Is it possible to deploy $SPLUNK_HOME/etc/log.cfg via the deployment server to my forwarders? I wish to reduce the footprint of my Lightweight Forwarders by reducing the log sizes as mentioned here: http://www.splunk.com/wiki/Community:MinimizingForwarderFootprint
I am currently handling this at initial Splunk installation time, however would prefer to offload this on to the Splunk deployment server.