Ultimately this turned out to be a false alarm. Although the machine was under attack (on many levels: there was activity hitting the packet filter, trying all sorts of injection at the Apache level and having a go at SSH) the actual alert (based on looking in auth.log) was a false alarm based on a bad regexp.
Any particular reason you didn't want to use Snort or Bro?
Any particular reason you didn't want to use Snort or Bro?