If you enabled the connectors with the default output type (which is Alert, not nDepth or Alert,nDepth), then only the normalized events are sent. The normalized events are sent only for the enabled connectors.
Is the "excessive" bandwidth coming from 1 agent or multiple agents combined? Where are your agents relative to the LEM appliance - all in the same location or another location? You can check which connectors are turned on for a particular node from MANAGE > Nodes and the Gear icon > Connectors next to the agent node. You can change the sleep time from 1 (second) to say 10 (seconds) to see if it helps