pretty old topic, but might be useful to someone:
$SPLUNK_HOME/etc/apps/search/local/inputs.conf
By following proper guidelines you can solve your problem.
I downvoted this post because not helpful
I downvoted this post because not productive
/bin/splunk remove monitor /name/of/previous/monitor
Just go to the inputs.conf file on the forwarder and look at the monitor settings. Remove what you don't want from the file and restart Splunk. See the link below.
http://docs.splunk.com/Documentation/Splunk/5.0/Data/Editinputs.conf
It must be located in another inputs.conf. Take a look at those as well.
http://docs.splunk.com/Documentation/Splunk/5.0/admin/Aboutconfigurationfiles
I checked inputs.conf file under $SPLUNK_HOME/etc/system/local/ but dont see any reference for Application eventlog. Am i looking at the right inputs.conf file?
I have the same issue, while installing the forwarder i have selected application and system eventlog as input and now i dont need that anymore. What needs to be done to stop sending the eventlog data to indexer?