I'm going with Option B. Parsing the log in transient mode is a good compromise - it can still process the data without permanently adding the new source. And hey, at least it's not ignoring the log completely, right?
Option D is just plain lazy. Ignoring the log altogether? What is this, 1990? NetWitness should be all about capturing and analyzing every bit of data it can get its hands on.
Option C seems to be the correct answer. NetWitness should add the new Event Source to the existing list, so it can start processing logs from that source going forward.
Onita
1 months agoTonette
9 days agoDeja
15 days agoCherry
20 days agoMerissa
1 months agoKate
1 months agoJamal
2 months agoAlberta
2 months agoUlysses
2 months agoAlecia
22 days agoLeota
24 days agoGregg
26 days agoLaurel
2 months agoBev
1 months agoRosita
1 months agoWhitney
2 months agoJudy
2 months ago