Jul 2 10:18:46 prd-ubuntu1804-docker-4c-4g-4386 passwd[960]: password for 'ubuntu' changed by 'root' Jul 2 10:18:46 prd-ubuntu1804-docker-4c-4g-4386 systemd-logind[1009]: Watching system buttons on /dev/input/event0 (Power Button) Jul 2 10:18:46 prd-ubuntu1804-docker-4c-4g-4386 systemd-logind[1009]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jul 2 10:18:46 prd-ubuntu1804-docker-4c-4g-4386 systemd-logind[1009]: New seat seat0. Jul 2 10:18:47 prd-ubuntu1804-docker-4c-4g-4386 sshd[1226]: Server listening on 0.0.0.0 port 22. Jul 2 10:18:47 prd-ubuntu1804-docker-4c-4g-4386 sshd[1226]: Server listening on :: port 22. Jul 2 10:18:49 prd-ubuntu1804-docker-4c-4g-4386 sshd[1370]: Did not receive identification string from 10.32.4.5 port 49618 Jul 2 10:18:55 prd-ubuntu1804-docker-4c-4g-4386 sshd[1489]: Invalid user jenkins from 10.32.4.5 port 49620 Jul 2 10:18:55 prd-ubuntu1804-docker-4c-4g-4386 sshd[1489]: Received disconnect from 10.32.4.5 port 49620:11: Closed due to user request. [preauth] Jul 2 10:18:55 prd-ubuntu1804-docker-4c-4g-4386 sshd[1489]: Disconnected from invalid user jenkins 10.32.4.5 port 49620 [preauth] Jul 2 10:18:57 prd-ubuntu1804-docker-4c-4g-4386 sshd[1493]: Invalid user jenkins from 10.32.4.5 port 49622 Jul 2 10:18:57 prd-ubuntu1804-docker-4c-4g-4386 sshd[1493]: Received disconnect from 10.32.4.5 port 49622:11: Closed due to user request. [preauth] Jul 2 10:18:57 prd-ubuntu1804-docker-4c-4g-4386 sshd[1493]: Disconnected from invalid user jenkins 10.32.4.5 port 49622 [preauth] Jul 2 10:18:59 prd-ubuntu1804-docker-4c-4g-4386 sshd[1514]: Invalid user jenkins from 10.32.4.5 port 49624 Jul 2 10:18:59 prd-ubuntu1804-docker-4c-4g-4386 sshd[1514]: Received disconnect from 10.32.4.5 port 49624:11: Closed due to user request. [preauth] Jul 2 10:18:59 prd-ubuntu1804-docker-4c-4g-4386 sshd[1514]: Disconnected from invalid user jenkins 10.32.4.5 port 49624 [preauth] Jul 2 10:19:01 prd-ubuntu1804-docker-4c-4g-4386 sshd[1516]: Invalid user jenkins from 10.32.4.5 port 49626 Jul 2 10:19:01 prd-ubuntu1804-docker-4c-4g-4386 CRON[1518]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 2 10:19:01 prd-ubuntu1804-docker-4c-4g-4386 CRON[1518]: pam_unix(cron:session): session closed for user root Jul 2 10:19:01 prd-ubuntu1804-docker-4c-4g-4386 sshd[1516]: Received disconnect from 10.32.4.5 port 49626:11: Closed due to user request. [preauth] Jul 2 10:19:01 prd-ubuntu1804-docker-4c-4g-4386 sshd[1516]: Disconnected from invalid user jenkins 10.32.4.5 port 49626 [preauth] Jul 2 10:19:03 prd-ubuntu1804-docker-4c-4g-4386 sshd[1527]: Invalid user jenkins from 10.32.4.5 port 49630 Jul 2 10:19:03 prd-ubuntu1804-docker-4c-4g-4386 sshd[1527]: Received disconnect from 10.32.4.5 port 49630:11: Closed due to user request. [preauth] Jul 2 10:19:03 prd-ubuntu1804-docker-4c-4g-4386 sshd[1527]: Disconnected from invalid user jenkins 10.32.4.5 port 49630 [preauth] Jul 2 10:19:05 prd-ubuntu1804-docker-4c-4g-4386 sshd[1529]: Invalid user jenkins from 10.32.4.5 port 49632 Jul 2 10:19:05 prd-ubuntu1804-docker-4c-4g-4386 sshd[1529]: Received disconnect from 10.32.4.5 port 49632:11: Closed due to user request. [preauth] Jul 2 10:19:05 prd-ubuntu1804-docker-4c-4g-4386 sshd[1529]: Disconnected from invalid user jenkins 10.32.4.5 port 49632 [preauth] Jul 2 10:19:07 prd-ubuntu1804-docker-4c-4g-4386 sshd[1531]: Invalid user jenkins from 10.32.4.5 port 49634 Jul 2 10:19:08 prd-ubuntu1804-docker-4c-4g-4386 sshd[1531]: Received disconnect from 10.32.4.5 port 49634:11: Closed due to user request. [preauth] Jul 2 10:19:08 prd-ubuntu1804-docker-4c-4g-4386 sshd[1531]: Disconnected from invalid user jenkins 10.32.4.5 port 49634 [preauth] Jul 2 10:19:10 prd-ubuntu1804-docker-4c-4g-4386 sshd[1696]: Invalid user jenkins from 10.32.4.5 port 49636 Jul 2 10:19:10 prd-ubuntu1804-docker-4c-4g-4386 sshd[1696]: Received disconnect from 