Host-based Intrusion Detection System

Does anyone have any good info on a decent Host-based Intrusion Detection

System? Even though the Govt Orgz on the floor where I work sit behind a

firewall I have been informed that I need to implement a HIDS to protect my

network from the inside of the firewall. I have a meeting next week with a

group from Enterasys to hear about their DRAGON system (and get a free

lunch). Anybody got the goodz?