A tiny, real-time Sysmon event viewer for Windows — in your browser.
tinySIEM reads the Microsoft-Windows-Sysmon/Operational event log, streams
every event live to a local web dashboard, and lets you filter, search and
explore what's happening on your machine. No database, no agents, no cloud —
just Python, Flask and a browser.
- Live stream — new Sysmon events show up instantly (Server-Sent Events).
- Event table — paginated, with a detail tooltip for every event.
- Filters — per-column filters plus inclusion / exclusion rules that persist.
- Volume chart — event volume over time; click a bar to filter by event ID.
- Process tree — parent/child relationships from Sysmon Event ID 1.
- Statistics — event ID distribution and per-process counts.
- Dark / light mode.
- Windows 10 / 11 / Server
- Sysmon installed and running
- Python 3.8+ in your
PATH - Administrator rights (needed to read the Sysmon log)
git clone https://github.com/ceofraud/tinySIEM.git
cd tinySIEM
.\run.ps1run.ps1 asks for admin rights, creates a virtual environment, installs the
dependencies, starts the server and opens http://localhost:5000.
Then:
-
Pick how much history to load — the last N events, a timeframe, or a date range — and click Start Monitoring.
-
Watch events stream in. Toggle Live to pause, Chart to show the volume strip.
-
Filter with the ⏷ icons in the column headers, or open Filters to include / exclude events by process, user, event ID and more.
-
Explore with Tree (process tree) and Stats (event statistics).
┌──────────────────────────────────────┐
│ Windows Event Log │
│ Microsoft-Windows-Sysmon/Operational│
└──────────────────┬───────────────────┘
│ history (EvtQuery) + live (EvtSubscribe)
▼
┌──────────────────────────────────────┐
│ Python backend (server/) │
│ │
│ SysmonMonitor ──► EventParser │
│ │ XML → dict │
│ ▼ │
│ Queue │
│ │ │
│ ▼ │
│ ClientManager │
│ (history buffer + fan-out) │
│ │ │
│ Flask /stream │
└────────────────────────┬─────────────┘
│ Server-Sent Events
▼
┌──────────────────────────────────────┐
│ Browser dashboard (static/) │
│ table · filters · chart · tree · │
│ stats (plain ES modules) │
└──────────────────────────────────────┘
All settings are optional environment variables (defaults in
server/config.py):
| Variable | Default | Description |
|---|---|---|
TINYSIEM_HOST |
127.0.0.1 |
Interface to bind (loopback only by default) |
TINYSIEM_PORT |
5000 |
Web server port |
TINYSIEM_DEBUG |
false |
Flask debug mode — never use with a non-loopback host |
TINYSIEM_LOG_TYPE |
Microsoft-Windows-Sysmon/Operational |
Event channel to read |
TINYSIEM_HISTORY_SIZE |
500 |
Events replayed to newly connected clients |
TINYSIEM_QUEUE_SIZE |
5000 |
Internal queue capacity |
python -m venv venv
.\venv\Scripts\Activate
pip install -r requirements-dev.txt
python -m server # run the server
python -m pytest # tests (run without Windows/Sysmon)
python -m ruff check . # lint
.\build.ps1 # build standalone .exe files (PyInstaller, Nuitka, cx_Freeze)



