Fortigate IPSEC tunnels

IS it possible to get IPSEC tunnels to report as down on libre?

I could only see ways to get the interfaces to report as down, however that also reports if a normal interface goes down?

ports.ifOperStatus = “down” AND ports.ifOperStatus_prev = “up” AND eventlog.datetime >= macros.past_5m

as well as

eventlog.message LIKE ‘%phase 1%’ AND eventlog.datetime >= macros.past_5m

syslog.msg LIKE ‘%phase 2%’ AND syslog.timestamp >= macros.past_5m

cheers