Does the Splunk HTTP Event Collector, splunk_hec(), support compression
The Splunk HTTP Event Collector does not support compression.
However, to increase performance when logging to Splunk there are two options that play a significant role in increasing throughput, workers and batch-lines.
Please see the following KB article for further details.
For a details on all splunk_hec() options please see “splunk-hec: Sending messages to Splunk HTTP Event Collector” in the Syslog-ng PE Admin Guide