Are those packets just passing across the switch? You can create an ACL on the ingress and the egress and count the number of packets ingressing vs. egressing. Keep in mind those ACLs can only be created if those packets can be identified (i.e., they have specific IP address or MAC addresses).