Apr 22 13:31:35 prd-ubuntu1804-docker-4c-4g-692 passwd[950]: password for 'ubuntu' changed by 'root' Apr 22 13:31:35 prd-ubuntu1804-docker-4c-4g-692 systemd-logind[989]: Watching system buttons on /dev/input/event0 (Power Button) Apr 22 13:31:35 prd-ubuntu1804-docker-4c-4g-692 systemd-logind[989]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Apr 22 13:31:35 prd-ubuntu1804-docker-4c-4g-692 systemd-logind[989]: New seat seat0. Apr 22 13:31:35 prd-ubuntu1804-docker-4c-4g-692 sshd[1273]: Server listening on 0.0.0.0 port 22. Apr 22 13:31:35 prd-ubuntu1804-docker-4c-4g-692 sshd[1273]: Server listening on :: port 22. Apr 22 13:31:38 prd-ubuntu1804-docker-4c-4g-692 sshd[1486]: Did not receive identification string from 10.32.4.5 port 53274 Apr 22 13:31:45 prd-ubuntu1804-docker-4c-4g-692 sshd[1535]: Invalid user jenkins from 10.32.4.5 port 53286 Apr 22 13:31:45 prd-ubuntu1804-docker-4c-4g-692 sshd[1535]: Received disconnect from 10.32.4.5 port 53286:11: Closed due to user request. [preauth] Apr 22 13:31:45 prd-ubuntu1804-docker-4c-4g-692 sshd[1535]: Disconnected from invalid user jenkins 10.32.4.5 port 53286 [preauth] Apr 22 13:31:47 prd-ubuntu1804-docker-4c-4g-692 sshd[1539]: Invalid user jenkins from 10.32.4.5 port 53296 Apr 22 13:31:47 prd-ubuntu1804-docker-4c-4g-692 sshd[1539]: Received disconnect from 10.32.4.5 port 53296:11: Closed due to user request. [preauth] Apr 22 13:31:47 prd-ubuntu1804-docker-4c-4g-692 sshd[1539]: Disconnected from invalid user jenkins 10.32.4.5 port 53296 [preauth] Apr 22 13:31:49 prd-ubuntu1804-docker-4c-4g-692 sshd[1541]: Invalid user jenkins from 10.32.4.5 port 53304 Apr 22 13:31:49 prd-ubuntu1804-docker-4c-4g-692 sshd[1541]: Received disconnect from 10.32.4.5 port 53304:11: Closed due to user request. [preauth] Apr 22 13:31:49 prd-ubuntu1804-docker-4c-4g-692 sshd[1541]: Disconnected from invalid user jenkins 10.32.4.5 port 53304 [preauth] Apr 22 13:31:51 prd-ubuntu1804-docker-4c-4g-692 sshd[1543]: Invalid user jenkins from 10.32.4.5 port 53308 Apr 22 13:31:51 prd-ubuntu1804-docker-4c-4g-692 sshd[1543]: Received disconnect from 10.32.4.5 port 53308:11: Closed due to user request. [preauth] Apr 22 13:31:51 prd-ubuntu1804-docker-4c-4g-692 sshd[1543]: Disconnected from invalid user jenkins 10.32.4.5 port 53308 [preauth] Apr 22 13:31:53 prd-ubuntu1804-docker-4c-4g-692 sshd[1563]: Invalid user jenkins from 10.32.4.5 port 53314 Apr 22 13:31:53 prd-ubuntu1804-docker-4c-4g-692 sshd[1563]: Received disconnect from 10.32.4.5 port 53314:11: Closed due to user request. [preauth] Apr 22 13:31:53 prd-ubuntu1804-docker-4c-4g-692 sshd[1563]: Disconnected from invalid user jenkins 10.32.4.5 port 53314 [preauth] Apr 22 13:31:55 prd-ubuntu1804-docker-4c-4g-692 sshd[1565]: Invalid user jenkins from 10.32.4.5 port 53322 Apr 22 13:31:55 prd-ubuntu1804-docker-4c-4g-692 sshd[1565]: Received disconnect from 10.32.4.5 port 53322:11: Closed due to user request. [preauth] Apr 22 13:31:55 prd-ubuntu1804-docker-4c-4g-692 sshd[1565]: Disconnected from invalid user jenkins 