Maybe instead of doing a trending search for no data, look into the metadata command to go by hosts, sourcetype, or source. Then make your alert based off of the hour last seen. | metadata type=sourcetypes index=google
| sort recentTime desc
| convert ctime(recentTime) as Recent_Time
| eval hours_since = round((now() - recentTime) / 3600,2)
... View more