You can do a debug/refresh which will not stop the Splunk service:
http://localhost:8000/en-US/debug/refresh
However, an App install or particular changes may require a Splunk restart.
... View more
Modify your inputs.conf monitor the actual log files in that path. If the logs end in .log, wild card the .log extension. You can also blacklist the .gz files etc...
... View more