This actually worked pretty good. Then I ran into a a snag. I want relevant email (current) but the "SalesGroup" information is going to be loaded weekly. So, when I correlate events in the last 4 hours, or even 24 hours, the results are blank because splunk is trying to query the "SalesGroup" source for that time frame too.
I don't think a CSV lookup will suffice in this case, because it's 400k records. However, if it will I can attemp that route.
If I could ignore time on the subsearch, that would be ideal.