I'm using Packetbeat to capture traffic between hosts, as below, with the filter "final=true".
Just downloaded a 2.4 GB file and it indeed appeared in my query for the last 15m, which is good.
But, if I query for the last 4h, my entry does not show up at all any longer, while other hosts that transferred only 500MB, 100MB, etc. appear during the last 4h.
What I expected was to see my entry appearing in 15m, 30m, 1h, and even in 4h, because my 2.4 GB download is supposed to be the heaviest traffic for the last 4h.
Could an expert please explain this behavior so that it'd make sense?