Some suggestions I would make:
1 – tcpout:group1
forwardedindex.filter.disable = false
Then put the Indexes you want to forward in black and whitelist like you did for group 2. Ideally blacklisting Index6
2 – group2 looks good.
Once you make the change restart Splunk on that forwarder..
... View more