I'm going with Option B. Parsing the log in transient mode is a good compromise - it can still process the data without permanently adding the new source. And hey, at least it's not ignoring the log completely, right?
Option D is just plain lazy. Ignoring the log altogether? What is this, 1990? NetWitness should be all about capturing and analyzing every bit of data it can get its hands on.
Option C seems to be the correct answer. NetWitness should add the new Event Source to the existing list, so it can start processing logs from that source going forward.
Onita
5 months agoTonette
4 months agoDeja
4 months agoCherry
4 months agoMerissa
5 months agoKate
5 months agoJamal
5 months agoAlberta
5 months agoUlysses
5 months agoAlecia
4 months agoLeota
4 months agoGregg
4 months agoLaurel
5 months agoBev
5 months agoRosita
5 months agoWhitney
5 months agoJudy
5 months ago