Have you tried using an append command or using a subsearch?
Append Splunk Doc: http://docs.splunk.com/Documentation/Splunk/6.2.4/SearchReference/Append
You can also control the subsearch with settings in limits.conf for the runtime and maximum number of results returned.
The thing you want to achieve requires sequencing of search queries as the lookup from 1st query should be populated before 2nd query should start. If the timerange/data for 1st query doesn't change very much drastically, you can schedule it to run frequently and update the lookup file. The 2nd query will just get the data from the latest scheduled run of the 1st query. Thoughts?