search query - Lack of account activity for more than 3 months.
There is a directory with the accounts that you need to drive through the activity from the connection for three months.
How can I make such a search ?
You're best off creating a lookup containing all seen users, and frequently update last-seen timestamps with recent data.
Enterprise Security already has such a user tracker, the Security Essentials app might also - not sure, do check it out: https://splunkbase.splunk.com/app/3435/
Lacking that, here's a guide how to build such stateful lookups: https://www.splunk.com/blog/2011/01/11/maintaining-state-of-the-union.html