I'm going with Option B. Parsing the log in transient mode is a good compromise - it can still process the data without permanently adding the new source. And hey, at least it's not ignoring the log completely, right?
Option D is just plain lazy. Ignoring the log altogether? What is this, 1990? NetWitness should be all about capturing and analyzing every bit of data it can get its hands on.
Option C seems to be the correct answer. NetWitness should add the new Event Source to the existing list, so it can start processing logs from that source going forward.
Onita
7 months agoTonette
6 months agoDeja
7 months agoCherry
7 months agoMerissa
8 months agoKate
8 months agoJamal
8 months agoAlberta
8 months agoUlysses
8 months agoAlecia
7 months agoLeota
7 months agoGregg
7 months agoLaurel
8 months agoBev
7 months agoRosita
7 months agoWhitney
8 months agoJudy
8 months ago