I have the suspicion that s51580 may have been used (willingly or unwillingly) to perform a DOS attack against the databases, which has been partially succesful, forcing labsdb1010 to failover service to labsdb1009 through its load balancer. If that was intentional or mistake or a compromised account, I do not know.
This was the report from tendril:
Hits Tmax Tavg Tsum Hosts Users Schemas 589 18,335 15,395 9,067,658 labsdb1010 s51580 select count(*), fr_user from dewiki_p.flaggedrevs where ( fr_flags = 'dynamic' or fr_flags = ', dynamic' ) and fr_timestamp like '201712%' group by fr_user order by count(*) /* SLOW_OK */ /* 8572d5fb0ce04c1550e67b48fa7322c9 labsdb1010 12455s */ 1066 661 261 278,254 labsdb1009, labsdb1010 s51580 #select all articles that were never reviewed #1 min 20, 335 select page_id, page_title from dewiki_p.page #not flagged where page_id not in (select distinct fp_page_id from dewiki_p.flaggedpages) #not a redirect and page_is_redirect = 0 #and page_id not in (select distinct rd_from from dewiki_p.redirect) #and in article namespace and page_namespace = 0 /* 50752df04c3acd7da0baddaacc3d1773 labsdb1010 2s */