I'll recommend using the following documentation https://learn.microsoft.com/en-us/entra/identity/monitoring-health/howto-stream-logs-to-event-hub?tabs=splunk
If this response was helpful, please consider accepting it. Feel free to ask if you have more questions or need further assistance!