# Kibana cluster email alerts

**URL:** <https://discuss.elastic.co/t/kibana-cluster-email-alerts/270712>\
**Category:** Kibana\
**Created:** [April 20, 2021, 1:24pm UTC](https://discuss.elastic.co/t/kibana-cluster-email-alerts/270712 "2021-04-20T13:24:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mutt13y](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mutt13y/32/74962_2.png) [@mutt13y](https://discuss.elastic.co/u/mutt13y)\
**Post date:** [April 20, 2021, 1:24pm UTC](https://discuss.elastic.co/t/kibana-cluster-email-alerts/270712/1 "2021-04-20T13:24:24Z")

</div>

Hi,  
I have configured monitoring.cluster\_alerts.email\_notifications.email\_address in kibana.yml

in elasticsearch.yml I am using SES

The SES configuration does not allow me to include a from, ES refuses to start if its configured.

The alert emails are sent using the provided address and the TO and the FROM. This works for some destinations but not all. Specifically it does not seem to work with slack.

Is there a way to configure the From address for the cluster\_alerts ?

---

<div class="post-metadata">

**Author:** ![Igor\_Zaytsev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_zaytsev/32/50662_2.png) [@Igor\_Zaytsev](https://discuss.elastic.co/u/Igor_Zaytsev)\
**Post date:** [April 26, 2021, 7:26am UTC](https://discuss.elastic.co/t/kibana-cluster-email-alerts/270712/2 "2021-04-26T07:26:22Z")

</div>

@mutt13y

The reasons the emails are being picked up as spoofed emails is due to the email address that appears in the `from` address of the system watcher, is different to the actual email address the server is sending from.

Unfortunately there is no way to modify the built-in monitoring Watches to change the `from` email address to be different from the `to` address.

However, there is a (not really recommended) workaround. You can disable monitoring alerts, either entirely or by blacklisting a subset of the built-in alerts (see [these docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/monitoring-settings.html#http-exporter-settings) for setting details) and install modified versions of those SM [watches](https://github.com/elastic/elasticsearch/tree/master/x-pack/plugin/monitoring/src/main/resources/monitoring/watches) manually, and then replace `"from": "X-Pack Admin <{{ctx.vars.email_recipient}}>",` with `"from": "X-Pack Admin <the_email_it_should_come_from@example.com>",`. After which you can also configure your email [actions](https://www.elastic.co/guide/en/elasticsearch/reference/master/actions-email.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2021, 7:27am UTC](https://discuss.elastic.co/t/kibana-cluster-email-alerts/270712/3 "2021-05-24T07:27:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
