The problem with log files is that many people don't read them, particularly not proactively. Moreover, certain automated tools reading logs promote complacency--I;ve got tools checking for abnormalacy, I'm safe. Same thing happens with virus scanners that aren't kept up-to-date. However, if your business is running a hospital, how intrinsicly motivated are you to be secure? That isn't a core competency. It isn't even a profit center, at best it's meeting a mandate. Thus, most will do the least allowed to save cost. Mandating log files isn't mandating security.