Instead of running an alert twice, run it once (at quarter past), but compare the results of the last 5m to those from 15m-10m ago
from User warren – Stack Overflow https://stackoverflow.com/questions/76476439/splunk-re-run-alert-when-count-1-and-alert-only-if-both-have-count-1/76482448#76482448
via IFTTT