The vector Splunk_hec_log [1] support compression algorithms gzip,snappy,zlib and zstd. It seems the server splunk HEC only supports gzip(I am using docker.io/splunk/splunk 9.2). Does splunk HEC support snappy,zlib or zstd? Is this possible to enable this algorithms beside of gzip?
[1] https://vector.dev/docs/reference/configuration/sinks/splunk_hec_logs/#compression
As my colleague used to say - "Try and see". Set up a HEC input and try to push a few requests using different compression methods.
As far as I remember, there are no settings for selectively enabling/disabling compression (methods) on HTTP level so you'll either hit something that Splunk can process or you'll get an error.