How can I create the alert for if host is power off(I have one windows host I'd,)
Finding something that is not there is not Splunk's strong suit. See this blog entry for a good write-up on it.https://www.duanewaddle.com/proving-a-negative/