Update:
Research by PAN-support revealed that this depletion in our case, is related to traffic with destination address 173.255.112.173 (stream.pushbullet.com/). The application is classsified in the session table as 'pushbullet', then changes to 'websocket' and finishes off as 'web-browsing' when logged.
The sessions are persistent throug the firewall even when the client is disconnected.
Even if the number of sessions to stream.pushbullet.com are modest, it seems somehow to bleed out the 'software packet buffer 0' If this occcurs,it did help in our case to run a 'clear session all filter destination 173.255.112.173' Also if the depletion causes problems (if all software packet buffer 0-4 are depleted, possibly dataplane reset), create firewall rule denying traffic to 173.255.112.173.
(Thanks a lot to PAN-support engineer Nikola for invaluable help)
... View more