Yes, the feature is called "fschange monitor" and you use it like this in inputs.conf
[fschange:<path>]
However, the feature is deprecated (although it hasn't been removed yet), so you might want to look at this
fschange deprecated, what are the options
Also, Splunk cannot do fschange and a regular monitor over the same files/directories.