Apr 2 10:18:43 prd-ubuntu1804-docker-4c-4g-4151 passwd[927]: password for 'ubuntu' changed by 'root' Apr 2 10:18:43 prd-ubuntu1804-docker-4c-4g-4151 systemd-logind[1067]: Watching system buttons on /dev/input/event0 (Power Button) Apr 2 10:18:43 prd-ubuntu1804-docker-4c-4g-4151 systemd-logind[1067]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Apr 2 10:18:43 prd-ubuntu1804-docker-4c-4g-4151 systemd-logind[1067]: New seat seat0. Apr 2 10:18:43 prd-ubuntu1804-docker-4c-4g-4151 sshd[1246]: Server listening on 0.0.0.0 port 22. Apr 2 10:18:43 prd-ubuntu1804-docker-4c-4g-4151 sshd[1246]: Server listening on :: port 22. Apr 2 10:18:46 prd-ubuntu1804-docker-4c-4g-4151 sshd[1467]: Did not receive identification string from 10.32.4.5 port 38848 Apr 2 10:18:51 prd-ubuntu1804-docker-4c-4g-4151 sshd[1543]: Invalid user jenkins from 10.32.4.5 port 38852 Apr 2 10:18:52 prd-ubuntu1804-docker-4c-4g-4151 sshd[1543]: Received disconnect from 10.32.4.5 port 38852:11: Closed due to user request. [preauth] Apr 2 10:18:52 prd-ubuntu1804-docker-4c-4g-4151 sshd[1543]: Disconnected from invalid user jenkins 10.32.4.5 port 38852 [preauth] Apr 2 10:18:54 prd-ubuntu1804-docker-4c-4g-4151 sshd[1547]: Invalid user jenkins from 10.32.4.5 port 38854 Apr 2 10:18:54 prd-ubuntu1804-docker-4c-4g-4151 sshd[1547]: Received disconnect from 10.32.4.5 port 38854:11: Closed due to user request. [preauth] Apr 2 10:18:54 prd-ubuntu1804-docker-4c-4g-4151 sshd[1547]: Disconnected from invalid user jenkins 10.32.4.5 port 38854 [preauth] Apr 2 10:18:56 prd-ubuntu1804-docker-4c-4g-4151 sshd[1549]: Invalid user jenkins from 10.32.4.5 port 38856 Apr 2 10:18:56 prd-ubuntu1804-docker-4c-4g-4151 sshd[1549]: Received disconnect from 10.32.4.5 port 38856:11: Closed due to user request. [preauth] Apr 2 10:18:56 prd-ubuntu1804-docker-4c-4g-4151 sshd[1549]: Disconnected from invalid user jenkins 10.32.4.5 port 38856 [preauth] Apr 2 10:18:58 prd-ubuntu1804-docker-4c-4g-4151 sshd[1551]: Invalid user jenkins from 10.32.4.5 port 38858 Apr 2 10:18:58 prd-ubuntu1804-docker-4c-4g-4151 sshd[1551]: Received disconnect from 10.32.4.5 port 38858:11: Closed due to user request. [preauth] Apr 2 10:18:58 prd-ubuntu1804-docker-4c-4g-4151 sshd[1551]: Disconnected from invalid user jenkins 10.32.4.5 port 38858 [preauth] Apr 2 10:19:00 prd-ubuntu1804-docker-4c-4g-4151 sshd[1553]: Invalid user jenkins from 10.32.4.5 port 38860 Apr 2 10:19:00 prd-ubuntu1804-docker-4c-4g-4151 sshd[1553]: Received disconnect from 10.32.4.5 port 38860:11: Closed due to user request. [preauth] Apr 2 10:19:00 prd-ubuntu1804-docker-4c-4g-4151 sshd[1553]: Disconnected from invalid user jenkins 10.32.4.5 port 38860 [preauth] Apr 2 10:19:01 prd-ubuntu1804-docker-4c-4g-4151 CRON[1555]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 2 10:19:01 prd-ubuntu1804-docker-4c-4g-4151 CRON[1555]: pam_unix(cron:session): session closed for user root Apr 2 10:19:02 prd-ubuntu1804-docker-4c-4g-4151 sshd[1564]: Invalid user jenkins from 10.32.4.5 port 38862 Apr 2 10:19:02 prd-ubuntu1804-docker-4c-4g-4151 sshd[1564]: Received disconnect from 10.32.4.5 port 38862:11: Closed due to user request. [preauth] Apr 2 10:19:02 prd-ubuntu1804-docker-4c-4g-4151 sshd[1564]: Disconnected from invalid user jenkins 10.32.4.5 port 38862 [preauth] Apr 2 10:19:04 prd-ubuntu1804-docker-4c-4g-4151 sshd[1576]: Invalid user jenkins from 10.32.4.5 port 38866 Apr 2 10:19:04 prd-ubuntu1804-docker-4c-4g-4151 sshd[1576]: Received disconnect from 10.32.4.5 port 38866:11: Closed due to user request. [preauth] Apr 2 10:19:04 