If you look carefully, you can see the first column says "Destination". Since its the host itself, it means traffic coming to the device via that port. Flow means a group of packets with similar source IP and destination IP and port number. In this case, you have about 8 million unique flows. Very few applications reach that high and for client computer, that means some form of P2P application. Its entirely possible the client is using P2P Windows update but unlikely.
You can use packet capture when the client device is online to see what his traffic is doing. Just simply filter it to his MAC address or IP address.
Find my post helpful? Please give me a kudo!
CCNP Certified and Meraki Operator