Hi @raja8220 ,
as @adonio said there are hundreds of answers to this question!
so in few words you have to create a lookup (called e.g. perimeter.csv) containing the hosts to check: at least one column (called e.g. host) with the hostname.
then run a search like this:
| metasearch index=cisco | eval host=lower(host) | stats count BY host | append [ inputlookup perimeter.csv | eval host=lower(host), count=0 | fields host count ] | stats sum(count) AS total BY host | where total=0
then schedule this search as an alert with the frequency you like.
You can also use this search (cutting the last row) to display a situation of your infrastructure:
tons of answers in this portal.
here are few that jumps out right away:
hope it helps