10.32.4.5 port 53322 [preauth] Apr 22 13:31:57 prd-ubuntu1804-docker-4c-4g-692 sshd[1695]: Invalid user jenkins from 10.32.4.5 port 53326 Apr 22 13:31:57 prd-ubuntu1804-docker-4c-4g-692 sshd[1695]: Received disconnect from 10.32.4.5 port 53326:11: Closed due to user request. [preauth] Apr 22 13:31:57 prd-ubuntu1804-docker-4c-4g-692 sshd[1695]: Disconnected from invalid user jenkins 10.32.4.5 port 53326 [preauth] Apr 22 13:31:59 prd-ubuntu1804-docker-4c-4g-692 sshd[1832]: Invalid user jenkins from 10.32.4.5 port 53336 Apr 22 13:31:59 prd-ubuntu1804-docker-4c-4g-692 sshd[1832]: Received disconnect from 10.32.4.5 port 53336:11: Closed due to user request. [preauth] Apr 22 13:31:59 prd-ubuntu1804-docker-4c-4g-692 sshd[1832]: Disconnected from invalid user jenkins 10.32.4.5 port 53336 [preauth] Apr 22 13:32:01 prd-ubuntu1804-docker-4c-4g-692 CRON[1851]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 22 13:32:01 prd-ubuntu1804-docker-4c-4g-692 CRON[1851]: pam_unix(cron:session): session closed for user root Apr 22 13:32:02 prd-ubuntu1804-docker-4c-4g-692 sshd[1859]: Invalid user jenkins from 10.32.4.5 port 53338 Apr 22 13:32:02 prd-ubuntu1804-docker-4c-4g-692 sshd[1859]: Received disconnect from 10.32.4.5 port 53338:11: Closed due to user request. [preauth] Apr 22 13:32:02 prd-ubuntu1804-docker-4c-4g-692 sshd[1859]: Disconnected from invalid user jenkins 10.32.4.5 port 53338 [preauth] Apr 22 13:32:03 prd-ubuntu1804-docker-4c-4g-692 useradd[1877]: new group: name=jenkins, GID=1001 Apr 22 13:32:03 prd-ubuntu1804-docker-4c-4g-692 useradd[1877]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Apr 22 13:32:03 prd-ubuntu1804-docker-4c-4g-692 usermod[1884]: add 'jenkins' to group 'docker' Apr 22 13:32:03 prd-ubuntu1804-docker-4c-4g-692 usermod[1884]: add 'jenkins' to shadow group 'docker' Apr 22 13:32:04 prd-ubuntu1804-docker-4c-4g-692 sshd[1918]: Accepted publickey for jenkins from 10.32.4.5 port 53340 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Apr 22 13:32:04 prd-ubuntu1804-docker-4c-4g-692 sshd[1918]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Apr 22 13:32:04 prd-ubuntu1804-docker-4c-4g-692 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Apr 22 13:32:04 prd-ubuntu1804-docker-4c-4g-692 systemd-logind[989]: New session 2 of user jenkins. Apr 22 13:33:01 prd-ubuntu1804-docker-4c-4g-692 CRON[2505]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 22 13:33:01 prd-ubuntu1804-docker-4c-4g-692 CRON[2505]: pam_unix(cron:session): session closed for user root Apr 22 13:34:01 prd-ubuntu1804-docker-4c-4g-692 CRON[6784]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 22 13:34:01 prd-ubuntu1804-docker-4c-4g-692 CRON[6784]: pam_unix(cron:session): session closed for user root Apr 22 13:34:18 prd-ubuntu1804-docker-4c-4g-692 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/it-dep-helm-docker-verify-all ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Apr 22 13:34:18 prd-ubuntu1804-docker-4c-4g-692 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)