accessors
Amazon Managed Grafana
-
grafana:workspaces
Amazon Managed Service for Prometheus
-
aps:rulegroupsnamespace -
aps:workspace
Amazon Managed Streaming for Apache Kafka
-
kafka:cluster -
kafka:configuration
Amazon Managed Workflows for Apache Airflow
-
airflow:environment
Amazon MemoryDB
-
memorydb:acl -
memorydb:cluster -
memorydb:parametergroup -
memorydb:snapshot -
memorydb:subnetgroup -
memorydb:user
AWS Migration Hub Refactor Spaces
-
refactor-spaces:environment -
refactor-spaces:environment/application -
refactor-spaces:environment/application/route -
refactor-spaces:environment/application/service
AWS Mobile Targeting
-
mobiletargeting:apps/campaigns -
mobiletargeting:apps/segments -
mobiletargeting:templates/EMAIL -
mobiletargeting:templates/PUSH -
mobiletargeting:templates/SMS
AWS Network Firewall
-
network-firewall:firewall -
network-firewall:firewall-policy
AWS Network Manager
-
networkmanager:attachment -
networkmanager:core-network -
networkmanager:device -
networkmanager:global-network -
networkmanager:link
Amazon OpenSearch Service
-
es:domain
AWS Outposts
-
outposts:site
AWS Panorama
-
panorama:package
Amazon Personalize
-
personalize:dataset -
personalize:dataset-group -
personalize:schema -
personalize:solution
AWS Private Certificate Authority
-
acm-pca:certificate-authority
AWS Proton
-
proton:environment-account-connection -
proton:environment-template -
proton:service-template
Amazon Quick Suite
-
quicksight:dataset -
quicksight:datasource -
quicksight:template -
quicksight:theme
Amazon Redshift
-
redshift:cluster -
redshift:eventsubscription -
redshift:hsmclientcertificate -
redshift:parametergroup -
redshift:snapshot -
redshift:snapshotcopygrant -
redshift:snapshotschedule -
redshift:subnetgroup -
redshift:usagelimit
Amazon Rekognition
-
rekognition:project
Amazon Relational Database Service (Amazon RDS)
-
rds:auto-backup -
rds:cev -
rds:cluster -
rds:cluster-endpoint -
rds:cluster-pg -
rds:cluster-snapshot -
rds:db -
rds:db-proxy -
rds:db-proxy-endpoint -
rds:deployment -
rds:es -
rds:global-cluster -
rds:og -
rds:pg -
rds:ri -
rds:secgrp -
rds:snapshot -
rds:subgrp
AWS Resilience Hub
-
resiliencehub:resiliency-policy
AWS Resource Access Manager
-
ram:resource-share
AWS Resource Groups
-
resource-groups:group
AWS Resource Explorer
-
resource-explorer-2:index -
resource-explorer-2:view
Amazon Route 53
-
route53:domain -
route53:healthcheck -
route53:hostedzone
Amazon Route 53 Recovery Readiness
-
route53-recovery-readiness:readiness-check -
route53-recovery-readiness:recovery-group -
route53-recovery-readiness:resource-set
Amazon Route 53 Resolver
-
route53resolver:firewall-domain-list -
route53resolver:firewall-rule-group -
route53resolver:firewall-rule-group-association -
route53resolver:resolver-endpoint -
route53resolver:resolver-query-log-config -
route53resolver:resolver-rule
Amazon Glacier
-
glacier:vaults
Amazon SageMaker AI
-
sagemaker:action -
sagemaker:algorithm -
sagemaker:app -
sagemaker:app-image-config -
sagemaker:artifact -
sagemaker:cluster -
sagemaker:code-repository -
sagemaker:context -
sagemaker:domain -
sagemaker:endpoint -
sagemaker:endpoint-config -
sagemaker:experiment -
sagemaker:experiment-trial -
sagemaker:experiment-trial-component -
sagemaker:feature-group -
sagemaker:flow-definition -
sagemaker:hub -
sagemaker:human-task-ui -
sagemaker:image -
sagemaker:image-version -
sagemaker:inference-component -
sagemaker:inference-experiment -
sagemaker:mlflow-tracking-server -
sagemaker:model -
sagemaker:model-card -
sagemaker:model-package -
sagemaker:model-package-group -
sagemaker:notebook-instance -
sagemaker:notebook-instance-lifecycle-config -
sagemaker:pipeline -
sagemaker:project -
sagemaker:space -
sagemaker:studio-lifecycle-config -
sagemaker:user-profile -
sagemaker:workforce -
sagemaker:workteam
AWS Secrets Manager
-
secretsmanager:secret
AWS Service Catalog
-
servicecatalog:applications -
servicecatalog:attribute-groups
AWS Signer
-
signer:signing-profiles
Amazon Simple Email Service
-
ses:configuration-set -
ses:contact-list -
ses:dedicated-ip-pool -
ses:identity
Amazon Simple Notification Service
-
sns:topic
Amazon Simple Queue Service
-
sqs:queue
Amazon Simple Storage Service (Amazon S3)
-
s3:accesspoint -
s3:bucket -
s3:multiregionaccesspoint -
s3:storage-lens
AWS Step Functions States Language
-
states:activity -
states:stateMachine
Storage Gateway
-
storagegateway:gateway
AWS Systems Manager
-
ssm:association -
ssm:document -
ssm:maintenancewindow -
ssm:managed-instance -
ssm:parameter -
ssm:resource-data-sync -
ssm:session -
ssm:windowtarget -
ssm:windowtask
AWS Transfer Family
-
transfer:agreement -
transfer:certificate -
transfer:connector -
transfer:profile -
transfer:server -
transfer:user -
transfer:workflow
Amazon WorkSpaces
-
workspaces:connectionalias -
workspaces:workspace
Programmatically accessing the list of supported resource types
To access the list of supported resource types from code, you can invoke the ListSupportedResourceTypes operation from any AWS SDK.
For example, you can run the list-supported-resource-types
$aws resource-explorer-2 list-supported-resource-types{ "ResourceTypes": [ { "ResourceType": "acm-pca:certificate-authority", "Service": "acm-pca" }, { "ResourceType": "airflow:environment", "Service": "airflow" }, { "ResourceType": "amplify:branches", "Service": "amplify" }, ... truncated for brevity ...
Resource types that appear as other types
Some resource types are identified by Amazon resource name (ARN) strings that share a common format with another resource type. When this happens, Resource Explorer can report such resources as that other resource type. This affects the resource types in the following table.
| Actual resource type | Reported as resource type |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|