I am trying to build a panel where I would like to input the source and present in a radial guaze.
The simple query looks something like this:
index=x host=y source = /logs/zzz* "keyword"| |timechart span=1m count as keyword
And in there I want to be able to change the "zzz" to different options as per input.
To do this you need to edit the dashboard and "add an input". Edit thatinput to set a token called for example "source".
Then in your panel, update the search to look like this:
index=x host=y source = $source$* "keyword |timechart span=1m count as keyword
Here is some more info: https://docs.splunk.com/Documentation/Splunk/7.2.3/Viz/tokens#Using_tokens_in_a_search