I've managed to talk to the great @jamesspi on Slack about this, and for future reference:
Currently, the endpoint integration does not log raw UDP 53 traffic. It seems to be an exception because for DNS, there are more higher quality logs available directly from the OS. However, these logs unfortunately don't contain the contacted DNS server IP. So the data I was searching for is not there as it stands right now (7.15).