This is probably a good place to start:
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Wheretofindtheconfigurationfiles
Also, you need to know that truncation of events take place in the parsing phase, which can happen on either a heavy forwarder or an indexer, so there is no need to push such configs to a Universal forwarder. For more information on that subject, see;
http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings
Hope this helps,
Kristian
... View more