Yeah, that thought hadn't escaped me, but you wouldn't believe the number of INTERNET ACCESSIBLE boxes I find in pen tests that are only logging locally.
<Sigh> ... Sad, but very true.
I did figure out if you send the send the correct kill signal you can pause lots of logging, clear out the stuff you want removed, and then restart it. Obviously it depends on the logging app. I can never remember the correct signal name, and I am away from home right now so I can't look it up.