IIRC a server log that retains IP addresses is covered under GDPR and may itself require disclosure via e.g. a popup. (IP addresses are part of the protected class of personal data.)
More to the point, server logs != modern Web analytics. Modern Web analytics require someone to ingest lots of data and run an app to allow users to analyze that data. Common practice outside of sensitive industries like healthcare and finance means offloading all of that ingestion/storage/management/analytics to a third party, hence 3P cookies.