Sysmon captures domain names and network.protocol for network connection events using event ID 3.
As a user of Elastic Defend, I would like all connection events to include the domain and network protocol for events to analyze when possible. There may be a cost to resolve the domain from the IP but it seems to be worth it based on how Sysmon does it today.