@Matt Brown... Not sure about your powershell script, but for a lot of the process and file auditing features of OSQuery, the queries return deltas from the last query. It is waaaaay cheaper from the Splunk perspective to only pickup create/delete/modify events rather than dumping a list of all running processes, kernel modules, etc.