Getting an ELK stack up and running can be complicated, especially if not already familiar with the stack. But the basic components are:
Elasticsearch running on some server.
Kibana running, usually on the same server as Elasticsearch, connected to Elasticsearch.
Logstash or Filebeat running on your Suricata sensor forwarding the logs to Elasticsearch.
But then generally you are left on your own to build up nice Dashboards in Kibana, as Iām not aware of a simple way to share pre-built ones. Or you could also try out something like SELKS (Stamus Networks | SELKS) which does all of the above for you with some nice Dashboards.