@simpki could you show a cgroup full path (lets take memory)
Default is
cgroups to match as systemd services = !/system.slice/*/*.service /system.slice/*.service
Result is the following cgroups are matched as systemd services
[ilyam@pc ~]$ ls -l /sys/fs/cgroup/memory/system.slice/ | awk '{ print $9 }' | grep "\.service"
apparmor.service
avahi-daemon.service
cronie.service
dbus.service
docker.service
kmod-static-nodes.service
lvm2-monitor.service
ModemManager.service
netdata.service
NetworkManager.service
NetworkManager-wait-online.service
polkit.service
rtkit-daemon.service
sddm.service
smartd.service
snapd.apparmor.service
sshd.service
systemd-binfmt.service
systemd-journald.service
systemd-journal-flush.service
systemd-logind.service
systemd-modules-load.service
systemd-random-seed.service
systemd-remount-fs.service
systemd-sysctl.service
systemd-tmpfiles-setup-dev.service
systemd-tmpfiles-setup.service
systemd-udevd.service
systemd-udev-trigger.service
systemd-update-utmp.service
systemd-user-sessions.service
tlp.service
udisks2.service
upower.service
wpa_supplicant.service
The following are not
[ilyam@pc ~]$ ls -l /sys/fs/cgroup/memory/system.slice/ | awk '{ print $9 }' | grep -v "\.service" | grep -v "memory."
avahi-daemon.socket
boot-efi.mount
cgroup.clone_children
cgroup.event_control
cgroup.procs
dbus.socket
dm-event.socket
docker.socket
lvm2-lvmpolld.socket
notify_on_release
run-user-1000-gvfs.mount
run-user-1000.mount
snapd.socket
systemd-coredump.socket
systemd-journald-audit.socket
systemd-journald-dev-log.socket
systemd-journald.socket
systemd-rfkill.socket
systemd-udevd-control.socket
systemd-udevd-kernel.socket
system-getty.slice
system-modprobe.slice
system-systemd\x2dcoredump.slice
system-systemd\x2dfsck.slice
tasks
tmp.mount