That isn't enough log context to tell whether it's rekeying or what's happening. The only thing that shows definitively is the remote end is telling your end to delete the SA. Might be because it's rekeyed, or its lifetime expired, or the SA was deleted manually on the remote end, among other possibilities. What logs surround that?