Yes, we need this!!!
I am doing something similar to what you're trying to do -- basically I am tagging events in splunk with change ticket numbers using lookups. You should be able to tune this to your requirements:
http://answers.splunk.com/questions/3982/correlate-and-tag-splunk-events-with-change-control-tickets
This sure would be a nice feature.