You will want to look at the Search Language guide. This question is very broad, and with no indication of what your data looks like. You could try source=/var/log/secure login failed
and see what happens, but really you should refer to the Search Tutorial and go from there.
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/Startsearching