Mar 4 10:18:45 prd-ubuntu1804-docker-4c-4g-8075 passwd[940]: password for 'ubuntu' changed by 'root' Mar 4 10:18:45 prd-ubuntu1804-docker-4c-4g-8075 systemd-logind[973]: Watching system buttons on /dev/input/event0 (Power Button) Mar 4 10:18:45 prd-ubuntu1804-docker-4c-4g-8075 systemd-logind[973]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Mar 4 10:18:45 prd-ubuntu1804-docker-4c-4g-8075 systemd-logind[973]: New seat seat0. Mar 4 10:18:45 prd-ubuntu1804-docker-4c-4g-8075 sshd[1084]: Server listening on 0.0.0.0 port 22. Mar 4 10:18:45 prd-ubuntu1804-docker-4c-4g-8075 sshd[1084]: Server listening on :: port 22. Mar 4 10:18:46 prd-ubuntu1804-docker-4c-4g-8075 sshd[1256]: Did not receive identification string from 10.32.4.5 port 60976 Mar 4 10:18:52 prd-ubuntu1804-docker-4c-4g-8075 sshd[1457]: Invalid user jenkins from 10.32.4.5 port 60978 Mar 4 10:18:52 prd-ubuntu1804-docker-4c-4g-8075 sshd[1457]: Received disconnect from 10.32.4.5 port 60978:11: Closed due to user request. [preauth] Mar 4 10:18:52 prd-ubuntu1804-docker-4c-4g-8075 sshd[1457]: Disconnected from invalid user jenkins 10.32.4.5 port 60978 [preauth] Mar 4 10:18:54 prd-ubuntu1804-docker-4c-4g-8075 sshd[1475]: Invalid user jenkins from 10.32.4.5 port 60980 Mar 4 10:18:54 prd-ubuntu1804-docker-4c-4g-8075 sshd[1475]: Received disconnect from 10.32.4.5 port 60980:11: Closed due to user request. [preauth] Mar 4 10:18:54 prd-ubuntu1804-docker-4c-4g-8075 sshd[1475]: Disconnected from invalid user jenkins 10.32.4.5 port 60980 [preauth] Mar 4 10:18:56 prd-ubuntu1804-docker-4c-4g-8075 sshd[1477]: Invalid user jenkins from 10.32.4.5 port 60984 Mar 4 10:18:56 prd-ubuntu1804-docker-4c-4g-8075 sshd[1477]: Received disconnect from 10.32.4.5 port 60984:11: Closed due to user request. [preauth] Mar 4 10:18:56 prd-ubuntu1804-docker-4c-4g-8075 sshd[1477]: Disconnected from invalid user jenkins 10.32.4.5 port 60984 [preauth] Mar 4 10:18:58 prd-ubuntu1804-docker-4c-4g-8075 sshd[1479]: Invalid user jenkins from 10.32.4.5 port 60986 Mar 4 10:18:58 prd-ubuntu1804-docker-4c-4g-8075 sshd[1479]: Received disconnect from 10.32.4.5 port 60986:11: Closed due to user request. [preauth] Mar 4 10:18:58 prd-ubuntu1804-docker-4c-4g-8075 sshd[1479]: Disconnected from invalid user jenkins 10.32.4.5 port 60986 [preauth] Mar 4 10:19:00 prd-ubuntu1804-docker-4c-4g-8075 sshd[1481]: Invalid user jenkins from 10.32.4.5 port 60988 Mar 4 10:19:00 prd-ubuntu1804-docker-4c-4g-8075 sshd[1481]: Received disconnect from 10.32.4.5 port 60988:11: Closed due to user request. [preauth] Mar 4 10:19:00 prd-ubuntu1804-docker-4c-4g-8075 sshd[1481]: Disconnected from invalid user jenkins 10.32.4.5 port 60988 [preauth] Mar 4 10:19:01 prd-ubuntu1804-docker-4c-4g-8075 CRON[1483]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 4 10:19:01 prd-ubuntu1804-docker-4c-4g-8075 CRON[1483]: pam_unix(cron:session): session closed for user root Mar 4 10:19:02 prd-ubuntu1804-docker-4c-4g-8075 sshd[1492]: Invalid user jenkins from 10.32.4.5 port 60992 Mar 4 10:19:02 prd-ubuntu1804-docker-4c-4g-8075 sshd[1492]: Received disconnect from 10.32.4.5 port 60992:11: Closed due to user request. [preauth] Mar 4 10:19:02 prd-ubuntu1804-docker-4c-4g-8075 sshd[1492]: Disconnected from invalid user jenkins 10.32.4.5 port 60992 [preauth] Mar 4 10:19:04 prd-ubuntu1804-docker-4c-4g-8075 sshd[1494]: Invalid user jenkins from 10.32.4.5 port 60994 Mar 4 10:19:04 prd-ubuntu1804-docker-4c-4g-8075 sshd[1494]: Received disconnect from 10.32.4.5 port 60994:11: Closed due to user request. [preauth] Mar 4 10:19:04 prd-ubuntu1804-docker-4c-4g-8075 sshd[1494]: Disconnected from invalid user jenkins 10.32.4.5 port 60994 [preauth] Mar 4 10:19:06 prd-ubuntu1804-docker-4c-4g-8075 sshd[1506]: Invalid user jenkins from 10.32.4.5 port 60996 Mar 4 10:19:06 prd-ubuntu1804-docker-4c-4g-8075 sshd[1506]: Received disconnect from 10.32.4.5 port 60996:11: Closed due to user request. [preauth] Mar 4 10:19:06 prd-ubuntu1804-docker-4c-4g-8075 sshd[1506]: Disconnected from invalid user jenkins 10.32.4.5 port 60996 [preauth] Mar 