Skip to main content

Windows Monitor

Comprehensive real-time Windows system monitoring with rolling log display.

Features

100+ Monitors

System Monitoring

  • DNS - Real DNS queries with IP resolution
  • PROCESS - Process start/end with command lines
  • PROCESS_TREE - Process parent-child relationships
  • NETWORK - Connections, traffic, ARP table
  • SYSTEM - CPU, RAM, Swap, Disk
  • CPU_CORE - Per-core CPU usage
  • BANDWIDTH - Network bandwidth usage
  • PROC_RES - Top resource processes

Windows Services

  • SERVICE - Windows service state changes
  • SERVICE_DETAIL - Detailed service monitoring
  • FIREWALL - Firewall packet events
  • FW_RULES - Firewall rules changes

Event Logging

  • EVENTLOG - Windows Event Log entries
  • EVENTLOG_CH - Event log channels
  • WEF - Windows Event Forwarding
  • WER - Windows Error Reporting
  • WER_DETAIL - Detailed WER reports

Security

  • DEFENDER - Windows Defender status
  • DEF_EXCL - Defender exclusions
  • DEF_SCAN - Defender scans
  • DEF_BEHAV - Defender behavior
  • DEF_ATP - Defender ATP alerts
  • THREAT - Suspicious process detection
  • UAC - UAC settings
  • SMARTSCREEN - SmartScreen status
  • HELLO - Windows Hello/BitLocker
  • TPM_BL - TPM/BitLocker
  • LAPS - LAPS passwords
  • CRED - Credential manager
  • AUTORUN - Autorun entries
  • APPLOCKER - AppLocker events
  • APPCOMPAT - App compatibility
  • SECURITY - Failed login attempts

Registry & Configuration

  • REGISTRY - Registry changes
  • WMI - WMI events
  • HOSTS - Hosts file changes
  • PROXY - Proxy settings
  • AUTOPILOT - Autopilot status
  • GP - Group Policy changes
  • BOOT - Boot configuration
  • TZ - Timezone changes

Hardware

  • DEVICE - USB device changes
  • USB_DETAIL - Detailed USB devices
  • DRIVER - Driver load/unload
  • BATTERY - Battery status and charge
  • TEMP - CPU/GPU temperature
  • DISK_HEALTH - Disk SMART status
  • FAN - Fan speed
  • THERMAL - Thermal zones
  • GPU - GPU info
  • DISPLAY - Display settings
  • AUDIO - Audio devices
  • BT - Bluetooth
  • PRINTER - Printer queue

Network

  • LAN - LAN device discovery
  • WIFI - WiFi network profiles
  • SHARE - Network share changes
  • NETADAPTER - Network adapters
  • TCPSTATS - TCP statistics
  • NET_CONN - New network connections
  • NETPROF - Network profiles
  • DNS_CACHE - DNS cache
  • PORT - Port monitoring
  • WEB - Website availability

Files & Applications

  • FILE - File changes
  • DIR - Directory changes
  • APPLICATION - Application log changes
  • RECENT - Recent documents
  • JUMPLIST - Jump lists
  • TYPEDURL - Typed URLs
  • USERASSIST - User assist
  • BAGMRU - Bag MRU
  • PREFETCH - Prefetch files
  • AMCACHE - Amcache
  • LOGTAIL - Log file tailing

Windows Features

  • WUPDATE - Windows updates
  • WU_LOG - Windows Update log
  • WU_TELE - Update telemetry
  • FEATUPDATE - Feature updates
  • SOFTWARE - Installed software
  • WINFEAT - Windows features
  • STORE_APPS - Store apps
  • RECOVERY - Recovery status
  • SANDBOX - Windows Sandbox
  • WSL - WSL distros
  • DOCKER - Docker containers
  • HYPERV - Hyper-V VMs
  • IIS - IIS websites
  • SQL - SQL Server services
  • EXCHANGE - Exchange services
  • AD - Active Directory events

Advanced

  • POWERSHELL - PowerShell execution
  • WINRM - WinRM events
  • SYSMON - Sysmon events
  • SCHED_TASK - Scheduled tasks
  • TASK_EXEC - Task execution
  • CLOUD - Cloud sync (OneDrive, Dropbox, Google Drive)
  • WAC - Windows Admin Center
  • WPR - Windows Performance Recorder
  • MEMDIAG - Memory diagnostic
  • RESET - Windows Reset
  • CRYPTO - Crypto keys
  • CERT - Certificates
  • SETUPAPI - SetupAPI log
  • PERFMON - Performance counters

