Never centralize logging. Log at the leaves and store it there. Push search predicates down to servers running on each leaf when/if needed. Log to sockets always; your FD can be a regular file if you want but keep the flexibility to change it later.
If you're doing distributed containers, lambdas, or other more ephemeral things, you just can't do logging at leaf unfortunately.