Central logging reduces local erasure risk

If logs only exist on the machine that produced them, whoever compromises that machine can rewrite the story.

Clearing local logs is one of the first things an intruder does. Shipping them off the host as they are written means the attacker has to compromise the logging platform as well, which is a meaningfully harder job. It is also the only way to correlate across systems, so it pays twice.

More on Logging and telemetry