I have the same issue, while installing the forwarder i have selected application and system eventlog as input and now i dont need that anymore. What needs to be done to stop sending the eventlog data to indexer?
Just go to the inputs.conf file on the forwarder and look at the monitor settings. Remove what you don't want from the file and restart Splunk. See the link below.
I checked inputs.conf file under $SPLUNK_HOME/etc/system/local/ but dont see any reference for Application eventlog. Am i looking at the right inputs.conf file?