I think you are on the right track. The truth is on the wire. Wireshark from client or pcap from the appliance. If it is that chatty, you should be able to identify the high volume destinations. You could then also netstat -not to find the owning process. Or use the sysinternals tool TCPview to help you see more on the client side.
... View more