Found a workaround here, implemented it and it is doing exactly what I wanted to do - https://medium.com/@clong/splunk-building-dynamic-lookup-tables-a593261569
Would be nice to see Splunk handling stuff like this better in future releases
... View more