To my knowledge, Splunk does not (currently, as of 4.2) register with any filesystem event API. You should pretty much count on polling. Not all platforms have these APIs, and the APIs vary greatly from platform to platform.
It's possible that Splunk (the company) has these types of improvements to fschange in their roadmap/plan. You should submit an enhancement request to help raise the importance of such changes within the product.