I started logging to a file from rsyslog also and this is what I get:
Jun 11 21:21:18 XXXXX_Miami CEF: 0|Fortinet|Fortigate|v6.2.3|00020|traffic:forward accept|3|deviceExternalId=FGT3HD3915805616 FTNTFGTlogid=0000000020 cat=traffic:forward FTNTFGTsubtype=forward FTNTFGTlevel=notice FTNTFGTvd=root FTNTFGTeventtime=1591928479063045578 FTNTFGTtz=-0500 src=192.168.5.55 spt=59415 deviceInboundInterface=port2 FTNTFGTsrcintfrole=lan dst=10.208.88.30 dpt=1433 deviceOutboundInterface=port3 FTNTFGTdstintfrole=undefined FTNTFGTsrcuuid=6512069e-1b00-51e5-da4b-77658b7aee03 FTNTFGTdstuuid=6512069e-1b00-51e5-da4b-77658b7aee03 externalId=116110501 proto=6 act=accept FTNTFGTpolicyid=60 FTNTFGTpolicytype=policy FTNTFGTpoluuid=c2c683a0-c9c2-51e7-097d-3e015d58eaf6 app=MS-SQL FTNTFGTdstcountry=Reserved FTNTFGTsrccountry=Reserved FTNTFGTtrandisp=noop FTNTFGTduration=23503 out=77046 in=89424 FTNTFGTsentpkt=1593 FTNTFGTrcvdpkt=1584 FTNTFGTappcat=unscanned FTNTFGTsentdelta=372 FTNTFGTrcvddelta=372
So where there is XXXXX_Miami that is the host or the appliance name. This XXXXX_Miami does not appear any where on the logs on azure.