Hello Ken Korczynski,
Welcome to Microsoft Q&A Forum, thank you for posting your query here!
I understand that you are intended to send the logs from external tenant to Azure Event hub.
In this approach, as how you have been succeeded in sending logs to log analytics workspace using the Diagnostic settings, you can follow the same method to send logs to Even hub. and understood that you are using Azure Lighthouse to delegate a resource, which typically allows your external tenant to manage a workforce tenant resource.
So, once the customer has been onboarded, authorize the users by deploying an Azure Resource Manager template to the subscription that contains Azure Event Hub.
After this authorization is completed, the subscription and Event Hub can be selected as a target in the Diagnostic settings in external tenant.
The below article shows how you can stream your logs to an event hub by using one of the SIEM tools.
Once you have the Azure event hub ready, navigate to the any one of the SIEM tool that you want to integrate with the activity logs. so that you can send the logs to Azure event hub.
Hope this helps!
Please reply if you have any challenges.
Please do not forget to “upvote it” wherever the information provided helps you, this can be beneficial to other community members.it would be greatly appreciated and helpful to others.
Thanks