Have you tested using the latest version of the forwarder? That is what I would try. I doubt updating the version of the forwarder without updating the Splunk indexer version will matter much in this case.
... View more
I would run this on one of the servers having the issue after you try and make the change on that host. And restart splunk. See if it still shows old value. If so you likely have another outputs.conf taking precedence somewhere.
/splunk btool outputs list
... View more