Direct answer
Evidence should connect a monitoring objective to the source that can observe it, the owner of that source, current ingestion and parser health, usable event fields, time and identity quality, dependent detections, known gaps and remediation ownership. An inventory entry by itself is not proof of useful coverage.
Evidence to retain
Requirement evidence
EvidenceDetection objective
EvidenceRequired source/system
EvidenceExpected event categories
EvidenceAccountable source owner
Health evidence
EvidenceRecent ingestion attempt
EvidenceParser/normalization result
EvidenceSource identifiers and timestamps
EvidenceFailure or gap records
Usability evidence
EvidenceRequired fields present
EvidenceIdentity/asset context available
EvidenceTime quality sufficient
EvidenceRetention/access expectation documented
Coverage evidence
EvidenceDependent detection or monitoring objective
EvidenceKnown blind spots
EvidenceException or remediation owner
EvidenceLast review date
Relevant Cybatar sources
Cybatar sourcehttps://cybatar.co/connectors/factsCybatar sourcehttps://cybatar.co/developers/integration-healthCybatar sourcehttps://cybatar.co/platform/siem-event-pipelineCybatar sourcehttps://cybatar.co/control-evidence/logging-monitoring
External references
NIST SP 800-137https://csrc.nist.gov/pubs/sp/800/137/finalMITRE ATT&CK Detection Strategieshttps://attack.mitre.org/detectionstrategies/
Claim boundary
Source coverage does not prove attack coverage. A source can be connected while relevant events, fields, retention, identities or timestamps remain incomplete.