How can I create a splunk query that pops an alert when there is a suspicious login simultaneously from two different locations?

To elaborate,,
I currently have active directory logs on Splunk.
I need to find out the location of login, I have logs coming from all around the world.

Please help

can you post some evnt from the log?

