The reason I needed to turn that on is because I'm being bombarded by attempts to access a blocked resource. The file "/etc/httpd/logs/error_log" is generating about 10 lines per second (about 1 or 2 from the same IP each second) with the following (truncated):
Ok, I figured it out, different log file and different regex required. Nothing like people spamming your server to get you learning a new skill (PERL/regex) at 4am: