> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-inventory-assets/all-cloud-assets.md).

# All Cloud Assets

The **All Cloud Assets** page enables you to view all your cloud assets from the various cloud assets categories that you configured for collection from Google Cloud Platform, Microsoft Azure, and Amazon Web Services using the [Cloud Inventory data collector](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-cloud-assets.md).

To view the **All Cloud Assets** page, select Assets → Cloud Inventory → **All Cloud Assets**.

By default, the **All Cloud Assets** page displays all cloud assets according to the most recent time that the data was updated. To search for specific assets, use the filters above the results table to narrow the results. You can export the tables and respective asset views to a tab-separated values (TSV) file. From the **All Cloud Assets** page, you can also manage the asset's output using the right-click pivot menu. For more information, see [Manage Your Cloud Inventory Assets](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-inventory-assets/manage-your-cloud-inventory-assets.md).

The **All Cloud Assets** table is comprised of a number of common fields that are available when viewing any of the Specific Cloud Assets pages. The **Type** and **Subtype** fields are only available in the **All Cloud Assets** table as these fields determine the **Specific Cloud Assets** categories, and can be used to filter the different types of assets from the entire list of assets.

When any row in the table is selected, a side panel on the right with greater details is displayed, where you can view additional data divided by sections, such as **Asset Metadata** and **Asset Editors**. The **Asset Editors** section also provides a link to open a predefined query in **XQL Search** on the **cloud\_audit\_log** dataset to view the edit operations by the identity selected for this asset in the last seven days.

The following table describes the fields available when viewing **All Cloud Assets**.

{% hint style="info" %}

### Note

Certain fields are exposed and hidden by default. An asterisk (\*) is beside every field that is exposed by default.
{% endhint %}

| Field                       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| --------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Avaiblitity zone\*          | Displays the **Availability zone** according to the cloud provider.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Cloud tags\*                | Displays any cloud tags or labels configured according to the cloud provider.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Creation time\*             | Displays the time that the cloud asset was created.¹ This information is not always available.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| External IPs\*              | Displays a list of external public IPs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| GEO region\*                | Displays the normalized value indicating the geographic region, such as North America or the Middle East.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Hierarchy\*                 | <p>Displays the hierarchy of the associated <strong>Project</strong> in the cloud provider separated by a forward slash (<code>/</code>) similar to a file path.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The <strong>Project</strong> is called something else in each cloud provider. For more information, see the <strong>Project</strong> description.</p></div>                                                                                                                                                                                        |
| Integration key             | Internal Cortex XDR identification of the integration collection.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Internal IPs\*              | Displays list of internal private IPs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Internet exposure (ports)\* | Displays a list of ports, where the details regarding these ports are available to view in the side panel.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Last reported status\*      | Last reported status of the asset, such as **Available** or **Ready**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Name\*                      | Name that describes the asset as given in the cloud provider if provided.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Project\*                   | <p>Displays the associated project name as provided by the Cloud provider. For each cloud provider, the project is called something else.</p><ul><li><strong>AWS</strong>: account</li><li><strong>GCP</strong>: project</li><li><strong>Microsoft Azure</strong>: subscription</li></ul>                                                                                                                                                                                                                                                                                                                                                |
| Project ID                  | Displays the associated project ID as provided by the Cloud provider, where the project is called something else in each cloud provider. See **Project** description.                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Provider\*                  | The cloud provider used to collect these cloud assets is either **GCP**, **AWS**, or **Azure**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Raw asset                   | Internal Cortex XDR debug information that displays the raw data used to parse the data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Region\*                    | Displays the region as provided by the Cloud provider.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Resource group              | Displays the **Rserouce group** when using an Azure **Provider**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Resource ID                 | Displays the **Resource ID** as provided by the cloud provider.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Secondary asset ID          | Displays a **Secondary asset ID** provided by the cloud provider that is used in Cortex XDR to identify the asset if a **Name** is not provided.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Subtype\*                   | <p>The subtype of cloud asset based on the <strong>Type</strong> configured, which can be defined as one of the following.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Each Subtype is displayed with an icon beside it.</p></div><ul><li><strong>VM Instance</strong></li><li><strong>Bucket</strong></li><li><strong>Disk</strong></li><li><strong>Image</strong></li><li><strong>Subnet</strong></li><li><strong>Security Group</strong></li><li><strong>Other</strong></li></ul><p>This field is unique to the <strong>All Cloud Assets</strong> table.</p> |
| Type\*                      | <p>Type of cloud asset, which can be defined as one of the following.</p><ul><li><strong>Compute</strong></li><li><strong>Cloud Function</strong></li><li><strong>Storage</strong></li><li><strong>Other</strong></li></ul><p>This field is unique to the <strong>All Cloud Assets</strong> table.</p>                                                                                                                                                                                                                                                                                                                                   |
| Update time\*               | Displays the time that the cloud asset was updated. This information is not always available.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

Due to a known [AWS synchronization issue](https://github.com/aws/aws-cli/issues/3597), where the creation time displayed in the AWS Console does not match the actual time when the AWS Bucket was created, the **Creation time** in Cortex XDR does not always match the AWS Console as Cortex XDR displays the actual time.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-inventory-assets/all-cloud-assets.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
