Within splunk add on for AWS - CloudWatch input type has a option to specify assume role (for multi aws account setup). However for the CloudWatch logs input type there is no assume role option. So each account should have a programmatic access user if we have to cloudwatch logs input?