Is there any way to check for forwarders that have not connected recently and include a "sourcetype, source or host" value from that down host?
Perhaps a subsearch with the metadata search for down forwarders?
| metadata type=hosts | sort recentTime desc | convert ctime(recentTime) as Recent_Time