Apr 25 11:54:44 prd-ubuntu1804-docker-4c-4g-869 passwd[925]: password for 'ubuntu' changed by 'root' Apr 25 11:54:44 prd-ubuntu1804-docker-4c-4g-869 systemd-logind[962]: Watching system buttons on /dev/input/event0 (Power Button) Apr 25 11:54:44 prd-ubuntu1804-docker-4c-4g-869 systemd-logind[962]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Apr 25 11:54:44 prd-ubuntu1804-docker-4c-4g-869 systemd-logind[962]: New seat seat0. Apr 25 11:54:44 prd-ubuntu1804-docker-4c-4g-869 sshd[1234]: Server listening on 0.0.0.0 port 22. Apr 25 11:54:44 prd-ubuntu1804-docker-4c-4g-869 sshd[1234]: Server listening on :: port 22. Apr 25 11:54:47 prd-ubuntu1804-docker-4c-4g-869 sshd[1434]: Did not receive identification string from 10.32.4.5 port 48344 Apr 25 11:54:54 prd-ubuntu1804-docker-4c-4g-869 sshd[1505]: Invalid user jenkins from 10.32.4.5 port 48352 Apr 25 11:54:54 prd-ubuntu1804-docker-4c-4g-869 sshd[1505]: Received disconnect from 10.32.4.5 port 48352:11: Closed due to user request. [preauth] Apr 25 11:54:54 prd-ubuntu1804-docker-4c-4g-869 sshd[1505]: Disconnected from invalid user jenkins 10.32.4.5 port 48352 [preauth] Apr 25 11:54:56 prd-ubuntu1804-docker-4c-4g-869 sshd[1509]: Invalid user jenkins from 10.32.4.5 port 48360 Apr 25 11:54:56 prd-ubuntu1804-docker-4c-4g-869 sshd[1509]: Received disconnect from 10.32.4.5 port 48360:11: Closed due to user request. [preauth] Apr 25 11:54:56 prd-ubuntu1804-docker-4c-4g-869 sshd[1509]: Disconnected from invalid user jenkins 10.32.4.5 port 48360 [preauth] Apr 25 11:54:58 prd-ubuntu1804-docker-4c-4g-869 sshd[1511]: Invalid user jenkins from 10.32.4.5 port 48366 Apr 25 11:54:58 prd-ubuntu1804-docker-4c-4g-869 sshd[1511]: Received disconnect from 10.32.4.5 port 48366:11: Closed due to user request. [preauth] Apr 25 11:54:58 prd-ubuntu1804-docker-4c-4g-869 sshd[1511]: Disconnected from invalid user jenkins 10.32.4.5 port 48366 [preauth] Apr 25 11:55:00 prd-ubuntu1804-docker-4c-4g-869 sshd[1513]: Invalid user jenkins from 10.32.4.5 port 48372 Apr 25 11:55:00 prd-ubuntu1804-docker-4c-4g-869 sshd[1513]: Received disconnect from 10.32.4.5 port 48372:11: Closed due to user request. [preauth] Apr 25 11:55:00 prd-ubuntu1804-docker-4c-4g-869 sshd[1513]: Disconnected from invalid user jenkins 10.32.4.5 port 48372 [preauth] Apr 25 11:55:01 prd-ubuntu1804-docker-4c-4g-869 CRON[1516]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 25 11:55:01 prd-ubuntu1804-docker-4c-4g-869 CRON[1516]: pam_unix(cron:session): session closed for user root Apr 25 11:55:02 prd-ubuntu1804-docker-4c-4g-869 sshd[1524]: Invalid user jenkins from 10.32.4.5 port 48382 Apr 25 11:55:02 prd-ubuntu1804-docker-4c-4g-869 sshd[1524]: Received disconnect from 10.32.4.5 port 48382:11: Closed due to user request. [preauth] Apr 25 11:55:02 prd-ubuntu1804-docker-4c-4g-869 sshd[1524]: Disconnected from invalid user jenkins 10.32.4.5 port 48382 [preauth] Apr 25 11:55:05 prd-ubuntu1804-docker-4c-4g-869 sshd[1526]: Invalid user jenkins from 10.32.4.5 port 48390 Apr 25 11:55:05 