When exporting the Defender daemonset with twistcli defender export kubernetes, always pass --privileged and --cri. The Defender must run privileged and must use the Container Runtime Interface to protect the other pods' containers; without those flags the daemonset deploys, looks healthy, and never shows up in the console. After redeploying with both flags, confirm one defender pod per node and check Manage > Defenders in the console.

Context: Community thread on live.paloaltonetworks.com (16 replies, ~15k views): a user triaged an EKS cluster where the Prisma Defender daemonset deployed but never appeared in the console. The verified resolution from the reporter: the daemonset YAML generated by twistcli defender export was missing two options, and without them the Defender cannot protect the other pods' containers.