I've been a fan of Security Onion for a while. Richard Bejtlich's book "Practice of Network Security Monitoring" discusses setting it up and how to incorporate it into an operations center's routine.
Notably, Security Onion and other tools are very difficult to use in cloud environments where you don't control the network! There are ways of getting a sensor access to the relevant traffic, but they require careful architecture. Even when set up properly, encrypted traffic defeats much of the deep packet inspection-based monitoring.