This looks like a good tutorial but I've never tried it. In fact, this is my next project as well. I will be getting an old machine that I wan't to designate as an IDS using Snort/Acid/MySQL as well.
I'm not sure if I should use RedHat or Slackware for this project. I really like the ease of updating packages in RedHat.