Hello
So, the Windows event collection (OS default) maybe it is not flexible enough, defining Sysmon rules maybe help you with some events visibility, so I understand Sysmon as a good complement of Wazuh agent in some cases. The Winlogbeat use with a Wazuh agent doesn't make sense to me because the Wazuh agent covers all the Winlogbeat capabilities and offers a lot more.
Please let me know if you have any doubt.
Regards,
Alberto R