In Splunk Add-on for Sysmon | Splunkbase (and some other Add-Ons) XML extractions are done via a lot of manual transforms (e.g. [sysmon-version] REGEX = <Version>(\d+)</Version> FORMAT = Version::$1). Why aren't you using KV_MODE = XML?
And could you please add the field query_type (Network_Resolution DM) and record_type values for A and AAAA records (which do NOT have a type: .. entry).
I can't speak for the app's author, but one reason for using REGEX over KV_MODE is KV_MODE=xml only works on well-formed XML whereas REGEX often can extract fields from poorly-formatted XML events.
Sorry, but I would like an answer from the author of the app (as I already know what you wrote).