The only explanation I could think was that it was not uninstalled properly or it was over riding data somehow or it is was backlog?
If anyone has any idea what it might could be helpful thank you!
Do you see any Splunk process running ? Do you see any splunk process holding any files/IO open?
Have you rebooted the system since the uninstall? Do you still see connection from the old heavy forwarder to the indexers?
Are there other heavy forwarders the data could be coming from?
If the inputs.conf has the wrong hostname, the events will appear to be from a different host. This can happen when images are cloned.
The same is true for the GUID, if you are seeing license usage ensure there isn't another host using the same GUID.