We use Azure Log Analytics as our main log ingestion platform, we use standard and custom solutions, we even use it to ingest our own application logs using the ingestion API. This is a sound piece of technology. In particular the Security and Compliance Solution can be of great help in reaching GDPR compliance.
We engaged a few customers with Fortinet Fortigate solution for their internet access control and unfortunately they were not able to update all their appliances to the latest FortiOS release, the only only one that supports CEF and thus can be directly ingested in log analytics and processed by the Security and Compliance Solution.
So I developed a custom filter for the agent to ingest legacy logs and make them suitable for the Security and Compliance solution. You can find the preliminary documentation here and the PR in master branch of the OMS agent here. We’re currently using the solution in production without any noticeable glitch (read the caveats section in the documentation)
Hope this helps.