If you have osquery configuyred to use the watcher...
# general
t
If you have osquery configuyred to use the watcher, which is the default config, then two processes should always be running, the worker and the watcher. If the worker ever misbehaves, the watcher will kill it and attempt to spawn a new worker. This could happen on occasion if you have strict perf limits setup in tandem with expensive query packs. That all being said, it should more or less be the case that you have two processes running for your deployment