Rich Event Details

Every event includes:

  • Timestamp with millisecond precision
  • Source monitor name
  • Event category
  • Severity level (DEBUG/INFO/NOTICE/WARNING/ERROR/CRITICAL)
  • Detailed message
  • Structured data fields with location information
  • Bookmark and highlight support

Multiple View Modes

  • Normal - Standard scrolling log
  • Dashboard - Statistics overview
  • Alerts - Filtered warnings and errors
  • Tree - Process tree view
  • Compact - Condensed one-line format

Advanced Features

  • Dated Folder Logging - Organize logs by date and time
  • 30-Day Auto-Cleanup - Automatic log rotation and cleanup
  • Auto-Start - Add to Windows startup
  • EXE Build - Compile to standalone executable
  • Sound Alerts - Audio alerts for warnings and errors
  • Event Export - Export to JSON/CSV
  • Full-Screen Display - No gaps, continuous scrolling
  • Slow Mode - Comfortable reading speed
  • Event Deduplication - 5-second window to reduce noise
  • Regex Search - Advanced text filtering
  • Source Filtering - Filter by monitor source
  • Bookmarks - Mark important events
  • Highlights - Highlight specific sources

Installation

pip install windows-monitor

Quick Start

# Run with all monitors
windows-monitor

# Run with specific monitors disabled
windows-monitor --no-dns --no-services

# Enable dated folder logging
windows-monitor --log-dir D:/RollingLogMonitor

# Auto-start on boot
windows-monitor --auto-start

# Build EXE
windows-monitor --build-exe

Controls

  • ↑/↓ - Scroll up/down
  • PgUp/PgDn - Page scroll
  • Home/End - Jump to newest/oldest
  • Enter - View event detail
  • Space - Pause/resume
  • C - Clear events
  • D - Toggle data display
  • M - Toggle compact mode
  • B - Bookmark event
  • A - Toggle alerts
  • E - Export events
  • V - Cycle view mode
  • F - Filter by source
  • S - Quick source filter
  • / - Search text
  • H - Help
  • Q - Quit

Configuration

Create a config.json file:

{
  "interval": 1.0,
  "max_lines": 100,
  "domains": ["google.com", "github.com"],
  "disabled": ["dns", "browser"]
}

Run with: windows-monitor --config config.json

Log Structure

D:/RollingLogMonitor/
├── 2024-01-01/
│   ├── 10-30-00/
│   │   ├── dns.log
│   │   ├── process.log
│   │   └── network.log
│   └── 10-31-00/
│       └── ...
└── 2024-01-02/
    └── ...

Requirements

  • Windows 10/11
  • Python 3.8+
  • psutil

Building from Source

git clone https://github.com/example/windows-monitor.git
cd windows-monitor
pip install -e .

Building EXE

pip install windows-monitor[exe]
windows-monitor --build-exe

License

MIT

Metadata

Release files for windows-monitor 2.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for windows-monitor 2.0.0
File Size Uploaded
windows_monitor-2.0.0.tar.gz 54.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for windows-monitor 2.0.0
File Interpreter ABI Platform
windows_monitor-2.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 107.1 kB

Release files / windows_monitor-2.0.0.tar.gz

Download URL windows_monitor-2.0.0.tar.gz
Size 54.0 kB
Tags Source
SHA-256 checksum
How to use checksums
f4d6c906c294310866eb46805cab3a0589114a1a01e0880779f9a6918e24d6cc
BLAKE2b-256 checksum
How to use checksums
730335b0e4451ee7f6bb0014c95f907bbc40e1af27dd3d39b31a8da777126121
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release files / windows_monitor-2.0.0-py3-none-any.whl

Download URL windows_monitor-2.0.0-py3-none-any.whl
Size 53.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
dd297b206fbffccf554880aae3d48b991b6d5a08d1540ed219f0bda0f6da80ba
BLAKE2b-256 checksum
How to use checksums
bc34ad05c72c69e87927947eab0aadc1f42eb5228712266aac29311250e831a2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release history Release notifications | RSS feed

6.0.0

2 release files

5.0.0

2 release files

4.0.0

2 release files

3.0.0

2 release files

This release

2.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page