I'm going with Option B. Parsing the log in transient mode is a good compromise - it can still process the data without permanently adding the new source. And hey, at least it's not ignoring the log completely, right?
Option D is just plain lazy. Ignoring the log altogether? What is this, 1990? NetWitness should be all about capturing and analyzing every bit of data it can get its hands on.
Option C seems to be the correct answer. NetWitness should add the new Event Source to the existing list, so it can start processing logs from that source going forward.
Onita
9 months agoTonette
8 months agoDeja
9 months agoCherry
9 months agoMerissa
10 months agoKate
10 months agoJamal
10 months agoAlberta
10 months agoUlysses
10 months agoAlecia
9 months agoLeota
9 months agoGregg
9 months agoLaurel
10 months agoBev
9 months agoRosita
9 months agoWhitney
10 months agoJudy
10 months ago