DUO and Splunk reporting on Failures

I would like to report on failed authentications outside the US and be alerted. What query do I need to run within Splunk to retrieve that information?