In outputs.conf you can configure compressed = <boolean> to compress the data, but the documentation doesn't specify how the compression is done。
There is also no parameter specifying the compression method.
So my question is what compression is used by default, and whether there is any documentation on it to show that
TCP has it's own compression standards same is applied here.
Just like the Splunk protocol is undocumented, so too is the compression method. It may be a standard compression method or it may be proprietary like the protocol itself.
Splunk recommends using the compression available in SSL.