When viewing the Suspicious Conversations it appears to be only analyzing half of the SMTP and POP3 communications. There are bytes -> show 0 B for all entries. Is there a setting wrong. When in Full Analysis profile I see both ingress and egress data. Packet captures are done via a Aggregation tap.