There are a lot of amazing fancy services available... for a fee. We log billions of lines a year and use GrayLog because the other services are cost prohibitive.
This isn't because the auditor is going to care whether you have to log into 15 different hosts to grep for 20 different log lines; they have no idea what "grep" even is. It's because it's a lot of work to document 15 different processes coherently.
This idea is the basic lens through which people should be reading our recommendations here.