View a markdown version of this page

What is Amazon Resource Explorer? - Amazon Resource Explorer
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

What is Amazon Resource Explorer?

Amazon Resource Explorer is a resource search and discovery service. With Resource Explorer, you can explore your resources, such as Amazon Elastic Compute Cloud instances, Amazon Kinesis streams, or Amazon DynamoDB tables, using an internet search engine-like experience. Resource Explorer allows you to easily search for your resources using resource metadata like names, tags, and IDs, and displays additional resource details from other Amazon services, such as Amazon Config and Amazon Cloud Control. You can add resource metadata using tags, and collectively manage resources in an application. Resource Explorer works across Amazon Web Services Regions in your account to simplify your cross-Region workloads.

Amazon Resource Explorer provides fast responses to your search queries by using indexes that are created and maintained by the Amazon Resource Explorer service. These indexes come in two types: Resource Explorer-owned indexes that provide immediate partial results, and user-owned indexes that provide complete results with automatic updates. Resource Explorer uses a variety of data sources to gather information about resources in your Amazon Web Services account. Resource Explorer stores that information in the indexes for Resource Explorer to search.

Beginning October 6, 2025, Resource Explorer is enabled by default in your Amazon Web Services account with no setup steps required to begin searching for and finding resources. When you first access Resource Explorer through the Amazon Web Services Management Console, Unified Search, or CLI/SDK/API, you'll automatically receive search functionality based on your IAM permissions, as explained later in this page under Are you a first-time Resource Explorer user?. Resource Explorer provides immediate search results in each Amazon Web Services Region you access, with Unified Search showing results from your current Amazon Web Services Region without requiring any additional configuration.

For enhanced functionality, you can search across multiple Amazon Web Services Regions by enabling cross-Region search with a single click or API call to select an aggregator Amazon Web Services Region. Organizations can set up multi-account search by enabling trusted access and using Amazon CloudFormation deployment. If you previously configured Resource Explorer with cross-Region search, your existing setup remains unchanged. You can now search for resources across hundreds of Amazon Web Services services, such as Amazon Elastic Compute Cloud instances, Amazon Kinesis streams, Amazon DynamoDB tables, and more, without any initial configuration, making it easier to manage resources and troubleshoot issues from the moment you access your account.

We want your feedback about this documentation

Our goal is to help you get everything you can from Resource Explorer. If this guide helps you to do that, then let us know. If the guide isn't helping you, then we want to hear from you so we can address the issue. Use the Feedback link that's in the upper-right corner of every page. That sends your comments directly to the writers of this guide. We review every submission, looking for opportunities to improve the documentation. Thank you in advance for your help!

Are you a first-time Resource Explorer user?

As a first-time user of Resource Explorer, you can start searching for resources immediately without any setup steps. You can access Resource Explorer through the Amazon Web Services Management Console, Unified Search, or CLI/SDK/API to begin finding your resources.

Your search experience is automatically enabled based on your IAM permissions. If you have, at minimum, the permissions in the AWSResourceExplorerReadOnlyAccess managed policy, you can immediately search in partial results (all tagged resources and supported untagged resources created after the immediate resource discovery release). Resource Explorer uses a service-linked channel to receive Amazon CloudTrail events on your behalf, and this visibility is available in the CloudTrail console across all supported Regions. For complete resource inventory with automatic updates, you'll also need the iam:CreateServiceLinkedRole permission (included in the AWSResourceExplorerFullAccess managed policy). After the service-linked role is created in your account by any user, subsequent users only need the permissions in the AWSResourceExplorerReadOnlyAccess managed policy to get complete results on first search in subsequent Regions.

To get the most from Resource Explorer, we recommend starting with search and then exploring these topics as needed:

Features of Resource Explorer

Resource Explorer provides the following features:

  • Automatic features (available immediately):

    • Resource Explorer is automatically enabled when you first access the service or search in Unified Search, providing immediate search functionality. Depending on your IAM permissions, you can view either partial results immediately or complete resource inventory with automatic updates.

    • Users can search for resources in their current Amazon Web Services Region through the Resource Explorer console, Unified Search, or CLI/SDK/API.

    • Users can use keywords, search operators, and attributes like tags to filter the search results to only matching resources.

    • When users find a resource in the search results, they can immediately go to the resource's native console to work with that resource.

  • Enhanced features (optional configuration):

    • Cross-Region search capability when you select an aggregator Amazon Web Services Region.

    • Multi-account search through Amazon Organizations integration.

    • Additional resource details from other Amazon services, such as Amazon Config and Amazon Cloud Control, directly in the Resource Explorer console.

    • Resource management using quick Actions in the Resource Explorer console to manage tags and add resources to new or existing applications.

    • Custom views that administrators can create to define which resources are available in search results, with different views for different user groups based on their needs.

    Manual configuration is only needed in specific cases:

    • When you need to add missing permissions

    • When you want enhanced features like cross-Region search

    • When you want to set up multi-account configurations

    • When you want to customize your Resource Explorer setup

  • Resource Explorer, like many other Amazon Web Services services, is eventually consistent. Resource Explorer achieves high availability by replicating data across multiple servers within Amazon data centers around the world. If a request to change some data is successful, the change is committed and safely stored. However, then the change must be replicated across Resource Explorer, which can take some time. As an example, this includes Resource Explorer finding a resource in one Amazon Web Services Region, and replicating that to the Amazon Web Services Region that contains the aggregator index for the account.

Resource Explorer supported Regions

The following are the other Amazon Web Services services whose primary purpose is to help you manage your Amazon resources:

myApplications in the Amazon Web Services Management Console

myApplications is an extension of the Amazon Web Services Management Console that helps you manage and monitor the cost, health, security posture, and performance of your applications in Amazon. Applications allow you to group resources and metadata. From the Amazon Web Services Management Console, you can access all of the applications in your account, view metrics across all applications, and review cost, security, and operations metrics from multiple Amazon services in a single view. myApplications includes resource information from the following Amazon services:

  • Amazon Resource Access Manager (Amazon RAM)

    Share the resources in one Amazon Web Services account with other Amazon Web Services accounts. If your account is managed by Amazon Organizations, you can use Amazon RAM to share resources with the accounts in an organizational unit, or all of the accounts in the organization. The shared resources work for users in those accounts just like they would if they were created in the local account.

  • Amazon Resource Groups

    Create groups for your Amazon resources. Then, you can use and manage each group as a unit instead of having to reference every resource individually. Your groups can consist of resources that are part of the same Amazon CloudFormation stack, or that are tagged with the same tags. Some resource types also support applying a configuration to a resource group to affect all relevant resources in that group.

  • Amazon Resource Groups Tagging API

    Tags are customer-defined metadata that you can attach to your resources. You can categorize your resources for purposes like cost allocation and attribute-based access control.

Pricing

Automatic setup and basic search functionality are available at no additional cost. There are no charges to search for resources by using Amazon Resource Explorer, including creating views, completing setup in Amazon Web Services Regions, or searching for resources.

In the process of building your resource inventory, Resource Explorer calls APIs on your behalf that may result in charges. Interacting with the resources that you find in your search results can result in usage charges that vary depending on the resource type and its Amazon Web Services service. Some sources of additional data available in the Resource Explorer console are from other Amazon Web Services services that can result in usage charges, such as Amazon Config. These sources are only used if you explicitly enable them in your account. For more information about how Amazon bills for the normal use of a specific resource type, refer to the documentation for that resource type's owning service.