I operate from the assumption that any serious compromise starting at SQLI injection equates to kernel compromise, so I don't spend a lot of time thinking about host-IDS either.
Tripwire is not a total waste of time, like a network IDS would be, but for most startups a minute spent setting up Tripwire is a minute that could be better spent on appsec.