Search results will be part of the "Path to file containing the search results" (arg 8 ) and you might need to open and read the content of the file in your custom script. Reference : https://docs.splunk.com/Documentation/Splunk/8.0.6/Alert/Configuringscriptedalerts Please note that the run a script alert action is deprecated officially. Please refer to the below documentation to convert to Custom alert action framework https://docs.splunk.com/Documentation/Splunk/8.0.6/AdvancedDev/CustomAlertConvertScripted
... View more