Have you thought about getting this data via netflow and using the Netflow app on Splunkbase? It will give the details you are looking for I think.
Gotcha, the Netflow app won't work on windows. The Splunk App for Cisco firewall will have the field extractions you are looking for and may already have a view for amount of traffic based on IP. I think it is fine on windows from what I recall.