Detecting attacks is best done with a specialised tool such as
snort.
You'll need something else for monitoring servers; but there are probably lots of solutions for that.
Mon comes to mind.
I'm not an expert in configuring/installing either one, but I've used both on Red Hat without problems.
--Charlie