This is the main screen of the SysMon viewer:
This is the configuration screen for building an event processor flow:
This is the event details screen:
A SysMon Alert: