I can't think of an elegant way off the top of my head unless you have something you can export flow data from. A couple things you might try:
1. Put an ACL on the inside interface against outpount traffic. Make sure the ACL is set to allow IP any any with the "log" switch. At least then you can watch your syslogs to see if any one device on the inside is hitting the ACL more than others and you will have source/destination IP addresses to look into.
2. You have a managed switch between your LAN and PIX, try creating a port span and connecting a laptop to the receiving switchport. Use wireshark to capture the traffic when you see it spike.
If this posts answers your question or is helpful, please consider rating it and/or marking as answered.
If this posts answers your question or is helpful, please consider rating it and/or marking as answered.