Sep 3 10:18:54 prd-ubuntu1804-docker-4c-4g-2728 passwd[922]: password for 'ubuntu' changed by 'root' Sep 3 10:18:54 prd-ubuntu1804-docker-4c-4g-2728 systemd-logind[1051]: Watching system buttons on /dev/input/event0 (Power Button) Sep 3 10:18:54 prd-ubuntu1804-docker-4c-4g-2728 systemd-logind[1051]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Sep 3 10:18:54 prd-ubuntu1804-docker-4c-4g-2728 systemd-logind[1051]: New seat seat0. Sep 3 10:18:54 prd-ubuntu1804-docker-4c-4g-2728 sshd[1177]: Server listening on 0.0.0.0 port 22. Sep 3 10:18:54 prd-ubuntu1804-docker-4c-4g-2728 sshd[1177]: Server listening on :: port 22. Sep 3 10:18:58 prd-ubuntu1804-docker-4c-4g-2728 sshd[1428]: Did not receive identification string from 10.32.4.5 port 35966 Sep 3 10:19:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[1460]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 3 10:19:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[1460]: pam_unix(cron:session): session closed for user root Sep 3 10:19:06 prd-ubuntu1804-docker-4c-4g-2728 sshd[1483]: Invalid user jenkins from 10.32.4.5 port 35974 Sep 3 10:19:06 prd-ubuntu1804-docker-4c-4g-2728 sshd[1483]: Received disconnect from 10.32.4.5 port 35974:11: Closed due to user request. [preauth] Sep 3 10:19:06 prd-ubuntu1804-docker-4c-4g-2728 sshd[1483]: Disconnected from invalid user jenkins 10.32.4.5 port 35974 [preauth] Sep 3 10:19:08 prd-ubuntu1804-docker-4c-4g-2728 sshd[1487]: Invalid user jenkins from 10.32.4.5 port 35978 Sep 3 10:19:08 prd-ubuntu1804-docker-4c-4g-2728 sshd[1487]: Received disconnect from 10.32.4.5 port 35978:11: Closed due to user request. [preauth] Sep 3 10:19:08 prd-ubuntu1804-docker-4c-4g-2728 sshd[1487]: Disconnected from invalid user jenkins 10.32.4.5 port 35978 [preauth] Sep 3 10:19:10 prd-ubuntu1804-docker-4c-4g-2728 sshd[1489]: Invalid user jenkins from 10.32.4.5 port 35980 Sep 3 10:19:10 prd-ubuntu1804-docker-4c-4g-2728 sshd[1489]: Received disconnect from 10.32.4.5 port 35980:11: Closed due to user request. [preauth] Sep 3 10:19:10 prd-ubuntu1804-docker-4c-4g-2728 sshd[1489]: Disconnected from invalid user jenkins 10.32.4.5 port 35980 [preauth] Sep 3 10:19:12 prd-ubuntu1804-docker-4c-4g-2728 sshd[1491]: Invalid user jenkins from 10.32.4.5 port 35982 Sep 3 10:19:12 prd-ubuntu1804-docker-4c-4g-2728 sshd[1491]: Received disconnect from 10.32.4.5 port 35982:11: Closed due to user request. [preauth] Sep 3 10:19:12 prd-ubuntu1804-docker-4c-4g-2728 sshd[1491]: Disconnected from invalid user jenkins 10.32.4.5 port 35982 [preauth] Sep 3 10:19:14 prd-ubuntu1804-docker-4c-4g-2728 sshd[1501]: Invalid user jenkins from 10.32.4.5 port 35984 Sep 3 10:19:14 prd-ubuntu1804-docker-4c-4g-2728 sshd[1501]: Received disconnect from 10.32.4.5 port 35984:11: Closed due to user request. [preauth] Sep 3 10:19:14 prd-ubuntu1804-docker-4c-4g-2728 sshd[1501]: Disconnected from invalid user jenkins 10.32.4.5 port 35984 [preauth] Sep 3 10:19:16 prd-ubuntu1804-docker-4c-4g-2728 sshd[1517]: Invalid user jenkins from 10.32.4.5 port 35986 Sep 3 10:19:17 prd-ubuntu1804-docker-4c-4g-2728 sshd[1517]: Received disconnect from 10.32.4.5 port 35986:11: Closed due to user request. [preauth] Sep 3 10:19:17 prd-ubuntu1804-docker-4c-4g-2728 sshd[1517]: Disconnected from invalid user jenkins 10.32.4.5 port 35986 [preauth] Sep 3 10:19:19 prd-ubuntu1804-docker-4c-4g-2728 sshd[1735]: Invalid user jenkins from 10.32.4.5 port 35988 Sep 3 10:19:19 prd-ubuntu1804-docker-4c-4g-2728 sshd[1735]: Received disconnect from 10.32.4.5 port 35988:11: Closed due to user request. [preauth] Sep 3 10:19:19 prd-ubuntu1804-docker-4c-4g-2728 sshd[1735]: Disconnected from invalid user jenkins 10.32.4.5 port 35988 [preauth] Sep 3 10:19:21 prd-ubuntu1804-docker-4c-4g-2728 sshd[1761]: