Aug 20 12:42:13 prd-ubuntu1804-docker-4c-4g-1500 passwd[926]: password for 'ubuntu' changed by 'root' Aug 20 12:42:13 prd-ubuntu1804-docker-4c-4g-1500 systemd-logind[1038]: Watching system buttons on /dev/input/event0 (Power Button) Aug 20 12:42:13 prd-ubuntu1804-docker-4c-4g-1500 systemd-logind[1038]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Aug 20 12:42:13 prd-ubuntu1804-docker-4c-4g-1500 systemd-logind[1038]: New seat seat0. Aug 20 12:42:13 prd-ubuntu1804-docker-4c-4g-1500 sshd[1236]: Server listening on 0.0.0.0 port 22. Aug 20 12:42:13 prd-ubuntu1804-docker-4c-4g-1500 sshd[1236]: Server listening on :: port 22. Aug 20 12:42:19 prd-ubuntu1804-docker-4c-4g-1500 sshd[1498]: Did not receive identification string from 10.32.4.5 port 48492 Aug 20 12:42:26 prd-ubuntu1804-docker-4c-4g-1500 sshd[1517]: Invalid user jenkins from 10.32.4.5 port 48508 Aug 20 12:42:26 prd-ubuntu1804-docker-4c-4g-1500 sshd[1517]: Received disconnect from 10.32.4.5 port 48508:11: Closed due to user request. [preauth] Aug 20 12:42:26 prd-ubuntu1804-docker-4c-4g-1500 sshd[1517]: Disconnected from invalid user jenkins 10.32.4.5 port 48508 [preauth] Aug 20 12:42:28 prd-ubuntu1804-docker-4c-4g-1500 sshd[1521]: Invalid user jenkins from 10.32.4.5 port 48514 Aug 20 12:42:28 prd-ubuntu1804-docker-4c-4g-1500 sshd[1521]: Received disconnect from 10.32.4.5 port 48514:11: Closed due to user request. [preauth] Aug 20 12:42:28 prd-ubuntu1804-docker-4c-4g-1500 sshd[1521]: Disconnected from invalid user jenkins 10.32.4.5 port 48514 [preauth] Aug 20 12:42:30 prd-ubuntu1804-docker-4c-4g-1500 sshd[1523]: Invalid user jenkins from 10.32.4.5 port 48526 Aug 20 12:42:30 prd-ubuntu1804-docker-4c-4g-1500 sshd[1523]: Received disconnect from 10.32.4.5 port 48526:11: Closed due to user request. [preauth] Aug 20 12:42:30 prd-ubuntu1804-docker-4c-4g-1500 sshd[1523]: Disconnected from invalid user jenkins 10.32.4.5 port 48526 [preauth] Aug 20 12:42:32 prd-ubuntu1804-docker-4c-4g-1500 sshd[1525]: Invalid user jenkins from 10.32.4.5 port 48530 Aug 20 12:42:32 prd-ubuntu1804-docker-4c-4g-1500 sshd[1525]: Received disconnect from 10.32.4.5 port 48530:11: Closed due to user request. [preauth] Aug 20 12:42:32 prd-ubuntu1804-docker-4c-4g-1500 sshd[1525]: Disconnected from invalid user jenkins 10.32.4.5 port 48530 [preauth] Aug 20 12:42:35 prd-ubuntu1804-docker-4c-4g-1500 sshd[1544]: Invalid user jenkins from 10.32.4.5 port 48536 Aug 20 12:42:35 prd-ubuntu1804-docker-4c-4g-1500 sshd[1544]: Received disconnect from 10.32.4.5 port 48536:11: Closed due to user request. [preauth] Aug 20 12:42:35 prd-ubuntu1804-docker-4c-4g-1500 sshd[1544]: Disconnected from invalid user jenkins 10.32.4.5 port 48536 [preauth] Aug 20 12:42:37 prd-ubuntu1804-docker-4c-4g-1500 sshd[1752]: Invalid user jenkins from 10.32.4.5 port 48542 Aug 20 12:42:37 prd-ubuntu1804-docker-4c-4g-1500 sshd[1752]: Received disconnect from 10.32.4.5 port 48542:11: Closed due to user request. [preauth] Aug 20 12:42:37 prd-ubuntu1804-docker-4c-4g-1500 sshd[1752]: Disconnected from invalid user jenkins 10.32.4.5 port 48542 [preauth] Aug 20 12:42:39 prd-ubuntu1804-docker-4c-4g-1500 sshd[1798]: Invalid user jenkins from 10.32.4.5 port 48550 Aug 20 12:42:39 prd-ubuntu1804-docker-4c-4g-1500 sshd[1798]: Received disconnect from 10.32.4.5 port 48550:11: Closed due to user request. [preauth] Aug 20 12:42:39 prd-ubuntu1804-docker-4c-4g-1500 sshd[1798]: Disconnected from invalid user jenkins 10.32.4.5 port 48550 [preauth] Aug 20 12:42:41 prd-ubuntu1804-docker-4c-4g-1500 sshd[1806]: Invalid user jenkins from 10.32.4.5 port 48554 Aug 20 12:42:41 prd-ubuntu1804-docker-4c-4g-1500 sshd[1806]: Received disconnect from 10.32.4.5 port 48554:11: Closed due to user request. [preauth] Aug 20 12:42:41 prd-ubuntu1804-docker-4c-4g-1500 sshd[1806]: Disconnected from invalid user jenkins 10.32.4.5 port 48554 [preauth] Aug 20 12:42:43 prd-ubuntu1804-docker-4c-4g-1500 sshd[1820]: Invalid user jenkins from 10.32.4.5 port 48558 Aug 20 12:42:43 prd-ubuntu1804-docker-4c-4g-1500 