This seems to work when trying to find unique values for a field, like 'host':
* | chart count by host
The Splunk Enterprise version 5.0 documentation from 2012 is no longer available. Similar information is available in newer versions of the Splunk documentation. Replace "5.0" in the URL with "latest" or a more recent version number to view the topics.
dedup: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Dedup
stats: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonStatsFunctions
stats values(field)
is what I used.