If I understand you correctly, you have two tenants. Both have Sentinel but one (Tenant A) is the primary.
Sentinel is billed based on data ingestion. Accessing the logs in another tenant should not incur an additional cost. Can you clarify more about the costs you are wanting to reduce?
Generally speaking, cost optimization involves reviewing the data being ingested to make a more informed decision about what data to collect or exclude. Use workbooks and queries to identify the most expensive data sources and largest contributors to those sources. Verify that the data has forensic value or is required for regulatory reasons. Work to filter away low-value, high-volume data at the source or through the data collection mechanism. You can also save by combining Defender for Cloud workspaces with Sentinel (due to the 500MB daily included per VM).
In practical terms this means filtering Syslog and Windows security events. You may also discover that operational issues can lead to higher than expected volume. For example, a faulty application or configuration leading to higher than expected log volume.