Skip to content

Repository files navigation

Platform Python Flask License

🛡️ tinySIEM

tinySIEM dashboard

A tiny, real-time Sysmon event viewer for Windows — in your browser.

tinySIEM reads the Microsoft-Windows-Sysmon/Operational event log, streams every event live to a local web dashboard, and lets you filter, search and explore what's happening on your machine. No database, no agents, no cloud — just Python, Flask and a browser.

Features

  • Live stream — new Sysmon events show up instantly (Server-Sent Events).
  • Event table — paginated, with a detail tooltip for every event.
  • Filters — per-column filters plus inclusion / exclusion rules that persist.
  • Volume chart — event volume over time; click a bar to filter by event ID.
  • Process tree — parent/child relationships from Sysmon Event ID 1.
  • Statistics — event ID distribution and per-process counts.
  • Dark / light mode.

Requirements

  • Windows 10 / 11 / Server
  • Sysmon installed and running
  • Python 3.8+ in your PATH
  • Administrator rights (needed to read the Sysmon log)

Usage

git clone https://github.com/ceofraud/tinySIEM.git
cd tinySIEM
.\run.ps1

run.ps1 asks for admin rights, creates a virtual environment, installs the dependencies, starts the server and opens http://localhost:5000.

Then:

  1. Pick how much history to load — the last N events, a timeframe, or a date range — and click Start Monitoring.

    Quick Start
  2. Watch events stream in. Toggle Live to pause, Chart to show the volume strip.

    Event table

  3. Filter with the ⏷ icons in the column headers, or open Filters to include / exclude events by process, user, event ID and more.

    Filters

  4. Explore with Tree (process tree) and Stats (event statistics).

    Process tree Statistics

Architecture

  ┌──────────────────────────────────────┐
  │  Windows Event Log                   │
  │  Microsoft-Windows-Sysmon/Operational│
  └──────────────────┬───────────────────┘
                     │  history (EvtQuery) + live (EvtSubscribe)
                     ▼
  ┌──────────────────────────────────────┐
  │  Python backend  (server/)           │
  │                                      │
  │   SysmonMonitor ──► EventParser      │
  │                        │ XML → dict  │
  │                        ▼             │
  │                      Queue           │
  │                        │             │
  │                        ▼             │
  │                  ClientManager       │
  │           (history buffer + fan-out) │
  │                        │             │
  │                  Flask  /stream      │
  └────────────────────────┬─────────────┘
                           │  Server-Sent Events
                           ▼
  ┌──────────────────────────────────────┐
  │  Browser dashboard  (static/)        │
  │  table · filters · chart · tree ·    │
  │  stats   (plain ES modules)          │
  └──────────────────────────────────────┘

Configuration

All settings are optional environment variables (defaults in server/config.py):

Variable Default Description
TINYSIEM_HOST 127.0.0.1 Interface to bind (loopback only by default)
TINYSIEM_PORT 5000 Web server port
TINYSIEM_DEBUG false Flask debug mode — never use with a non-loopback host
TINYSIEM_LOG_TYPE Microsoft-Windows-Sysmon/Operational Event channel to read
TINYSIEM_HISTORY_SIZE 500 Events replayed to newly connected clients
TINYSIEM_QUEUE_SIZE 5000 Internal queue capacity

Development

python -m venv venv
.\venv\Scripts\Activate
pip install -r requirements-dev.txt

python -m server          # run the server
python -m pytest          # tests (run without Windows/Sysmon)
python -m ruff check .    # lint
.\build.ps1               # build standalone .exe files (PyInstaller, Nuitka, cx_Freeze)

License

MIT

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages