Apache 129 's combined log format (Logs and LogFormat) splits cleanly two ways: on spaces, where the client address is field 1 and the status field 9, and on double quotes, which keeps the space-filled user agent in one piece.

cut -d sets the delimiter and -f picks fields (1, 1,7, 4-6). uniq -c counts adjacent duplicates, so sort comes first, and sort -rn then puts the largest count on top: the classic log one-liner.
cut -d' ' -f1 access.log | sort | uniq -c | sort -rn | head -5 # top client IPs
cut -d' ' -f9 access.log | sort | uniq -c | sort -rn # status codes
cut -d'"' -f6 access.log | sort | uniq -c | sort -rn | head -3 # top user agents 182 203.0.113.10
105 203.0.113.21
82 203.0.113.34
60 203.0.113.99
38 203.0.113.58
396 200
111 404
10 403
120 Mozilla/5.0 (X11; Linux x86_64; rv:143.0) Gecko/20100101 Firefox/143.0
119 curl/8.18.0
113 Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)The ten 403s are the scanner asking for /server-status, which Ubuntu 225 's mod_status serves only to local clients. To sort whole lines by a field, give a separator and a bounded key: sort -t' ' -k10,10nr orders requests by size, while -k10 alone would sort on everything from field 10 to the end of the line.
On Ubuntu 26.04, sort, cut, uniq and wc are the Rust rewrite from the uutils project (sort --version prints "uutils coreutils 0.8.0"); the GNU originals stay installed as gnusort and friends.