On the Purview appliance,
1. Do a "ifconfig"
2. Do a 'tcpdump -i gre1'
3. Is the SSA meant to pass traffic of is it just a collector for Netflow and mirroring data?
You want to see the presence of 'two-way' traffic, from both source and destination. I suspect that you will want netflow and policy enabled on both the ingress and return port of what your trying to capture (rx only), unless something else is mirroring a two way conversation to ge.1.5. In that case you would likely want to do a 'both' on the netflow port, and a pvid 0 on the policy, but be very careful with that, as it will drop traffic if it is inline with the actual data flow.