> Source?
Experience. I've set up SELinux, AppArmor, etc. For example back near 2000 a lot of Apache servers I worked on were running as root, now few are, and better still many have limited permissions even as their user/group.
The same can be said for many Linux services today. And better still the few that HAVE to run as root often come shipped with some level of permission controls to limit exposure.
I can link you to a random book on Linux access controls and security if you want an actual third party source. Or be a total dick and link to a man-page.
> intercept where?
It depends which system you're using to send logs remotely (and how it is configured). Sometimes the filesystem, sometimes IPC, etc.
e.g. http://www.rsyslog.com/doc/queues.html
>> Most attackers have to start outside and fight their way in which will generate plenty of logs for either external logging or FSS.
> Source?
Source on, what? That attackers who break into systems generate logs? You REALLY need a source on that, REALLY? Come on now.
> Point is, thus far they have not, and their first choice was not what the author views as more secure.
Alright, and then criticise them for that. If the article had been about systemd's lack of remote logging that would have been one thing, but it was complaining that FSS was bad because systemd lacked remote logging. FSS existing is irrelevant.
Also, again, open source. Go implement shit.