A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Just an update.
This works when you put the DCR on Tenant B. Since the WEC is in Tenant B, the setup aligns to MS statement below.
*Microsoft documents that a DCR can collect from machines across subscriptions/tenants and send to a Log Analytics workspace in another tenant when Azure Lighthouse is enabled. The DCR should be in the same region as the destination Log Analytics workspace.
*The rationale: the WEC VM in Tenant B uses a managed identity that the DCR in Tenant A could not recognize so the authentication fails. When we moved the DCR to Tenant B, it is able to authenticate the managed identity of the WEC VM allowing the DCR settings to be downloaded and applied. Then the ingestion flow to Tenant A's Log Analytics Workspace.