My understanding is that Elastic Defend's yaml config is the Elastic Agent's config with Elastic Defend added to it.
Is it possible that running the Elastic Agent DaemonSet alongside the Elastic Defend DaemonSet is causing issues?
Our documentation regarding this is not great, gonna fix it.