I think the way you request is not impossible, just too much burden. In a similar cases, I had ingested all 3 ( assuming size is low) , and get rid of 2 of them in search. I can provide you a search to clear other 2.
in a way requesting, I don't see it is happening with built in mechanisms of Splunk. However, if you are on windows, you can enable file monitoring in the folder,
http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/MonitorfilesystemchangesonWindows
From same documentation:
You must enable security auditing for the file(s) or director(ies) you want Splunk Enterprise to monitor changes to
When this is set, you will be able to capture file from file monitoring via Splunk search, you can pass path of the file to your script that does one of the following:
if it is deployment server, it can update the inputs file resides in \deployment-apps\your_application_for_forwarder
if it is a heavy forwarder that access to share, you can also set the same using Splunk REST Api.
I hope it helps
... View more