Yep, it's a challenge with quick filling up diskspace.
I've got a colleague that's working with a script to select between flow logs vs flow_start and flow_end logs. Apparently my colleague noticed that the flow_start and flow_end logs which also show NAT information always write to the log even if that specific rule is not set to disable logging.
And then in that script you can merge different sources going to the same IP/port with hitcounters. This is useful to start adding more specific firewall rules. Oh well, busy busy 😉