We just tried switching the primary uplink back to the secondary WAN (WAN 2) - and the peer came up.
(We changed the primary uplink to WAN 1 from WAN 2 last week trying to stabilize our site-to-site VPN which was frequently going down. I didn't help - but didn't seem to make things worse other than today's discovery of the VPN peer being down.)
Guess the peer is somehow hard-wired to a specific uplink being the primary one? (Traffic is load balanced between uplinks, VPN "active-active" status doesn't seem to matter, nor does "immediate" vs. "graceful" failover.
Is there a way to configure it to work regardless of which uplink is primary?
P.S. The original question still stands though, how to track down the time a VPN peer went down or was last successfully used.