sshd[1820]: Received disconnect from 10.32.4.5 port 48558:11: Closed due to user request. [preauth] Aug 20 12:42:43 prd-ubuntu1804-docker-4c-4g-1500 sshd[1820]: Disconnected from invalid user jenkins 10.32.4.5 port 48558 [preauth] Aug 20 12:42:43 prd-ubuntu1804-docker-4c-4g-1500 useradd[1826]: new group: name=jenkins, GID=1001 Aug 20 12:42:43 prd-ubuntu1804-docker-4c-4g-1500 useradd[1826]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Aug 20 12:42:43 prd-ubuntu1804-docker-4c-4g-1500 usermod[1840]: add 'jenkins' to group 'docker' Aug 20 12:42:43 prd-ubuntu1804-docker-4c-4g-1500 usermod[1840]: add 'jenkins' to shadow group 'docker' Aug 20 12:42:46 prd-ubuntu1804-docker-4c-4g-1500 sshd[1887]: Accepted publickey for jenkins from 10.32.4.5 port 48562 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Aug 20 12:42:46 prd-ubuntu1804-docker-4c-4g-1500 sshd[1887]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Aug 20 12:42:46 prd-ubuntu1804-docker-4c-4g-1500 systemd-logind[1038]: New session 1 of user jenkins. Aug 20 12:42:46 prd-ubuntu1804-docker-4c-4g-1500 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Aug 20 12:43:01 prd-ubuntu1804-docker-4c-4g-1500 CRON[2095]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 20 12:43:01 prd-ubuntu1804-docker-4c-4g-1500 CRON[2095]: pam_unix(cron:session): session closed for user root Aug 20 12:44:01 prd-ubuntu1804-docker-4c-4g-1500 CRON[2115]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 20 12:44:01 prd-ubuntu1804-docker-4c-4g-1500 CRON[2115]: pam_unix(cron:session): session closed for user root Aug 20 12:44:09 prd-ubuntu1804-docker-4c-4g-1500 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/com-log-autotools-sonarqube ; USER=root ; COMMAND=/usr/bin/apt-get update Aug 20 12:44:09 prd-ubuntu1804-docker-4c-4g-1500 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Aug 20 12:44:24 prd-ubuntu1804-docker-4c-4g-1500 sudo: pam_unix(sudo:session): session closed for user root Aug 20 12:44:24 prd-ubuntu1804-docker-4c-4g-1500 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/com-log-autotools-sonarqube ; USER=root ; COMMAND=/usr/bin/apt-get -q -y install autoconf-archive libjsoncpp-dev rpm valgrind Aug 20 12:44:24 prd-ubuntu1804-docker-4c-4g-1500 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Aug 20 12:44:43 prd-ubuntu1804-docker-4c-4g-1500 sudo: pam_unix(sudo:session): session closed for user root Aug 20 12:44:58 prd-ubuntu1804-docker-4c-4g-1500 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/com-log-autotools-sonarqube ; USER=root ; COMMAND=/bin/mv build-wrapper-linux-x86 /opt/build-wrapper Aug 20 12:44:58 prd-ubuntu1804-docker-4c-4g-1500 sudo: pam_unix(sudo:session): session opened for user root by (uid=0) Aug 20 12:44:58 prd-ubuntu1804-docker-4c-4g-1500 sudo: pam_unix(sudo:session): session closed for user root Aug 20 12:45:01 prd-ubuntu1804-docker-4c-4g-1500 CRON[5345]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 20 12:45:01 prd-ubuntu1804-docker-4c-4g-1500 CRON[5345]: pam_unix(cron:session): session closed for user root Aug 20 12:46:01 prd-ubuntu1804-docker-4c-4g-1500 CRON[12507]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 20 12:46:01 prd-ubuntu1804-docker-4c-4g-1500 CRON[12507]: pam_unix(cron:session): session closed for user root Aug 20 12:47:01 prd-ubuntu1804-docker-4c-4g-1500 CRON[12853]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 20 12:47:01 prd-ubuntu1804-docker-4c-4g-1500 CRON[12853]: pam_unix(cron:session): session closed for user root Aug 20 12:48:01 prd-ubuntu1804-docker-4c-4g-1500 CRON[13056]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 20 12:48:02 prd-ubuntu1804-docker-4c-4g-1500 CRON[13056]: pam_unix(cron:session): session closed for user root Aug 20 12:48:12 prd-ubuntu1804-docker-4c-4g-1500 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/com-log-autotools-sonarqube ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Aug 20 12:48:12 prd-ubuntu1804-docker-4c-4g-1500 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)