Hi,
First of all, For Wazuh´s versions more recent than v3.8, we have a complete guide on How to configure Sysmon and then configure Wazuh to collect Sysmons events https://wazuh.com/blog/how-to-collect-windows-events-with-wazuh/.
Also in this link, you have available the mean of every Sysmon Event that is used in the guide.
Said this, I would like to ask you for some additional information:
If you have any questions, do not doubt to ask us.