I have a JSON log file that I'm attempting to ingest (Splunk v6.6.5). The events parse correctly, but the epoch time isn't being used as the event timestamp. Splunk is using the file modified date for the event timestamp.
Here's a sample record and my props config (which lives on the Indexers):
Everything looks good in the config. Have you looked to see if there is anything overriding that configuration that might be causing the date parsing problem? Use btool to see what Splunk is actually seeing as the configs:
splunk btool props list --debug | less
Then search for apm_json and see if the configs for that sourcetype match the above configs.