One of my co-workers was trying to find flows for a given subnet so I had them go to search by endpoint and put the subnet in.
It returned every IP in the subnet range, whether it had data flows or not.
I would think/request that when I put a range in like that, for a given time period, it would search the DB and return only IPs and flows for interfaces that have traffic.
We're working on our enhancing our filtering capabilities. In the meantime, you should be able to quickly create an IP address group for the subnet and then view the subnets flows in the Top XX IP Address Group resource.