Nov 23 02:43:37 prd-ubuntu1804-docker-4c-4g-11063 passwd[912]: password for 'ubuntu' changed by 'root' Nov 23 02:43:37 prd-ubuntu1804-docker-4c-4g-11063 systemd-logind[963]: Watching system buttons on /dev/input/event0 (Power Button) Nov 23 02:43:37 prd-ubuntu1804-docker-4c-4g-11063 systemd-logind[963]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Nov 23 02:43:37 prd-ubuntu1804-docker-4c-4g-11063 systemd-logind[963]: New seat seat0. Nov 23 02:43:37 prd-ubuntu1804-docker-4c-4g-11063 sshd[1222]: Server listening on 0.0.0.0 port 22. Nov 23 02:43:37 prd-ubuntu1804-docker-4c-4g-11063 sshd[1222]: Server listening on :: port 22. Nov 23 02:43:40 prd-ubuntu1804-docker-4c-4g-11063 sshd[1422]: Did not receive identification string from 10.32.4.5 port 42820 Nov 23 02:43:50 prd-ubuntu1804-docker-4c-4g-11063 sshd[1488]: Invalid user jenkins from 10.32.4.5 port 42828 Nov 23 02:43:50 prd-ubuntu1804-docker-4c-4g-11063 sshd[1488]: Received disconnect from 10.32.4.5 port 42828:11: Closed due to user request. [preauth] Nov 23 02:43:50 prd-ubuntu1804-docker-4c-4g-11063 sshd[1488]: Disconnected from invalid user jenkins 10.32.4.5 port 42828 [preauth] Nov 23 02:43:52 prd-ubuntu1804-docker-4c-4g-11063 sshd[1492]: Invalid user jenkins from 10.32.4.5 port 42832 Nov 23 02:43:52 prd-ubuntu1804-docker-4c-4g-11063 sshd[1492]: Received disconnect from 10.32.4.5 port 42832:11: Closed due to user request. [preauth] Nov 23 02:43:52 prd-ubuntu1804-docker-4c-4g-11063 sshd[1492]: Disconnected from invalid user jenkins 10.32.4.5 port 42832 [preauth] Nov 23 02:43:54 prd-ubuntu1804-docker-4c-4g-11063 sshd[1494]: Invalid user jenkins from 10.32.4.5 port 42834 Nov 23 02:43:54 prd-ubuntu1804-docker-4c-4g-11063 sshd[1494]: Received disconnect from 10.32.4.5 port 42834:11: Closed due to user request. [preauth] Nov 23 02:43:54 prd-ubuntu1804-docker-4c-4g-11063 sshd[1494]: Disconnected from invalid user jenkins 10.32.4.5 port 42834 [preauth] Nov 23 02:43:56 prd-ubuntu1804-docker-4c-4g-11063 sshd[1496]: Invalid user jenkins from 10.32.4.5 port 42836 Nov 23 02:43:56 prd-ubuntu1804-docker-4c-4g-11063 sshd[1496]: Received disconnect from 10.32.4.5 port 42836:11: Closed due to user request. [preauth] Nov 23 02:43:56 prd-ubuntu1804-docker-4c-4g-11063 sshd[1496]: Disconnected from invalid user jenkins 10.32.4.5 port 42836 [preauth] Nov 23 02:43:58 prd-ubuntu1804-docker-4c-4g-11063 sshd[1509]: Invalid user jenkins from 10.32.4.5 port 42838 Nov 23 02:43:58 prd-ubuntu1804-docker-4c-4g-11063 sshd[1509]: Received disconnect from 10.32.4.5 port 42838:11: Closed due to user request. [preauth] Nov 23 02:43:58 prd-ubuntu1804-docker-4c-4g-11063 sshd[1509]: Disconnected from invalid user jenkins 10.32.4.5 port 42838 [preauth] Nov 23 02:44:01 prd-ubuntu1804-docker-4c-4g-11063 sshd[1734]: Invalid user jenkins from 10.32.4.5 port 42840 Nov 23 02:44:01 prd-ubuntu1804-docker-4c-4g-11063 sshd[1734]: Received disconnect from 10.32.4.5 port 42840:11: Closed due to user request. [preauth] Nov 23 02:44:01 