I have seen alot of incoming and outgoing traffic, how could i know the user that makes use of it
Do you ever watch or read detective mysteries?
do you have netflow data?
=> will provide source and destination IP addresses that will give you a clue
=> if not then solarwinds have some free and pay-for tools that will let to view flow data. they used to have a free realtime analyser you'd run on your workstation. exporting netflow records from your border routers should be pretty standard in any environment.
How about your firewall logs?
=> should be recording flows, especially if you are natting
now you should have the source & destination IP addresses
=> which subnets are they on?
=> who is on those subnets?
=> who is on the specific IP addresses?
who is the sender?
=> netflix? pandora? youtube? company policy? HR opinion?
That you can achieve through Netflow traffic analyzer, top transmitter or top receiver for that link.