Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 2.18
Describe the issue: Cumulative error count after 1st 5 minute anomaly trigger delay alert until =1k error (example), can be seprate query. I am looking to count the spike if it meets criteria of the total spike of count, otherwise ignore.
Configuration: 5 shingle, 5 minute delay window, looking for Alerting separate
query config
Relevant Logs or Screenshots: