You need to forward some kind of log or KPI information into Splunk first. Then you search on that data. Let's assume it is Windows and you are sending perfmon
into Splunk. You can track one of the KPIs or even the mere presence (or rather lack there of) of events arriving into Splunk to determine if the server is OK or not. Once you get a search working that correctly identifies servers that are down, you just save this search as an Alert and have it send you an email (or trap or whatever) whenever the search returns any results. More details are here:
http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Real-timeWindowsperformancemonitoring
http://www.splunk.com/view/SP-CAAAGYG