Hogzilla IDS monitors the amount of data sent by each host in the protected network. An alert is send if a host sends an atypical amount of data.
There are some procedures to identify large Internet providers and discard them to avoid false positives.
The event may be refer to a data leak or an abused host.