I found this today and it is pretty good. It is a series of articles on the Snort Intrusion Detection System. The articles are written by Richard Bejtlich, the founder of TaoSecurity, BlackHat presenter, and the Director of Incident Response at GE. Topics cover installation, manipulation and data output.
Check out the Snort Report.