I am trying to determine the impact of using fschange on a large number of files.

Does Splunk check the time stamp of each and every file in the subdirectory with every poll interval or does Splunk register callback functions with the OS for changes to the directory or files?



To my knowledge, Splunk does not (currently, as of 4.2) register with any filesystem event API. You should pretty much count on polling. Not all platforms have these APIs, and the APIs vary greatly from platform to platform.

It's possible that Splunk (the company) has these types of improvements to fschange in their roadmap/plan. You should submit an enhancement request to help raise the importance of such changes within the product.