Hi Sean,
I can't say I've tried sysmon with AMA yet but everything you're doing sounds like you're doing it right.
I see you've figured out the right xpath filter to use in your data collection rule.
I haven't heard that AMA allows you to change which table your data ends up in so your observation is interesting.
I agree that you will have to change your functions to work with the new table.
Hopefully someone from Microsoft is listening so they can consider your experience when thinking about enhancements to the data collection rule and/or AMA.