It sounds like you'll want a rule that relies on some combination of Tool Profiles and User Defined Groups (UDG). The Tool Profiles allow you to group similar agents together for filters and rules. For example, you might have a Windows Server 2008 DC profile. If the agents you want to monitor with this rule are not exactly similar, then you'd use a UDG to group them. In either case, you'll probably also want to use a UDG for the list of services you want to monitor.
I'd recommend you take a look at the built-in NATO5 rule, MSSQL Service Shutdown for some rule logic you might want to emulate. You might also want to look at the built-in Security Processes UDG for an example of what this type of group looks like. Finally, check out the following KB articles for more info about Tool Profiles and UDGs.
- SolarWinds Knowledge Base :: Getting Started with User-Defined Groups
- SolarWinds Knowledge Base :: How to create custom User Defined Groups for use in your LEM Console
- SolarWinds Knowledge Base :: How to create Tool Profiles to manage and monitor LEM Agents
Let me know if you have any additional questions.