How are other admins monitoring their servers to detect any unauthorized access and/or hacking attempts? In a larger organization it's easier to throw people at the problem but in a smaller shop how can you effectively monitor your servers?
I tend to scan through the server logs looking for anything that jumps out at me, but it's really easy to miss things. In one case we were tipped off by low hard drive space: our server was taken over as an FTP site - they did a great job hiding the files by messing with the FAT table. Unless you knew the specific name of the folder it wouldn't show up in Explorer, from DOS, or when searching for files.
What other techniques and/or tools are people using?