Without the pipe you're searching for the word "stats" .
Note, by now there is the explicit command
| makeresults to create an empty result, it's slightly more efficient than stats and much more readable.
there no command in splunk that function exactly like the command ech of linux. but from a combination of command you get the result that you want .
and Display High values of a field , you can use commands such as "table"; "field" .....
to change the field values you use the "eval"; ...
you can use macro to simulate aproche
or map command, see this example can help you:
sourcetype=syslog sudo | stats count by user host | map search="search index=ad_summary username=$user$ type_logon=ad_last_logon"