by default the siem should deliver all Logs from the Datasource.
Try this: (you lost all logs befor)
Delete the datasource
And than add the datasource with all log configuration.
Try also is this dont work:
There is a McAfee Event Collector for Windows. Install this Event Collector to get all Logs from the Datasource. This collector is also for more Logsources from one Datasource.
You will have to deploy SIEM collector agent on the Domain controller to get the DNS logs. The basic wmi data source configuration will only pull basic system logs (system, application,security) you need the agent to pull the rest.
You can get the more detailed DNS logs by either using an agent such as the SIEM Collector, or by ingesting the logs via SCP, SFTP, CIFS share, etc. Either way, a WMI pull only gets you so much. Applications such as DNS, Exchange, IIS, etc, require agents or file pulls because Microsoft does not place all the wanted information in the event viewer and make it available for a WMI pull. Microsoft instead puts the interesting logs in a separate flat file.