Adjusted for python 3 on splunk 8. Nothing new. Icludeds a samle in the description though.
Simple custom command to make events with one or many multivalue fields into a table by expanding each event
Example with wsus data:
| mvtable mvfields="kbnumber,arrival_date" keepfields="host,OS,_time"
mvfields being the fields containing several values and keepfields limiting the retained fields on the resulting table. Then format it as a table with | table * or whatever.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.