Hi mara7,
take a look at this blog post below.
It might be easier to configure an app registration and create a logic app/event hub to pull the logs over to your log analytics workspace.
If you expect to scale to multiple tenants and several log sources, then setting up lighthouse with an 'upper tier sentinel instance' might make sense, but if this is a one-off then I'd consider the logic app approach.
Azure lighthouse and even Sentinel are free to stand up, so there's no harm in playing with your suggestion if you don't mind all the setup.