My office network connects as below. I see alot of intermediate network spikes to the internet. I suspect one of the servers is doing this. Is there a way I can pull these traffic from the SRX firewall and find out which server is doing this.
Except the on box "show security flow session" that Steve mentioned - you might use NetFlow for this.
Seting up a simple netflow analyzer is not a very difficult task. The setup consist of SRX configuration making it send statistical data to the tool (analyzer) runing on one of your hosts (might be even your Windows workstation). The SRX setup is quite simple. Thera are some free NetFlow analyzers out there you can use. (I use Solarwinds).