I dont run packetbeat on prod systems, but its a fantastic auditing tool when you need to know whats going where without onerous pcaps.
nslookup uses an internal DNS engine so it doesn't get seen by Win32 DNS API. PacketBeat can be used to dissect raw DNS traffic on the client adapter. That's the only way, outside blocking port 53 outbound from usermode apps. Which might be interesting...