
Explanation:
Box 1: 3
Number of workspace
One for Sub2, one for Sub3, and one for Sub4.
Note: Extend Microsoft Sentinel across workspaces and tenants
When you onboard Microsoft Sentinel, your first step is to select your Log Analytics workspace.
While you can get the full benefit of the Microsoft Sentinel experience with a single workspace, in some cases, you might want to extend your workspace to query and analyze your data across workspaces and tenants.
Box 2: Azure Lighthouse
Service
Manage workspaces across tenants using Azure Lighthouse
As mentioned above, in many scenarios, the different Log Analytics workspaces enabled for Microsoft Sentinels can be located in different Microsoft Entra tenants. You can use Azure Lighthouse to extend all cross-workspace activities across tenant boundaries, allowing users in your managing tenant to work on workspaces across all tenants.
Once Azure Lighthouse is onboarded, use the directory + subscription selector on the Azure portal to select all the subscriptions containing workspaces you want to manage, in order to ensure that they'll all be available in the different workspace selectors in the portal.
When using Azure Lighthouse, it's recommended to create a group for each Microsoft Sentinel role and delegate permissions from each tenant to those groups.
Reference:
https://learn.microsoft.com/en-us/azure/sentinel/extend-sentinel-across-workspaces-tenants
https://learn.microsoft.com/en-us/azure/sentinel/multiple-tenants-service-providers