I like @chanfoli's answer, but you can also do this:
Splunk 6: Is the deployment client phoning home?
index=_internal (*phonehome* component=DC*) OR (component=DC:HandshakeReplyHandler) host=hostname | sort _time | table _time host log_level message
In Splunk 5, the Splunk internal log format was a bit different. You could also use a similar search to identify clients that were phoning home yesterday, but have not phoned home today:
index=_internal (*phonehome* component=DC*) OR (component=DC:HandshakeReplyHandler) earliest=-2d | eval Day=if(_time>(now()-86400),"Today","Yesterday") | chart count by host day | where Yesterday>0 AND Today<0
Via splunk web on the deployment server. Go to settings->forwarder management, select the clients and type in part of the hostname in the filter text box. If it is phoning home it should show up there with app count and time since last phone-home.