You could use your monitoring solution, such as Nagios, to write a log entry when a server comes online. Alternatively, you can write a cron job (or scheduled task in windows) to check the list of machines and have that program write to Splunk read logs that the machine has come online. You could create the list to check from a lookup generated in Splunk, manually, or even from your IDS to drive the process.
If that system uses a Splunk Forwarder, you can check to see when it last connected with:
index=_internal "statusee=TcpInputProcessor" source="/opt/splunk/var/log/splunk/metrics.log" sourceHost=yourhost
... View more