Skip to content
Notifications
Clear all

How do I filter out findings for non-production accounts?

6 Posts
6 Users
0 Reactions
27 Views
(@cloud_infra_newbie)
Honorable Member
Joined: 6 months ago
Posts: 367
Topic starter   [#22073]

Hey everyone, I'm still getting my head around InsightCloudSec and Terraform together. We have a multi-account setup (dev, stage, prod) and I'm getting overwhelmed with findings from all accounts in the dashboard.

I want to focus on production issues first. Is there a way to filter the findings view so it only shows alerts from our production AWS account? I looked at the "Environment" filter but we haven't tagged our accounts yet.

Maybe there's a better way using tags? Do I need to set up something in the InsightCloudSec side, or should I tag the accounts via Terraform and then filter? Here's how I'm defining our accounts in Terraform right now:

```hcl
module "prod_account" {
source = "./modules/account"
account_name = "prod"
account_email = "[email protected]"
}
```

What's the simplest way to make InsightCloudSec ignore or filter out the dev/stage findings? I saw something about "Clusters" but not sure if that's the right path. Thanks for any tips! 😅



   
Quote
(@emilyk)
Reputable Member
Joined: 3 months ago
Posts: 286
 

You're on the right track with tags. The "Environment" filter in ICS depends on the `Environment` tag being populated on the cloud account resource. Since you're using Terraform, the cleanest method is to add a standard set of tags in your account module, then ensure ICS is configured to ingest them.

Add an `environment` tag in your module definition:
```hcl
module "prod_account" {
source = "./modules/account"
account_name = "prod"
account_email = "[email protected]"
tags = {
Environment = "prod"
Owner = "platform-team"
}
}
```

After your next inventory collection in ICS, you can filter using the built-in "Environment" dropdown. You can also create a custom dashboard view or a policy that excludes resources where `Environment != prod`. Clusters are for grouping resources, but for your use case, account-level tagging is the more direct and maintainable approach.


Show me the numbers, not the roadmap.


   
ReplyQuote
(@aiden22)
Reputable Member
Joined: 3 months ago
Posts: 350
 

Tagging via Terraform is the right method, but don't rely on ICS to pick up tags automatically. You must go to Settings > Cloud Accounts and edit the account to manually assign the "Environment" there using the tags you've created. The filter works off this setting, not the raw AWS tags directly.

Clusters are for logical grouping, not environment filtering. They won't solve your immediate problem.

Quickest temporary fix: Use the account name filter in the findings dashboard. Type your prod account name or ID. It's manual but works now while you sort the tagging.


Show me the bill


   
ReplyQuote
(@cost_observer_42)
Honorable Member
Joined: 4 months ago
Posts: 407
 

Wait, you have to manually assign the environment in the ICS settings *even after* tagging the account in AWS? That seems like a strange extra step. What's the point of ingesting tags if you then have to re-key them?

I've seen this kind of duplication cause problems. Someone updates the Terraform tags, but the platform team forgets to update the ICS settings, and suddenly your "prod" filters are missing half the resources. It creates two sources of truth.

The account name filter is the only reliable method until you automate that sync, honestly.


cost_observer_42


   
ReplyQuote
(@alexf)
Reputable Member
Joined: 3 months ago
Posts: 233
 

Exactly. The manual sync is a known pain point.

We solved it by scripting the ICS API to pull the AWS tags and auto-update the account settings. It runs after each Terraform apply. Takes the platform team out of the loop entirely.

If your team can't automate it yet, the account name filter is your safest bet. Tag drift will burn you.


Optimize or die.


   
ReplyQuote
(@harperk)
Honorable Member
Joined: 3 months ago
Posts: 537
 

Everyone's telling you to tag your way out of it, but honestly, the "Environment" filter in ICS is a bit of a trap unless your team's process is airtight. The second you have a tag mismatch between your Terraform and the ICS console, your filter silently fails and you're back to scanning noise.

The simplest thing you can do right now is use the account name filter in the findings dashboard. Just type your prod account name or ID. It's manual, but it's immediate and guaranteed to work, no tagging required.

If you go the tag route, you're committing to automating the sync into ICS settings, otherwise you'll create a configuration drift headache. The Terraform tag alone doesn't cut it; ICS needs you to manually map it in the UI, which is where everyone falls down. So pick your poison: a manual filter you run every time, or a small automation script to keep the two systems in sync.


Data over dogma.


   
ReplyQuote