Usually this is because there are new logs arriving for that VDOM. Have you deleted that VDOM from the FortiGate as well? And is there is any other device forwarding logs from the FortiGate in question?
Yeah seen the same behavior. You can open a case with TAC. It has nothing to do with log_forward. If you craft a vdom and afterwards delete, if the FAZ picks it up it does NOT sync with FGT and delete the unused and deleted vdom