Usually the graphs for "in", "out" and "service" overlap more or less as long as the in/out volume is similar.
Recently we noticed high spikes for "service" traffic on the active unit in a device group where mirroring is enabled for some virtual servers (in PerformanceL4 mode). At the same time we noticed high CPU and problems with some applications handled by the BIG-IP.
So perhaps the "service" traffic includes as well the mirrored traffic. I´m under the impression, that the mirroring failed somehow and caused the CPU and throughput (service) spikes.