@richgalloway yes I do, we have events coming in (assume index=fortinet).
However, I do not know how to write specific search query that can capture an event when the VPN is down. Also if I simply search "index = fortinet", how do you narrow the search to find events that shows a down VPN or tunnel? I could not find those events.
This is when it helps to understand your data. If you're not familiar with the Fortinet logs I suggest you reach out to someone in your company who is familiar with them so he or she can tell you what to look for.
Some basic searches to get started include looking for the word "down"
index=fortinet "down"
or the name of a VPN or tunnel
index=fortinet "<VPN or tunnel name>"