The others are in this case the DPAs.
The GDPR forbids any processing of personal data, unless ... If you have no really good reason to store the IP addresses longer than absolutely necessary, then the period should be as short as possible. Otherwise you have to explain it with good reasons and...
I strongly disagree. GDPR is pretty clear about one thing: It is forbidden to claim any personal data (ip adress is one of them) from users of the eu unless it is absolutly necessary (which i doubt for logfiles, because there are strikt rules too) or prescribed by law.