Keep in mind that the initial IKE Phase 1 tunnel will never stay continuously up longer than the "Renegotiate IKE security associations every" SA timer expressed in minutes (1440 by default). Similarly the IPSec tunnel will never stay continuously up longer than the "Renegotiate IPSec security associations every" SA timer expressed in seconds (3600 by default). However when the SA Lifetime is reached for either of these tunnels associated with a VPN Community, if there is still traffic trying to traverse the VPN connection (or Permanent Tunnels is enabled) then the tunnel will come right back.
That being said, other than examining "Key Exchange" events (key icon) in the firewall logs there is not really a direct way to see how long a tunnel has been continually available ("up" is probably not the proper term here) that I can find.
--
My book "Max Power: Check Point Firewall Performance Optimization"
now available via http://maxpowerfirewalls.com.
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com