Is there a way to configure Splunk Universal agent to filter events on each of the agent hosts and not on the Indexer?
I want to only send relevant events to indexer and not everything that exists in a path covered in inputs.conf
[monitor:///log/mongodb.log]
Nope, filtering cannot be done on a Universal Forwarder.
Your options are to either use heavy forwarders instead (these can perform filtering) or...well, to accept that filtering must otherwise be done on the indexer.