Greetings Bjp106,
I hope that this note finds you well! Depending on what you are trying to solve, there are options available. If the VM/Instance is within an onboarded cloud account you can look at some of the examples that we have in RQL here (https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-rql-reference/rql-reference/rql-examples). You could potentially have a tag in a CFT or terraform template that would identify a newly created VM/Instance and, based on the CSP, create an RQL query that correlates to that tag returned in the JSON metadata to the CSPM console that could be additionally scoped to the service where the VM/Instance is located at the CSP level. Please let me know if you need any additional information and hopefully this direction helps!
Kind Regards,
J. Avery King
... View more