Philip,
It is probably a long shot, but any chance you could spin up a packet sniffer (tcpdump, tshark/wireshark) and set it up to filter on the incoming TCP/UDP data port number and save it to a PCAP file for an hour?
I have no idea how much raw data that would be, so maybe a shorter window, but given the frequency of occurrence the hope is that the file time stamp of an aborted / crashed in and_o or _e tsv file overlaps the PCAP file where one could look to identify the IP(s), and callsign(s) and the app reporting.
From my recollection, I thought most of that posted data was clear text, so it may be a vector to honing in on the culprit.
If you can do this, just post the PCAP file somewhere and send me a URL and I'll try to help and investigate further.
andyz - K1RA