It may because you are using a basic conditional alert rather than an advanced conditional alert.
See http://docs.splunk.com/Documentation/Splunk/latest/User/SchedulingSavedSearches#Define_alerts_that_are_based_on_scheduled.2C_historical_searches for more details.
... View more