I've tried a couple of variations on my config file, I attached the current configuration to this reply.
{
"SourceModuleName": "xxxx_W3SVC1",
"SourceModuleType": "im_file",
"Hostname": "xxxx",
"Datacenter": "xxxx",
"log_type": "Azure Pack Website Log",
"date": "2016-09-27",
"time": "20:00:00",
"s_ip": "xxxx",
"cs_method": "GET",
"cs_uri_stem": "xxxx",
"cs_uri_query": "xxxx",
"s_port": 443,
"cs_username": "xxxx",
"c_ip": "xxxx",
"cs_User_Agent": null,
"cs_host": "xxxx",
"sc_status": 302,
"sc_substatus": 0,
"sc_win32_status": 64,
"sc_bytes": 0,
"cs_bytes": 136,
"time_taken": 46,
"EventTime": "2016-09-27 20:00:00",
"tag": "azurePack"
}
In the buffer file output, the data looks like this:
1970-01-01 00:33:36 azurePack {"SourceModuleName":"REDACTED_W3SVC1","SourceModuleType":"im_file","Hostname":"REDACTED","Datacenter":"xxxx","log_type":"Azure Pack Website Log","date":"2016-09-27","time":"22:03:19","s_ip":"x.x.x.x","cs_method":"GET","cs_uri_stem":"/404","cs_uri_query":"xxxx","s_port":443,"cs_username":"xxxx","c_ip":"xxxx","cs_User_Agent":"Mozilla/3.0+(compatible;+Indy+Library)","cs_host":"xxxx","sc_status":200,"sc_substatus":0,"sc_win32_status":0,"sc_bytes":30594,"cs_bytes":286,"time_taken":532,"EventTime":"2016-09-27 22:03:19"}
It does upload to S3, but it is doing so every minute rather than hour with a name of 1970010100_0.gz. The send to logentries works fine.
Essentially, it seems like for some reason time_slice_format isn't able to get the current time and is using the epoch?