Yes, there is a default limit of 10000 events for the
sort command. However you can specify your own limit as a parameter, so for instance if you want to specify a limit of 15000 events instead you would do this:
index=sample | sort 15000 host
More information regarding the
sort command is available here. http://www.splunk.com/base/Documentation/latest/SearchReference/Sort
Yes the sort command will only return 10,000 rows by default. You can raise that by specifying a different limit, ie
| sort 50000 host however eventually you may hit other more fundamental limits.
And I think you may want to look at this:
| stats count by host
which will chug through all the work and wont hit any kind of limits.