If you are looking to integrate w ES, the ossecfileintegritymonitoring source type maps to change analysis and the ossecalert maps to alert data model.
You could adapt some of the existing correlation searches that use change analysis to fit this need or use the guided search to build a correlation search. You will want to think about how often you want to be alerted to these changes and if there is a certain threshold you would want to set.
Im trying to integrate it in Splunk enterprise, since we dont have enterprise security here, is it also possible on enterprise edition?
Yes. You can use the common information model and and the associated TA on splunkbase https://splunkbase.splunk.com/app/2808/ and build a datamodel search using the change analysis data model or you can just take the ossec data in and then build some searches based on what you see.