Invalid user jenkins from 10.32.4.5 port 35990 Sep 3 10:19:21 prd-ubuntu1804-docker-4c-4g-2728 sshd[1761]: Received disconnect from 10.32.4.5 port 35990:11: Closed due to user request. [preauth] Sep 3 10:19:21 prd-ubuntu1804-docker-4c-4g-2728 sshd[1761]: Disconnected from invalid user jenkins 10.32.4.5 port 35990 [preauth] Sep 3 10:19:23 prd-ubuntu1804-docker-4c-4g-2728 sshd[1779]: Invalid user jenkins from 10.32.4.5 port 35994 Sep 3 10:19:23 prd-ubuntu1804-docker-4c-4g-2728 sshd[1779]: Received disconnect from 10.32.4.5 port 35994:11: Closed due to user request. [preauth] Sep 3 10:19:23 prd-ubuntu1804-docker-4c-4g-2728 sshd[1779]: Disconnected from invalid user jenkins 10.32.4.5 port 35994 [preauth] Sep 3 10:19:25 prd-ubuntu1804-docker-4c-4g-2728 sshd[1793]: Invalid user jenkins from 10.32.4.5 port 35996 Sep 3 10:19:25 prd-ubuntu1804-docker-4c-4g-2728 sshd[1793]: Received disconnect from 10.32.4.5 port 35996:11: Closed due to user request. [preauth] Sep 3 10:19:25 prd-ubuntu1804-docker-4c-4g-2728 sshd[1793]: Disconnected from invalid user jenkins 10.32.4.5 port 35996 [preauth] Sep 3 10:19:27 prd-ubuntu1804-docker-4c-4g-2728 useradd[1819]: new group: name=jenkins, GID=1001 Sep 3 10:19:27 prd-ubuntu1804-docker-4c-4g-2728 useradd[1819]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Sep 3 10:19:27 prd-ubuntu1804-docker-4c-4g-2728 usermod[1826]: add 'jenkins' to group 'docker' Sep 3 10:19:27 prd-ubuntu1804-docker-4c-4g-2728 usermod[1826]: add 'jenkins' to shadow group 'docker' Sep 3 10:19:27 prd-ubuntu1804-docker-4c-4g-2728 sshd[1860]: Accepted publickey for jenkins from 10.32.4.5 port 35998 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Sep 3 10:19:27 prd-ubuntu1804-docker-4c-4g-2728 sshd[1860]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Sep 3 10:19:27 prd-ubuntu1804-docker-4c-4g-2728 systemd-logind[1051]: New session 2 of user jenkins. Sep 3 10:19:27 prd-ubuntu1804-docker-4c-4g-2728 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Sep 3 10:20:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[2376]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 3 10:20:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[2376]: pam_unix(cron:session): session closed for user root Sep 3 10:21:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[2434]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 3 10:21:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[2434]: pam_unix(cron:session): session closed for user root Sep 3 10:22:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[3067]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 3 10:22:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[3067]: pam_unix(cron:session): session closed for user root Sep 3 10:23:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[8126]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 3 10:23:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[8126]: pam_unix(cron:session): session closed for user root Sep 3 10:24:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[8189]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 3 10:24:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[8189]: pam_unix(cron:session): session closed for user root Sep 3 10:25:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[8193]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 3 10:25:01 prd-ubuntu1804-docker-4c-4g-2728 CRON[8193]: pam_unix(cron:session): session closed for user root Sep 3 10:25:55 prd-ubuntu1804-docker-4c-4g-2728 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/aiml-fw-athp-data-extraction-docker-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Sep 3 10:25:55 prd-ubuntu1804-docker-4c-4g-2728 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)