10.32.4.5 port 49636:11: Closed due to user request. [preauth] Jul 2 10:19:10 prd-ubuntu1804-docker-4c-4g-4386 sshd[1696]: Disconnected from invalid user jenkins 10.32.4.5 port 49636 [preauth] Jul 2 10:19:12 prd-ubuntu1804-docker-4c-4g-4386 sshd[1772]: Invalid user jenkins from 10.32.4.5 port 49644 Jul 2 10:19:12 prd-ubuntu1804-docker-4c-4g-4386 sshd[1772]: Received disconnect from 10.32.4.5 port 49644:11: Closed due to user request. [preauth] Jul 2 10:19:12 prd-ubuntu1804-docker-4c-4g-4386 sshd[1772]: Disconnected from invalid user jenkins 10.32.4.5 port 49644 [preauth] Jul 2 10:19:15 prd-ubuntu1804-docker-4c-4g-4386 sshd[1809]: Invalid user jenkins from 10.32.4.5 port 49646 Jul 2 10:19:15 prd-ubuntu1804-docker-4c-4g-4386 sshd[1809]: Received disconnect from 10.32.4.5 port 49646:11: Closed due to user request. [preauth] Jul 2 10:19:15 prd-ubuntu1804-docker-4c-4g-4386 sshd[1809]: Disconnected from invalid user jenkins 10.32.4.5 port 49646 [preauth] Jul 2 10:19:17 prd-ubuntu1804-docker-4c-4g-4386 sshd[1813]: Invalid user jenkins from 10.32.4.5 port 49648 Jul 2 10:19:17 prd-ubuntu1804-docker-4c-4g-4386 sshd[1813]: Received disconnect from 10.32.4.5 port 49648:11: Closed due to user request. [preauth] Jul 2 10:19:17 prd-ubuntu1804-docker-4c-4g-4386 sshd[1813]: Disconnected from invalid user jenkins 10.32.4.5 port 49648 [preauth] Jul 2 10:19:18 prd-ubuntu1804-docker-4c-4g-4386 useradd[1829]: new group: name=jenkins, GID=1001 Jul 2 10:19:18 prd-ubuntu1804-docker-4c-4g-4386 useradd[1829]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Jul 2 10:19:18 prd-ubuntu1804-docker-4c-4g-4386 usermod[1836]: add 'jenkins' to group 'docker' Jul 2 10:19:18 prd-ubuntu1804-docker-4c-4g-4386 usermod[1836]: add 'jenkins' to shadow group 'docker' Jul 2 10:19:19 prd-ubuntu1804-docker-4c-4g-4386 sshd[1887]: Accepted publickey for jenkins from 10.32.4.5 port 49652 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Jul 2 10:19:19 prd-ubuntu1804-docker-4c-4g-4386 sshd[1887]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jul 2 10:19:19 prd-ubuntu1804-docker-4c-4g-4386 systemd-logind[1009]: New session 2 of user jenkins. Jul 2 10:19:19 prd-ubuntu1804-docker-4c-4g-4386 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jul 2 10:20:02 prd-ubuntu1804-docker-4c-4g-4386 CRON[2404]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 2 10:20:02 prd-ubuntu1804-docker-4c-4g-4386 CRON[2404]: pam_unix(cron:session): session closed for user root Jul 2 10:21:01 prd-ubuntu1804-docker-4c-4g-4386 CRON[2452]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 2 10:21:01 prd-ubuntu1804-docker-4c-4g-4386 CRON[2452]: pam_unix(cron:session): session closed for user root Jul 2 10:22:01 prd-ubuntu1804-docker-4c-4g-4386 CRON[3175]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 2 10:22:01 prd-ubuntu1804-docker-4c-4g-4386 CRON[3175]: pam_unix(cron:session): session closed for user root Jul 2 10:23:01 prd-ubuntu1804-docker-4c-4g-4386 CRON[8161]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 2 10:23:01 prd-ubuntu1804-docker-4c-4g-4386 CRON[8161]: pam_unix(cron:session): session closed for user root Jul 2 10:24:01 prd-ubuntu1804-docker-4c-4g-4386 CRON[8203]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 2 10:24:01 prd-ubuntu1804-docker-4c-4g-4386 CRON[8203]: pam_unix(cron:session): session closed for user root Jul 2 10:25:01 prd-ubuntu1804-docker-4c-4g-4386 CRON[8208]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 2 10:25:01 prd-ubuntu1804-docker-4c-4g-4386 CRON[8208]: pam_unix(cron:session): session closed for user root Jul 2 10:25:51 prd-ubuntu1804-docker-4c-4g-4386 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/aiml-fw-athp-data-extraction-docker-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Jul 2 10:25:51 prd-ubuntu1804-docker-4c-4g-4386 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)