Hello,
Currently I am using Lighthouse to integrate Tenant A with Tenant B. Tenant A has a log analytics workspace and a Microsoft Sentinel, and is being used has a central SIEM for all log sources. We have used Lighthouse to have access to the Tenant B log analytics where they are configuring logs to be sent to. In order to create rules in our Microsoft Sentinel (Tenant A) over these logs located at Tenant B log analytics we also needed to create a Microsoft Sentinel in top of this log analytics.
Our problem is the costs that this architecture is incurring on Tenant B, so I would like to ask if anyone has any other option to have access to logs on a different Tenant while keeping costs lower as possible?
The Tenant B log analytics is located at West Europe.
While Tenant A log analytics and Sentinel are located in France Central.
Regards,