I'm going with Option B. Parsing the log in transient mode is a good compromise - it can still process the data without permanently adding the new source. And hey, at least it's not ignoring the log completely, right?
Option D is just plain lazy. Ignoring the log altogether? What is this, 1990? NetWitness should be all about capturing and analyzing every bit of data it can get its hands on.
Option C seems to be the correct answer. NetWitness should add the new Event Source to the existing list, so it can start processing logs from that source going forward.
Onita
2 months agoTonette
1 months agoDeja
1 months agoCherry
1 months agoMerissa
2 months agoKate
2 months agoJamal
2 months agoAlberta
3 months agoUlysses
3 months agoAlecia
1 months agoLeota
2 months agoGregg
2 months agoLaurel
3 months agoBev
2 months agoRosita
2 months agoWhitney
2 months agoJudy
3 months ago