Will,
It sounds like there is something else going on with your Splunk instance. You should check your logs or look at the SoS app to diagnose.
Here are some good blog posts on using getwatchlist against your data:
http://blogs.splunk.com/2011/08/16/getwatchlist-getting-watchlists-into-splunk-quickly-and-easily-with-a-splunk-custom-search-command/
and
http://blogs.splunk.com/2011/09/08/anonymous-proxies/
Both of the posts contain examples of how you can use your downloaded watchlist against your events.
Thanks,
Dave
... View more