We found that there was a device connected to the 3850 stack, which that device was configured as a port channel, however, on the 3850, it was just 2 ports. There were 28 trillion drops on that port in like 12 hours. I suppose its possible that blew out the buffers across the switch. After correcting that, we're not seeing drops as bad. We cleared the counters on the cisco last night after making that config change, and there have only be 108 pause input on the cisco.
I believe according the marketing numbers, the 15600 is good for 13.6gb throughput in threat prevention configuration. We hit high water marks of like 250mb on that 10gb interface. So why would the box tell the switch to slow down?
In regards to the QOS policy applied to the cisco port....
policy-map Firewall-ports
class class-default
bandwidth percent 100
queue-buffers ratio 100
interface tenGigabitEthernet 2/0/1
service-policy output Firewall-ports