What is the suspected issue? If you have a RAP and tunneled SSID, traffic will be end-to-end encrypted to the controller. That traffic will look like a single encrypted flow for intermediate devices.
If your issue is that you see 300+GB in one hour and none in the others, that can have to do with the reporting of the tool that you use.
Many of these tools use accounting records that only have start-time, end-time, and bytes transferred. For long living flows, like the RAP connection, that may give results like this. If you have many flows or short living flows the result will spread out and it may not be so obvious.