It is funny that you should post this now. Up until 5 minutes ago was pulling my hair out trying to figure out where all of our bandwidth was going. I had the syslog set up and I kept coming up blank. Then, finally, the traffic problem stopped and the culprit showed up in the syslog as a single log entry for a 1.5GB file download. It was then that I realized that this is the wrong tool for the job. I need to syslog the lan traffic in real time, not wait for the transaction to complete so that it will show up in the fortilog. Of course that is somewhat of a rare occurrence, but it is still a lesson learned for me.
Your suggestion is a good one though. That would be a good quick and dirty tool for keeping tabs on things.