If I am understanding your question correctly, you can provide a view using a component like the bar chart with the following settings:
1. Select that you want to use Source IP as your query
2. In the filter option, select the filter next to source IP and choose the watchlist you want to use.
Your results should be similar to the following:
A list of all the IPs in the watchlist that have events associated to them. Then you can bind additional components off this list as needed.
Yup. I was too focused on the specifics and missed the sledge hammer
I guess the only possible downside will be performance since I'm now running a pretty big query to drive another 15 queries. But it shoud do it