The rule is " any to any" pass and extended logging is used
Active Blades: NGTX Package
question #1 : One session categorized "Unknown Traffic" , total bytes is 394.8 KB.
It has 12 connection, summarized total bytes more than 1.3GB
question #2: One session categorized "Weiyun" , total bytes is nothing.
It has 2 connection, summarized total bytes is 19.1KB
I don't think it's normal behavior.
question #3: One session categorized "Windows Update" , destination is "52.175.39.99"
SmartEvent aggregate data by Application only , can't aggregate data by destination (connection detination ip address)
Is it normal ?