Hello timqa,
Just a thought....
You could deploy a test laptop running wireshark, install a port mirroring switch and a set up a continous "Ring Buffer" file.
When the event is reported, you can go back to the timestampped file and analyze it in wireshark to see what happened at moment it happened.
This is not possible with the packet capture tool built into the NEC because the capture maxes out at 300 seconds.