You would need to be specific about the information you mean, but the
answer is no. It's always good advice to not trust input from the
network (including the DNS), it's up to you to audit the syslog-ng
source code to see what sanity checks it puts on the input, and up to
you to ensure that your configuration doesn't compromise your security.

The FAQ just gives generally good advice. If someone can prove that
syslog-ng will never compromise a host's security because of filenames
created using macro expansion (good luck proving perfect security), then
I'll update the FAQ. It should be noted that many, if not most people do
use the hostname to log by directory and no ill effects have been
reported (to my knowledge) besides the junk directory names.