prd-ubuntu1804-docker-4c-4g-11063 sshd[1734]: Disconnected from invalid user jenkins 10.32.4.5 port 42840 [preauth] Nov 23 02:44:01 prd-ubuntu1804-docker-4c-4g-11063 CRON[1736]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 23 02:44:01 prd-ubuntu1804-docker-4c-4g-11063 CRON[1736]: pam_unix(cron:session): session closed for user root Nov 23 02:44:03 prd-ubuntu1804-docker-4c-4g-11063 sshd[1783]: Invalid user jenkins from 10.32.4.5 port 42842 Nov 23 02:44:03 prd-ubuntu1804-docker-4c-4g-11063 sshd[1783]: Received disconnect from 10.32.4.5 port 42842:11: Closed due to user request. [preauth] Nov 23 02:44:03 prd-ubuntu1804-docker-4c-4g-11063 sshd[1783]: Disconnected from invalid user jenkins 10.32.4.5 port 42842 [preauth] Nov 23 02:44:06 prd-ubuntu1804-docker-4c-4g-11063 sshd[1787]: Invalid user jenkins from 10.32.4.5 port 42844 Nov 23 02:44:06 prd-ubuntu1804-docker-4c-4g-11063 sshd[1787]: Received disconnect from 10.32.4.5 port 42844:11: Closed due to user request. [preauth] Nov 23 02:44:06 prd-ubuntu1804-docker-4c-4g-11063 sshd[1787]: Disconnected from invalid user jenkins 10.32.4.5 port 42844 [preauth] Nov 23 02:44:06 prd-ubuntu1804-docker-4c-4g-11063 useradd[1803]: new group: name=jenkins, GID=1001 Nov 23 02:44:06 prd-ubuntu1804-docker-4c-4g-11063 useradd[1803]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Nov 23 02:44:06 prd-ubuntu1804-docker-4c-4g-11063 usermod[1810]: add 'jenkins' to group 'docker' Nov 23 02:44:06 prd-ubuntu1804-docker-4c-4g-11063 usermod[1810]: add 'jenkins' to shadow group 'docker' Nov 23 02:44:08 prd-ubuntu1804-docker-4c-4g-11063 sshd[1853]: Accepted publickey for jenkins from 10.32.4.5 port 42846 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Nov 23 02:44:08 prd-ubuntu1804-docker-4c-4g-11063 sshd[1853]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Nov 23 02:44:08 prd-ubuntu1804-docker-4c-4g-11063 systemd-logind[963]: New session 2 of user jenkins. Nov 23 02:44:08 prd-ubuntu1804-docker-4c-4g-11063 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Nov 23 02:45:01 prd-ubuntu1804-docker-4c-4g-11063 CRON[2600]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 23 02:45:01 prd-ubuntu1804-docker-4c-4g-11063 CRON[2600]: pam_unix(cron:session): session closed for user root Nov 23 02:46:01 prd-ubuntu1804-docker-4c-4g-11063 CRON[4148]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 23 02:46:01 prd-ubuntu1804-docker-4c-4g-11063 CRON[4148]: pam_unix(cron:session): session closed for user root Nov 23 02:47:01 prd-ubuntu1804-docker-4c-4g-11063 CRON[8877]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 23 02:47:01 prd-ubuntu1804-docker-4c-4g-11063 CRON[8877]: pam_unix(cron:session): session closed for user root Nov 23 02:47:49 prd-ubuntu1804-docker-4c-4g-11063 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/it-dev-bldr-ubuntu18-c-go-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Nov 23 02:47:49 prd-ubuntu1804-docker-4c-4g-11063 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)