prd-ubuntu1804-docker-4c-4g-869 sshd[1526]: Received disconnect from 10.32.4.5 port 48390:11: Closed due to user request. [preauth] Apr 25 11:55:05 prd-ubuntu1804-docker-4c-4g-869 sshd[1526]: Disconnected from invalid user jenkins 10.32.4.5 port 48390 [preauth] Apr 25 11:55:07 prd-ubuntu1804-docker-4c-4g-869 sshd[1609]: Invalid user jenkins from 10.32.4.5 port 48394 Apr 25 11:55:07 prd-ubuntu1804-docker-4c-4g-869 sshd[1609]: Received disconnect from 10.32.4.5 port 48394:11: Closed due to user request. [preauth] Apr 25 11:55:07 prd-ubuntu1804-docker-4c-4g-869 sshd[1609]: Disconnected from invalid user jenkins 10.32.4.5 port 48394 [preauth] Apr 25 11:55:10 prd-ubuntu1804-docker-4c-4g-869 sshd[1766]: Invalid user jenkins from 10.32.4.5 port 48404 Apr 25 11:55:10 prd-ubuntu1804-docker-4c-4g-869 sshd[1766]: Received disconnect from 10.32.4.5 port 48404:11: Closed due to user request. [preauth] Apr 25 11:55:10 prd-ubuntu1804-docker-4c-4g-869 sshd[1766]: Disconnected from invalid user jenkins 10.32.4.5 port 48404 [preauth] Apr 25 11:55:12 prd-ubuntu1804-docker-4c-4g-869 sshd[1803]: Invalid user jenkins from 10.32.4.5 port 48414 Apr 25 11:55:12 prd-ubuntu1804-docker-4c-4g-869 sshd[1803]: Received disconnect from 10.32.4.5 port 48414:11: Closed due to user request. [preauth] Apr 25 11:55:12 prd-ubuntu1804-docker-4c-4g-869 sshd[1803]: Disconnected from invalid user jenkins 10.32.4.5 port 48414 [preauth] Apr 25 11:55:13 prd-ubuntu1804-docker-4c-4g-869 useradd[1821]: new group: name=jenkins, GID=1001 Apr 25 11:55:13 prd-ubuntu1804-docker-4c-4g-869 useradd[1821]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Apr 25 11:55:13 prd-ubuntu1804-docker-4c-4g-869 usermod[1828]: add 'jenkins' to group 'docker' Apr 25 11:55:13 prd-ubuntu1804-docker-4c-4g-869 usermod[1828]: add 'jenkins' to shadow group 'docker' Apr 25 11:55:14 prd-ubuntu1804-docker-4c-4g-869 sshd[1862]: Accepted publickey for jenkins from 10.32.4.5 port 48416 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Apr 25 11:55:14 prd-ubuntu1804-docker-4c-4g-869 sshd[1862]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Apr 25 11:55:14 prd-ubuntu1804-docker-4c-4g-869 systemd-logind[962]: New session 2 of user jenkins. Apr 25 11:55:14 prd-ubuntu1804-docker-4c-4g-869 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Apr 25 11:56:01 prd-ubuntu1804-docker-4c-4g-869 CRON[2431]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 25 11:56:01 prd-ubuntu1804-docker-4c-4g-869 CRON[2431]: pam_unix(cron:session): session closed for user root Apr 25 11:57:01 prd-ubuntu1804-docker-4c-4g-869 CRON[6448]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 25 11:57:01 prd-ubuntu1804-docker-4c-4g-869 CRON[6448]: pam_unix(cron:session): session closed for user root Apr 25 11:57:30 prd-ubuntu1804-docker-4c-4g-869 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/it-dep-helm-docker-verify-all ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Apr 25 11:57:30 prd-ubuntu1804-docker-4c-4g-869 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)