@CyberWarship And in regards to stopping 8002, I don't see a way to do this for the AppLocker channels. Anything outside of the security channel is mostly all or nothing with very few exceptions.
@CyberWarship You could setup winlogbeat to batch read the channels you care about while filtering in or out event_ids. This is what I do and it works great with many output options that support Splunk, Elasticsearch, Logstash, or even a file on the local system if you must.