Have a look at the fschange
functionality: http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/Monitorchangestoyourfilesystem
Like the docs page says though, sadly this feature is deprecated - it still exists, but it's not going to be developed and may eventually be dropped altogether from what I understand.
Otherwise, your best bet would be to use a scripted input that gathers the directory listings in a way you want and then sends them off to Splunk.
Have a look at the fschange
functionality: http://docs.splunk.com/Documentation/Splunk/5.0.2/Data/Monitorchangestoyourfilesystem
Like the docs page says though, sadly this feature is deprecated - it still exists, but it's not going to be developed and may eventually be dropped altogether from what I understand.
Otherwise, your best bet would be to use a scripted input that gathers the directory listings in a way you want and then sends them off to Splunk.