Speaking of Suricata, here is a distribution iso for Smooth-Sec, which is a Suricata + Snorby build on top of Ubuntu 10.04. I have not tried this, so I can’t attest to how easy it is to install or get ready, but it sounds like a promising IDS/IPS setup, even though the wiki (documentation?) is behind a sourceforge registration-wall.. The wiki is here!