Anomaly detector cumulative of 1k error threshold before alerting condition trigger

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 2.18

Describe the issue: Cumulative error count after 1st 5 minute anomaly trigger delay alert until =1k error (example), can be seprate query. I am looking to count the spike if it meets criteria of the total spike of count, otherwise ignore.

Configuration: 5 shingle, 5 minute delay window, looking for Alerting separate


query config

Relevant Logs or Screenshots:

Processing: Screenshot 2025-06-27 at 4.30.33 PM.png…