log files have a different original purpose. But yes, if you repurpose your log files to track individual users granularly, that processing would be illegal without gathering informed consent first.
Unless it's necessary. The legitimate interests basis of the GDPR allows you to make a balanced decision of your business requirements against user privacy expectations.
hint, user-level analytics rarely is. And in this specific example, repurposing logs kept for one purpose(ex, security/auditing) to user analytics is definitely not something you can just do