@User16096767 This may seem like a question that would go without saying, however, could you please confirm that you have the Endpoint Security for Linux license extension 10.2.0.103 checked in? In the event you do not, then the / is not able to be properly processed within policy.
If that is taken care of, do you utilize default/low/high-risk process policy? If so, it's possible that the exclusion needs to be propagated through other policies to be fully honored.
If neither of these are on point, then it's clear we would need some more information and detail regarding your configuration in order to provide accurate assistance.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please give kudos or select "Accept as Solution" in my reply, as appropriate, so together we can help other members?