Windows Internals books likely touch on it.
Otherwise most in depth and readily accessible document I know of can be found here:
I was wondering whether there is any actual, throughout and in-depth documentation of Sysmon (ID's and its atributes) and sysmonconfig schema. Often I'm using the "Troubleshooting with the Windows Sysinternal tools" by Mark Russinovich and it is in great detail but very outdated. Can anyone give me some tip (forum, book, online material etc)