I have multiple AWS accounts and would like to set up the AWS:description resource in these accounts to send data to Splunk. What is the best way to go about doing this, is it just setting up an IAM user in each account? And what would the policy look like?