Your best bet is to use the punct field which is the pattern of the event. You can read more about this field here: http://www.splunk.com/base/Documentation/4.2.2/User/UseDefaultAndInternalFields#punct
For example:
sourcetype=syslog | stats count first(_raw) as event by punct | table count event | sort -count
... View more