I have a realtime alert that's kicking off a python script, and I'd like to use the contents of the log entry that triggered the alert in the script. Is that possible?
You need to use the alert parameters for the script. The search needs to be formatted so that you get the content in the field to use in the script. Pass the script in savedsearch window or action.script.filename = <script filename>
action.script.filename = <script filename>
More documentation here: