Hello,
1) To answer your first question:
You can configure something like below which will automatically send 'interface up/down' logs to syslog.
set system syslog host <IP of Syslog Server> any any.
Note:- Interface up event has severity of info & Interface down event has severity of warning. So any any can be changed accordingly.
2) To answer your second question:
If Primary ISP port & Secondary ISP port is in untrust zone, if one goes down & second is preferred, traffic will pass seamlessly if routing & other parameters are correct.
Regards,
Rushi