On this repo are some various configuration files, references, and scripts Brian and I have used to help setup and maintain our ELK instances. These may not necessarily be the best way to do things, but it does get the job done.
http://www.slideshare.net/EricLuellen/elk-its-big-log-season
http://blogs.cisco.com/security/step-by-step-setup-of-elk-for-netflow-analytics
https://github.com/elastic/logstash/blob/v1.4.0/patterns/grok-patterns
https://grokdebug.herokuapp.com/
https://github.com/elastic/curator
http://blog.stevenmeyer.co.uk/2014/02/securing-kibana-and-elasticsearch-with-https-ssl.html
http://ossec-docs.readthedocs.org/en/latest/manual/
http://nxlog.org/products/nxlog-community-edition/download
https://mbrownnyc.wordpress.com/2012/11/08/nxlog-configure-pattern-matching/
https://blog.codecentric.de/en/2014/05/elasticsearch-indexing-performance-cheatsheet/ https://www.elastic.co/blog/performance-considerations-elasticsearch-indexing https://www.loggly.com/blog/nine-tips-configuring-elasticsearch-for-high-performance/
http://blog.takipi.com/log-management-tools-face-off-splunk-vs-logstash-vs-sumo-logic/