Skip to content

Quickstart

The rundev management command starts a complete local SIEMatic environment with SQLite and a self-signed certificate. It is intended for development and evaluation, not production.

Early-release alpha

SIEMatic is an alpha. It is suitable for evaluation and development, not for production reliance. For a production support contract, contact sales@mcindi.com.

Prerequisites

  • Python 3.12 or newer (CI exercises Python 3.13 and 3.14)
  • Git and pip

Install

Clone the repository, create a virtual environment, and install the runtime dependencies:

git clone https://github.com/mcindi/SIEMatic.git
cd SIEMatic
python -m venv .venv

Activate it on Windows PowerShell:

.venv\Scripts\Activate.ps1
pip install -r requirements.txt

Or on macOS and Linux:

source .venv/bin/activate
pip install -r requirements.txt

Start the stack

python manage.py rundev

No .env file is required. The command uses db.sqlite3, applies migrations, collects static assets, and creates certs/siematic.crt and certs/siematic.key when they are absent. It also creates or updates the siematic-admin development superuser with a random password. The command writes the credentials to rundev-superuser.txt in the repository root. It then supervises:

  • the HTTPS web application at https://localhost:8000/
  • the TLS WebSocket indexer at https://localhost:8001/
  • an authenticated agent running the cross-platform Sysmon, network-security, and host-security-posture plugins.

The browser will warn about the self-signed development certificate. After accepting it, use the username and password in rundev-superuser.txt to sign in. Allow several seconds for CPU, memory, disk, listening-port, active- connection, and host-posture events to become searchable. Press Ctrl+C to stop the process tree.

rundev-superuser.txt is ignored by Git and is overwritten with a newly generated password each time rundev starts. Treat it as a secret and use this account only in the local development environment.

When either port is occupied, choose alternatives:

python manage.py rundev --web-port 8443 --indexer-port 8444

Open the administration site

Sign in at https://localhost:8000/admin/ with the generated credentials in rundev-superuser.txt. See User and Permission Management before provisioning ordinary users or agent service accounts.

Open /search2/ and enter:

search --filter='index="sysmon"' --order-by='["-created"]' --limit=20

To inspect recently discovered listeners and active connections, use:

search --filter='index="network_security"' --order-by='["-created"]' --limit=20

To inspect host identity, interfaces, accounts, sessions, filesystems, and security-control posture, use:

search --filter='index="host_security_posture"' --order-by='["-created"]' --limit=20

Use the command help displayed beside the search form or consult the generated Search Command Reference.