Sending Azure Active Directory logs to Log Analytics does not work for sign-in logs.
Sending Azure Active Directory logs to Log Analytics as per (preview) feature https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/howto-integrate-activity-logs-with-log-analytics works for audit logs but not for sign-in logs (i.e. the former show up in Log Analytics; the latter don't). The same issue occurs with streaming these logs to an event hub.
Craig (MSFT) commented
Lack of identity data in the logs is a security issue, otherwise how do we track storage requests to a user?