Obvious question: how do you filter out bot traffic with server side logs? What percent of visitors are bots anyway?
Script kiddie attack bots are generally fairly obvious as they hammer away at things like /wp-login.php for days on end regardless of what error codes the server returns.
Most other bots are pretty evident just by looking at access patterns. Just identify their IPs and drop them from your analytics.