Hi there splunker, try like this.
index=_audit tag=authentication info=succeeded | stats count by user, info, host | sort - info
index=_audit tag=authentication info=failed | stats count by user, info, host | sort - info
Dont know about your Splunk environment, but if you are looking to get this from all your instances, you have to forward _audit index to your Search Head.
Hope it helps.
... View more