prd-ubuntu1804-docker-4c-4g-4151 sshd[1576]: Disconnected from invalid user jenkins 10.32.4.5 port 38866 [preauth] Apr 2 10:19:08 prd-ubuntu1804-docker-4c-4g-4151 sshd[1793]: Invalid user jenkins from 10.32.4.5 port 38868 Apr 2 10:19:08 prd-ubuntu1804-docker-4c-4g-4151 sshd[1793]: Received disconnect from 10.32.4.5 port 38868:11: Closed due to user request. [preauth] Apr 2 10:19:08 prd-ubuntu1804-docker-4c-4g-4151 sshd[1793]: Disconnected from invalid user jenkins 10.32.4.5 port 38868 [preauth] Apr 2 10:19:10 prd-ubuntu1804-docker-4c-4g-4151 sshd[1842]: Invalid user jenkins from 10.32.4.5 port 38872 Apr 2 10:19:10 prd-ubuntu1804-docker-4c-4g-4151 sshd[1842]: Received disconnect from 10.32.4.5 port 38872:11: Closed due to user request. [preauth] Apr 2 10:19:10 prd-ubuntu1804-docker-4c-4g-4151 sshd[1842]: Disconnected from invalid user jenkins 10.32.4.5 port 38872 [preauth] Apr 2 10:19:12 prd-ubuntu1804-docker-4c-4g-4151 sshd[1850]: Invalid user jenkins from 10.32.4.5 port 38880 Apr 2 10:19:12 prd-ubuntu1804-docker-4c-4g-4151 sshd[1850]: Received disconnect from 10.32.4.5 port 38880:11: Closed due to user request. [preauth] Apr 2 10:19:12 prd-ubuntu1804-docker-4c-4g-4151 sshd[1850]: Disconnected from invalid user jenkins 10.32.4.5 port 38880 [preauth] Apr 2 10:19:13 prd-ubuntu1804-docker-4c-4g-4151 useradd[1866]: new group: name=jenkins, GID=1001 Apr 2 10:19:13 prd-ubuntu1804-docker-4c-4g-4151 useradd[1866]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Apr 2 10:19:13 prd-ubuntu1804-docker-4c-4g-4151 usermod[1873]: add 'jenkins' to group 'docker' Apr 2 10:19:13 prd-ubuntu1804-docker-4c-4g-4151 usermod[1873]: add 'jenkins' to shadow group 'docker' Apr 2 10:19:14 prd-ubuntu1804-docker-4c-4g-4151 sshd[1907]: Accepted publickey for jenkins from 10.32.4.5 port 38882 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Apr 2 10:19:14 prd-ubuntu1804-docker-4c-4g-4151 sshd[1907]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Apr 2 10:19:14 prd-ubuntu1804-docker-4c-4g-4151 systemd-logind[1067]: New session 2 of user jenkins. Apr 2 10:19:14 prd-ubuntu1804-docker-4c-4g-4151 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Apr 2 10:20:02 prd-ubuntu1804-docker-4c-4g-4151 CRON[2471]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 2 10:20:02 prd-ubuntu1804-docker-4c-4g-4151 CRON[2471]: pam_unix(cron:session): session closed for user root Apr 2 10:21:01 prd-ubuntu1804-docker-4c-4g-4151 CRON[3381]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 2 10:21:01 prd-ubuntu1804-docker-4c-4g-4151 CRON[3381]: pam_unix(cron:session): session closed for user root Apr 2 10:22:01 prd-ubuntu1804-docker-4c-4g-4151 CRON[8309]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 2 10:22:01 prd-ubuntu1804-docker-4c-4g-4151 CRON[8309]: pam_unix(cron:session): session closed for user root Apr 2 10:23:01 prd-ubuntu1804-docker-4c-4g-4151 CRON[8348]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 2 10:23:01 prd-ubuntu1804-docker-4c-4g-4151 CRON[8348]: pam_unix(cron:session): session closed for user root Apr 2 10:24:01 prd-ubuntu1804-docker-4c-4g-4151 CRON[8547]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 2 10:24:01 prd-ubuntu1804-docker-4c-4g-4151 CRON[8547]: pam_unix(cron:session): session closed for user root Apr 2 10:24:19 prd-ubuntu1804-docker-4c-4g-4151 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/aiml-fw-athp-data-extraction-docker-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Apr 2 10:24:19 prd-ubuntu1804-docker-4c-4g-4151 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)