4 10:19:09 prd-ubuntu1804-docker-4c-4g-8075 sshd[1716]: Invalid user jenkins from 10.32.4.5 port 60998 Mar 4 10:19:09 prd-ubuntu1804-docker-4c-4g-8075 sshd[1716]: Received disconnect from 10.32.4.5 port 60998:11: Closed due to user request. [preauth] Mar 4 10:19:09 prd-ubuntu1804-docker-4c-4g-8075 sshd[1716]: Disconnected from invalid user jenkins 10.32.4.5 port 60998 [preauth] Mar 4 10:19:11 prd-ubuntu1804-docker-4c-4g-8075 sshd[1761]: Invalid user jenkins from 10.32.4.5 port 32768 Mar 4 10:19:11 prd-ubuntu1804-docker-4c-4g-8075 sshd[1761]: Received disconnect from 10.32.4.5 port 32768:11: Closed due to user request. [preauth] Mar 4 10:19:11 prd-ubuntu1804-docker-4c-4g-8075 sshd[1761]: Disconnected from invalid user jenkins 10.32.4.5 port 32768 [preauth] Mar 4 10:19:13 prd-ubuntu1804-docker-4c-4g-8075 sshd[1779]: Invalid user jenkins from 10.32.4.5 port 32772 Mar 4 10:19:13 prd-ubuntu1804-docker-4c-4g-8075 sshd[1779]: Received disconnect from 10.32.4.5 port 32772:11: Closed due to user request. [preauth] Mar 4 10:19:13 prd-ubuntu1804-docker-4c-4g-8075 sshd[1779]: Disconnected from invalid user jenkins 10.32.4.5 port 32772 [preauth] Mar 4 10:19:15 prd-ubuntu1804-docker-4c-4g-8075 sshd[1795]: Invalid user jenkins from 10.32.4.5 port 32776 Mar 4 10:19:15 prd-ubuntu1804-docker-4c-4g-8075 sshd[1795]: Received disconnect from 10.32.4.5 port 32776:11: Closed due to user request. [preauth] Mar 4 10:19:15 prd-ubuntu1804-docker-4c-4g-8075 sshd[1795]: Disconnected from invalid user jenkins 10.32.4.5 port 32776 [preauth] Mar 4 10:19:16 prd-ubuntu1804-docker-4c-4g-8075 useradd[1799]: new group: name=jenkins, GID=1001 Mar 4 10:19:16 prd-ubuntu1804-docker-4c-4g-8075 useradd[1799]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Mar 4 10:19:16 prd-ubuntu1804-docker-4c-4g-8075 usermod[1806]: add 'jenkins' to group 'docker' Mar 4 10:19:16 prd-ubuntu1804-docker-4c-4g-8075 usermod[1806]: add 'jenkins' to shadow group 'docker' Mar 4 10:19:18 prd-ubuntu1804-docker-4c-4g-8075 sshd[1850]: Accepted publickey for jenkins from 10.32.4.5 port 32778 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Mar 4 10:19:18 prd-ubuntu1804-docker-4c-4g-8075 sshd[1850]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Mar 4 10:19:18 prd-ubuntu1804-docker-4c-4g-8075 systemd-logind[973]: New session 2 of user jenkins. Mar 4 10:19:18 prd-ubuntu1804-docker-4c-4g-8075 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Mar 4 10:20:02 prd-ubuntu1804-docker-4c-4g-8075 CRON[2382]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 4 10:20:02 prd-ubuntu1804-docker-4c-4g-8075 CRON[2382]: pam_unix(cron:session): session closed for user root Mar 4 10:21:01 prd-ubuntu1804-docker-4c-4g-8075 CRON[2692]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 4 10:21:01 prd-ubuntu1804-docker-4c-4g-8075 CRON[2692]: pam_unix(cron:session): session closed for user root Mar 4 10:22:01 prd-ubuntu1804-docker-4c-4g-8075 CRON[4567]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 4 10:22:01 prd-ubuntu1804-docker-4c-4g-8075 CRON[4567]: pam_unix(cron:session): session closed for user root Mar 4 10:23:01 prd-ubuntu1804-docker-4c-4g-8075 CRON[8158]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 4 10:23:01 prd-ubuntu1804-docker-4c-4g-8075 CRON[8158]: pam_unix(cron:session): session closed for user root Mar 4 10:24:01 prd-ubuntu1804-docker-4c-4g-8075 CRON[8192]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 4 10:24:01 prd-ubuntu1804-docker-4c-4g-8075 CRON[8192]: pam_unix(cron:session): session closed for user root Mar 4 10:25:01 prd-ubuntu1804-docker-4c-4g-8075 CRON[8390]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 4 10:25:01 prd-ubuntu1804-docker-4c-4g-8075 CRON[8390]: pam_unix(cron:session): session closed for user root Mar 4 10:25:27 prd-ubuntu1804-docker-4c-4g-8075 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/aiml-fw-athp-data-extraction-docker-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Mar 4 10:25:27 prd-ubuntu1804-docker-4c-4g-8075 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)