Unless it's necessary. The legitimate interests basis of the GDPR allows you to make a balanced decision of your business requirements against user privacy expectations.
hint, user-level analytics rarely is. And in this specific example, repurposing logs kept for one purpose(ex, security/auditing) to user analytics is definitely not something you can just do
Below 30 days it's a grey area as long as you only store as much information as is technically necessary (so e.g. for 14 days IP addresses could be okay, ask your lawyer about specifics), but you definitely need to inform your users about this.
To make this processing legal, then GDPR demands that you inform your users, minimize the amount of PII, anonymize as soon as possible, and most of all not use this PII for other purposes.