Based on the above results I am going to display the most recent user whose connection was closed recently by using a return command.
Lets assume from the above results ABC connection was closed recently (lets say 6:15). so I would like send an email alert to ABC with a message "ABC device connection is closed at 6:15". In the similar way each user in the organization should receive an email when their connection was closed based on the query results.
No. Not in Splunk. I did it Mulesoft. You need an orchestration tool to automate that workflow. Or write a python script from the csv. I have done similar with AWS using a bash script to email invenotry.