I'm going with Option B. Parsing the log in transient mode is a good compromise - it can still process the data without permanently adding the new source. And hey, at least it's not ignoring the log completely, right?
Option D is just plain lazy. Ignoring the log altogether? What is this, 1990? NetWitness should be all about capturing and analyzing every bit of data it can get its hands on.
Option C seems to be the correct answer. NetWitness should add the new Event Source to the existing list, so it can start processing logs from that source going forward.
Onita
6 months agoTonette
5 months agoDeja
5 months agoCherry
5 months agoMerissa
6 months agoKate
6 months agoJamal
7 months agoAlberta
7 months agoUlysses
7 months agoAlecia
6 months agoLeota
6 months agoGregg
6 months agoLaurel
7 months agoBev
6 months agoRosita
6 months agoWhitney
6 months agoJudy
7 months ago