# Podman path starts with . causes heaps of alerts

**URL:** <https://discuss.elastic.co/t/podman-path-starts-with-causes-heaps-of-alerts/382535>\
**Category:** Elastic Security\
**Created:** [October 9, 2025, 5:34am UTC](https://discuss.elastic.co/t/podman-path-starts-with-causes-heaps-of-alerts/382535 "2025-10-09T05:34:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![michael-a](https://avatars.discourse-cdn.com/v4/letter/m/c57346/32.png) [@michael-a](https://discuss.elastic.co/u/michael-a)\
**Post date:** [October 9, 2025, 5:34am UTC](https://discuss.elastic.co/t/podman-path-starts-with-causes-heaps-of-alerts/382535/1 "2025-10-09T05:34:00Z")

</div>

We’ve received large numbers of alerts from Linux endpoints where standard rule exeptions don’t work due to the fact that the logged process.executable path starts with a . rather than /, which affect multiple rules. Looks like this

process.executable "./usr/bin/podman" while the rule exception is "/usr/bin/podman".

We’ve had to create rule exceptions to 5+ rules to mitigate but it really looks like a bug - presumably in the agent. We’re still on 9.1.4 and noticed that 9.1.5 just came out, no release notes available though so not sure what’s being fixed.

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [October 9, 2025, 1:13pm UTC](https://discuss.elastic.co/t/podman-path-starts-with-causes-heaps-of-alerts/382535/2 "2025-10-09T13:13:03Z")

</div>

Hi @michael-a, that [bug](https://github.com/elastic/endpoint/issues/91) is [fixed in 9.1.3](https://www.elastic.co/docs/release-notes/security#elastic-security-9.1.3-release-notes). When you say you’re seeing it in 9.1.4 do you mean 9.1.4 Kibana or 9.1.4 Elastic Agent? The fix was in the Endpoint binary that Agent runs on the host generating the data so you’ll need to upgrade to an 9.1.3+ Elastic Agent to pick up the fix.

---

<div class="post-metadata">

**Author:** ![michael-a](https://avatars.discourse-cdn.com/v4/letter/m/c57346/32.png) [@michael-a](https://discuss.elastic.co/u/michael-a)\
**Post date:** [October 10, 2025, 5:47am UTC](https://discuss.elastic.co/t/podman-path-starts-with-causes-heaps-of-alerts/382535/3 "2025-10-10T05:47:07Z")

</div>

Hi @ferullo and thanks for the quick reply, just checking and as far as I can tell we have it on at least a handful of clients with agent 9.1.4 (backend i e Kibana is also 9.1.4 btw), hitting multiple rules i e

- Shell Configuration Creation or Modification
- Creation or Modification of Pluggable Authentication Module or Configuration
- Systemd Service Created

Let me know if there’s anything else I can do.
