> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/manage-cloud-instances.md).

# Manage cloud instances

You can manage the cloud instances configured for a CSP on the **Data Sources & Integrations** page. You can check the status, edit, delete, enable, or disable instances, and initiate discovery scan.

1. Navigate to **Settings → Data Sources & Integrations**.
2. Find the cloud instance by clicking the CSP name or using the **Search** field.
3. In the row for the cloud instance, click **View Details**. The **Cloud Instances** page is displayed, filtered by the CSP you selected.
4. In the **Cloud Instances** page, you can filter the results by any heading and value.
5. Click on an instance name to open the details pane for that instance.
6. You can perform the following actions on each cloud instance:

   <table><thead><tr><th width="194.8671875">Action</th><th>Instructions</th></tr></thead><tbody><tr><td>Discover Now</td><td>To initiate a discovery scan, in the row for the cloud instance, right-click and select <strong>Discover Now</strong>. Alternatively, in the details pane, click the more options icon and select <strong>Discover Now</strong>.</td></tr><tr><td>Enable/Disable</td><td>In the row for the cloud instance, right-click and select <strong>Enable</strong> or <strong>Disable</strong>. Alternatively, in the details pane, click the more options icon and select <strong>Enable</strong> or <strong>Disable</strong>.</td></tr><tr><td>Delete</td><td>In the row for the cloud instance, right-click and select <strong>Delete</strong>. Alternatively, in the details pane, click the more options icon and select <strong>Delete</strong>.</td></tr><tr><td>Create a new instance</td><td>Click <strong>New Instance</strong> and select the type of CSP of which you want to create a new instance. Follow the onboarding wizard to define its settings.</td></tr><tr><td>Edit configuration</td><td><p>In the row for the cloud instance, right-click and select <strong>Configuration</strong>. Alternatively, in the details pane, click the edit button. Follow the onboarding wizard to edit the cloud instance's settings.</p><p>(Optional) Under <strong>Show advanced settings</strong>, select <strong>Automation</strong> and select a log level for the automation integration logs.</p><p>You must execute the updated template in the CSP environment for the configuration changes to be applied.</p></td></tr></tbody></table>

### Cloud instance details pane

When you click an instance name, the details pane opens and shows the full health and configuration of that connector. The pane has three sections: the cloud instance overview, the **Security Capabilities** section, and the section that details the instance's resources.

#### Cloud instance overview

The overview shows the overall status of the instance and the following configuration details:

<table><thead><tr><th width="242.53125">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Status</strong></td><td>The overall health of the cloud instance: <strong>Connected</strong>, <strong>Warning</strong>, <strong>Error</strong>, or <strong>Disabled</strong>.</td></tr><tr><td><strong>Scope</strong></td><td>The number of accounts onboarded on the cloud instance and their individual statuses.</td></tr><tr><td><strong>Scan mode</strong></td><td>How Cortex Cloud scans your environment: <strong>Cloud Scan</strong> (Cortex-managed) or <strong>Outpost</strong> (customer-managed). For Outpost scan, the Outpost account ID and its status are also shown.</td></tr><tr><td><strong>Resource Tags</strong></td><td>Any custom tags applied to cloud resources during onboarding.</td></tr><tr><td><strong>Pending changes</strong></td><td>Displayed when a configuration edit has been saved but the updated template has not yet been redeployed in the cloud environment.</td></tr><tr><td><strong>Upgrade available</strong></td><td>Displayed when a newer version of the connector template is available.</td></tr></tbody></table>

#### Cloud instance status values

<table><thead><tr><th width="158.671875">Status</th><th>Meaning</th></tr></thead><tbody><tr><td><strong>Connected</strong></td><td>The cloud instance is enabled and has no issues.</td></tr><tr><td><strong>Warning</strong></td><td>The cloud instance is enabled and has minor issues. For example, some accounts or capabilities are in <strong>Warning</strong> or <strong>Error</strong> status.</td></tr><tr><td><strong>Error</strong></td><td>The cloud instance is enabled and has substantial errors. For example, an authentication failure, an Outpost failure, major permissions issues, or (for organization-level connectors) the majority of accounts are in <strong>Error</strong> status.</td></tr><tr><td><strong>Disabled</strong></td><td>The connector has been manually disabled.</td></tr></tbody></table>

#### Security capabilities

The **Security Capabilities** section lists every security capability that is active for this cloud instance, along with its current status. The capabilities shown depend on which ones were enabled during onboarding and on your license.

