Log Analytics workspace design is one thing, and Centralized is really the most simple one.
This becomes even more complex when implementing Azure Automation Update Management because if you settle for multiple workspaces, you need to create one for each workspace. And if you're running Azure Sentinel, it's even more complex if you have multiple workspaces, even though the recently announced possibility Cross-workspace Analytics rules and Cross-workspace Hunting) - but it's not like click of a single button and you get cross-workspace functionality - it's still limited.
So maybe you're thinking of logging to multiple workspaces at the same time? Well no, not all workloads (like Linux) supports this and it means you have to configure the agents manually. So for us, that is a no-go.
So whatever you do, really -really- try to stick with one workspace is my suggestion.
Hope to see improvements here in the upcoming months!