if this information Source IP, Destination IP and Upload Size given in the log than you can display it. There is a Dashboard "Normalized Dashboard" if you configure this dashboard you can change the table in the event section.
Do you have any data source reporting bytes transferred? FW, proxy, netflows, etc?
I have integrated this with Fortigate Firewall for Syslog data only (no netflow). Do bytes transferred get logged in syslog ?
I'm not sure. Do you have a sample? Byte counts would probably be included in a "flow teardown" type message.
yes it does but they are not automatically accumulated to be of use in reporting.
You'd need to map them to proper interesting fields that would make sense in your case.
You can Also write an correlation rule that will do something similar, but it's not a reportable like give utilization by IP, it's more along the lines of deviation from a value type of rule.
I hope this helps
Ping me if you need more help.