Snort is a network intrusion detection and prevention system with excels at traffic analysis and packet logging on IP networks. Using protocol analysis, content searching, and various pre-processors, Snort detects thousands of worms, vulnerability exploit attempts, port scans, and other suspicious behavior. Snort uses a flexible rule-based language to describe traffic that it should collect or pass, and a modular detection engine.
If your running a newtwork an IDS system gives you a level of security that is needed to keep your network secure.
out of these snort is one of the best.
http://www.snort.org/