Inky: receive phishing and threat events into Current
Inky is the one connector in Current that works backwards from all the others. Every other reporting integration is a key you paste so Current can go and read the vendor. Inky has no such API to read — its only way to send data out is its Custom SIEM Feed, which POSTs each email-security event to a URL you give it. So instead of Current reaching into Inky, you point Inky at Current. You enable a receiver here, copy the URL it gives you, and paste that URL into Inky.
Step 1 — Enable the receiver in Current
- 1Open Integrations → Inky → ManageIntegrations sits under Admin in the left sidebar, so this is a Tenant Admin action.
- 2Press Enable receiverCurrent generates a unique, secret feed URL for your workspace and stores it. Nothing is sent anywhere yet — the receiver is simply now listening.
- 3Copy the feed URLThe drawer shows the full URL with a Copy button. Anyone who has this URL can post events into your stats, so treat it like a password. It's shown here (not hidden) on purpose, so your team can re-copy it later without regenerating it.
Step 2 — Paste the URL into Inky
- 1Open Inky's Custom SIEM FeedIn Inky, go to Settings → Integrations → Custom SIEM Feed and choose Configure.
- 2Paste the URL and choose JSONEnter the URL you copied from Current as the webhook / endpoint URL, and set the format to JSON. If Inky offers event filters, you can scope which event types it sends.
- 3Save and send a test eventSave the feed, then use Inky's test/send option. The Current card flips from Awaiting feed to Receiving within seconds of the first event landing.
How events map to your customers
Each event carries a recipient — the protected mailbox — and Current uses that recipient's domain to decide which company it belongs to. A domain that uniquely matches one of your Current companies (by the website on the company profile) is linked automatically; a domain that matches none, or more than one, is left unmapped and still stored. Current never overwrites a mapping you set by hand.
Data retention
Current keeps 90 days of Inky events. Older entries are pruned automatically as new events arrive, so the feed stays a rolling three-month window rather than growing forever. This doesn't affect your reporting: the counts shown in business reviews and alerts all use windows that fit inside those 90 days — a 90-day review total, plus 30-day and 7-day lookbacks for phishing-spike alerts — so pruning older events never changes a number you see.
Troubleshooting
| What you see | What it means |
|---|---|
| Card stays on Awaiting feed | Inky hasn't delivered an event to the URL yet. Re-check that the exact URL from Current is saved in Inky's Custom SIEM Feed, the format is JSON, and any event filter isn't excluding everything. Use Inky's test-send to confirm. |
| Inky reports the feed failed / a 404 | The URL is wrong or the receiver was disconnected in Current. Re-copy the URL from the Inky card (Manage) and paste it again. If you pressed Disconnect in Current, the feed stops accepting events until you enable it again. |
| Events arrive but aren't on any company | Their recipient domain didn't uniquely match a Current company. Add the company's website to its Current profile so the domain can match, or map it by hand — new events on that domain then attach automatically. |
| You regenerated the URL | The old URL stops working immediately. Paste the new URL into Inky, or events will silently stop arriving. Only regenerate if the URL was exposed. |