<table><thead><tr><th width="162.96875">Status</th><th>Meaning</th></tr></thead><tbody><tr><td><strong>Connected</strong></td><td>The capability is running with no issues.</td></tr><tr><td><strong>Warning</strong></td><td>The capability has minor issues that may affect coverage.</td></tr><tr><td><strong>Error</strong></td><td>The capability has significant issues that are affecting its function.</td></tr><tr><td><strong>Disabled</strong></td><td>The capability is not enabled for this connector, or the connector itself is disabled.</td></tr></tbody></table>

Click any capability row that shows a **Warning** or **Error** status. The **Issues** table is displayed. To view the specific errors contributing to the status, click the **Errors** tab. In the case of Permissions, click the **Missing Permissions** tab:

* **Errors** (or **Missing Permissions** in the case of Permissions) are factual records automatically created when a problem occurs, such as a missing permission or a failed API call. Browse and filter errors to understand the scope and nature of the problem.
* **Issues** are actionable objects triggered when detected problems exceed defined thresholds. Issues are trackable, include remediation suggestions, and can be assigned and managed. Click an issue to open it and start investigating.

For the Discovery Engine, a **Coverage** bar is shown alongside the status. This bar gives a proportional view of how many scans succeeded, warned, or failed, so you can see at a glance whether a problem affects a small or large portion of your environment.

#### Export errors to a file

For the Permissions, Discovery Engine, and Audit Logs capabilities, you can export the errors table to a TSV file. This lets you share, analyze, or track errors outside of Cortex Cloud, such as in a spreadsheet or ticketing system.

**To export errors:**

1. Click a capability row that shows a **Warning** or **Error** status to expand the errors table.
2. Click the **Export** button in the table toolbar.

The file downloads immediately to your browser's default download location. The filename follows the pattern `<capability>_<timestamp>.tsv`.

The exported file includes all columns visible in the errors table. For the Permissions and Discovery Engine capabilities, any accounts and regions grouped in the UI view are fully expanded in the export. Rather than appearing as separate entries, accounts and regions are combined into a single comma-separated string within a single row per error. For example, `account-1 (region-a, region-b), account-2 (region-c)`.

#### Cloud instance resources

The bottom section of the panel lists the individual cloud resources onboarded on this connector and their individual statuses. The section label and terminology depend on the cloud provider:<br>

<table><thead><tr><th width="217.609375">Cloud provider</th><th>Resource term</th></tr></thead><tbody><tr><td>AWS</td><td>Account</td></tr><tr><td>GCP</td><td>Project</td></tr><tr><td>Azure</td><td>Subscription</td></tr><tr><td>OCI</td><td>Compartment</td></tr><tr><td>Alibaba Cloud</td><td>Account</td></tr></tbody></table>

For cloud instances with multiple resources (for example, organization or organizational unit scope), click an individual entry to filter the **Security Capabilities** section by that resource. This lets you see which capabilities are failing for a specific account, project, subscription, or compartment rather than across the entire cloud instance.

#### Investigating errors further

To investigate errors in more depth, run XQL queries against the `cloud_health_auditing` dataset. This dataset records error and recovery events for each security capability, including when the error started, how frequently it occurs, and whether it has recovered.

{% hint style="info" %}

#### Note

Errors related to audit log collection are recorded in the `collection_auditing` dataset, not `cloud_health_auditing`.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/deployment-steps-and-checklist/cloud-service-provider-csp-onboarding/manage-cloud-instances.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
