Monitoring Cisco router IPSec site to site VPN tunnel

By SA you mean a single IPSec/Phase II/Data SA associated with a VPN tunnel I guess.

You can’t. Right now you get only a summary for all the IPSec SAs associated with the VPN tunnel. So you should get this prefdata for the IPSec SAs:

  • IPSec active time (s)
  • IPSec Bytes in (byte/s)
  • IPSec Bytes out (byte/s)
  • IPSec packets in (/s)
  • IPSec packets out (/s)
  • IPSec packets dropped in (/s)
  • IPSec packets dropped out (/s)