The root ftp logins were blocked, the problem seems to have been script kiddos in AU trying about 5 times a second to login. So in case anyone else was having this problem here you go:
The ftp logs are going to /var/log/messages (at least the connections anyway)
Download fail2ban, get the noarch rpm for your distro and install.
Edit /etc/fail2ban/jail.conf to suit your needs.
DO NOT try starting and stopping fail2ban with the init.d script, use fail2ban-client to control the server.
Install whois if you want details in the emails
After all that the log files stay manageable and the services are working like they're supposed to.
Thanks again Till and Falko.
Last edited by JaJunk; 10th May 2007 at 23:28.