Thanks for the input Philip. And yes, I have traffic analysis set to detailed. When I noticed this users data usage I switched the traffic to detailed in hopes of getting more information on the activity. I believe you're right about it being peer-to-peer traffic, I was wanting to get more definitive evidence. You said "That to me indicates that traffic is being sent to 10.5.39.99". Okay ... I think I understand now ... I was expecting to see the ip address that was originating the traffic but like you said, there are a lot of flows (I may have to read up on the exact definition of a flow). I guess I'll have to use wireshark during the actual activity to see what's going on. fun.
... View more