AFAIK you cannot do this with the current state of Graylog alerting system. Graylog only considers alert conditions to be matched or not on a certain period of time (by default 60s). If you have multiple messages matching an alert condition in the same minute, only a single alert notification will be sent.
I see two options:
Set the message backlog to a high number - this was, Graylog’s notification should include all the messages, and your notification endpoint (e.g. HTTP server listening for webhooks) can take action for each individual message
Give feedback to the Graylog team so they implement the possibility to have alert conditions trigger on individual messages