Nov 20 22:15:39 prd-ubuntu1804-docker-4c-4g-10875 passwd[925]: password for 'ubuntu' changed by 'root' Nov 20 22:15:39 prd-ubuntu1804-docker-4c-4g-10875 systemd-logind[994]: Watching system buttons on /dev/input/event0 (Power Button) Nov 20 22:15:39 prd-ubuntu1804-docker-4c-4g-10875 systemd-logind[994]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Nov 20 22:15:39 prd-ubuntu1804-docker-4c-4g-10875 systemd-logind[994]: New seat seat0. Nov 20 22:15:39 prd-ubuntu1804-docker-4c-4g-10875 sshd[1097]: Server listening on 0.0.0.0 port 22. Nov 20 22:15:39 prd-ubuntu1804-docker-4c-4g-10875 sshd[1097]: Server listening on :: port 22. Nov 20 22:15:42 prd-ubuntu1804-docker-4c-4g-10875 sshd[1419]: Did not receive identification string from 10.32.4.5 port 56336 Nov 20 22:15:51 prd-ubuntu1804-docker-4c-4g-10875 sshd[1497]: Invalid user jenkins from 10.32.4.5 port 56344 Nov 20 22:15:51 prd-ubuntu1804-docker-4c-4g-10875 sshd[1497]: Received disconnect from 10.32.4.5 port 56344:11: Closed due to user request. [preauth] Nov 20 22:15:51 prd-ubuntu1804-docker-4c-4g-10875 sshd[1497]: Disconnected from invalid user jenkins 10.32.4.5 port 56344 [preauth] Nov 20 22:15:53 prd-ubuntu1804-docker-4c-4g-10875 sshd[1501]: Invalid user jenkins from 10.32.4.5 port 56348 Nov 20 22:15:53 prd-ubuntu1804-docker-4c-4g-10875 sshd[1501]: Received disconnect from 10.32.4.5 port 56348:11: Closed due to user request. [preauth] Nov 20 22:15:53 prd-ubuntu1804-docker-4c-4g-10875 sshd[1501]: Disconnected from invalid user jenkins 10.32.4.5 port 56348 [preauth] Nov 20 22:15:55 prd-ubuntu1804-docker-4c-4g-10875 sshd[1503]: Invalid user jenkins from 10.32.4.5 port 56350 Nov 20 22:15:55 prd-ubuntu1804-docker-4c-4g-10875 sshd[1503]: Received disconnect from 10.32.4.5 port 56350:11: Closed due to user request. [preauth] Nov 20 22:15:55 prd-ubuntu1804-docker-4c-4g-10875 sshd[1503]: Disconnected from invalid user jenkins 10.32.4.5 port 56350 [preauth] Nov 20 22:15:57 prd-ubuntu1804-docker-4c-4g-10875 sshd[1505]: Invalid user jenkins from 10.32.4.5 port 56352 Nov 20 22:15:57 prd-ubuntu1804-docker-4c-4g-10875 sshd[1505]: Received disconnect from 10.32.4.5 port 56352:11: Closed due to user request. [preauth] Nov 20 22:15:57 prd-ubuntu1804-docker-4c-4g-10875 sshd[1505]: Disconnected from invalid user jenkins 10.32.4.5 port 56352 [preauth] Nov 20 22:15:59 prd-ubuntu1804-docker-4c-4g-10875 sshd[1507]: Invalid user jenkins from 10.32.4.5 port 56354 Nov 20 22:15:59 prd-ubuntu1804-docker-4c-4g-10875 sshd[1507]: Received disconnect from 10.32.4.5 port 56354:11: Closed due to user request. [preauth] Nov 20 22:15:59 prd-ubuntu1804-docker-4c-4g-10875 sshd[1507]: Disconnected from invalid user jenkins 10.32.4.5 port 56354 [preauth] Nov 20 22:16:01 prd-ubuntu1804-docker-4c-4g-10875 sshd[1628]: Invalid user jenkins from 10.32.4.5 port 56356 Nov 20 22:16:01 prd-ubuntu1804-docker-4c-4g-10875 sshd[1628]: Received disconnect from 10.32.4.5 port 56356:11: Closed due to user request. [preauth] Nov 20 22:16:01 prd-ubuntu1804-docker-4c-4g-10875 sshd[1628]: Disconnected from invalid user jenkins 10.32.4.5 port 56356 [preauth] Nov 20 22:16:01 prd-ubuntu1804-docker-4c-4g-10875 CRON[1665]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 20 22:16:01 prd-ubuntu1804-docker-4c-4g-10875 CRON[1665]: pam_unix(cron:session): session closed for user root Nov 20 22:16:03 prd-ubuntu1804-docker-4c-4g-10875 sshd[1756]: Invalid user jenkins from 10.32.4.5 port 56360 Nov 20 22:16:03 prd-ubuntu1804-docker-4c-4g-10875 sshd[1756]: Received disconnect from 10.32.4.5 port 56360:11: Closed due to user request. [preauth] Nov 20 22:16:03 prd-ubuntu1804-docker-4c-4g-10875 sshd[1756]: Disconnected from invalid user jenkins 10.32.4.5 port 56360 [preauth] Nov 20 22:16:05 prd-ubuntu1804-docker-4c-4g-10875 sshd[1790]: Invalid user jenkins from 10.32.4.5 port 56362 Nov 20 22:16:05 prd-ubuntu1804-docker-4c-4g-10875 sshd[1790]: Received disconnect from 10.32.4.5 port 56362:11: Closed due to user request. [preauth] Nov 20 22:16:05 prd-ubuntu1804-docker-4c-4g-10875 sshd[1790]: Disconnected from invalid user jenkins 10.32.4.5 port 56362 [preauth] Nov 20 22:16:07 prd-ubuntu1804-docker-4c-4g-10875 useradd[1808]: new group: name=jenkins, GID=1001 Nov 20 22:16:07 prd-ubuntu1804-docker-4c-4g-10875 useradd[1808]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Nov 20 22:16:07 prd-ubuntu1804-docker-4c-4g-10875 usermod[1815]: add 'jenkins' to group 'docker' Nov 20 22:16:07 prd-ubuntu1804-docker-4c-4g-10875 usermod[1815]: add 'jenkins' to shadow group 'docker' Nov 20 22:16:08 prd-ubuntu1804-docker-4c-4g-10875 sshd[1849]: Accepted publickey for jenkins from 10.32.4.5 port 56364 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Nov 20 22:16:08 prd-ubuntu1804-docker-4c-4g-10875 sshd[1849]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Nov 20 22:16:08 prd-ubuntu1804-docker-4c-4g-10875 systemd-logind[994]: New session 2 of user jenkins. Nov 20 22:16:08 prd-ubuntu1804-docker-4c-4g-10875 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Nov 20 22:17:01 prd-ubuntu1804-docker-4c-4g-10875 CRON[2587]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 20 22:17:01 prd-ubuntu1804-docker-4c-4g-10875 CRON[2588]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 20 22:17:01 prd-ubuntu1804-docker-4c-4g-10875 CRON[2587]: pam_unix(cron:session): session closed for user root Nov 20 22:17:01 prd-ubuntu1804-docker-4c-4g-10875 CRON[2588]: pam_unix(cron:session): session closed for user root Nov 20 22:18:01 prd-ubuntu1804-docker-4c-4g-10875 CRON[3391]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 20 22:18:01 prd-ubuntu1804-docker-4c-4g-10875 CRON[3391]: pam_unix(cron:session): session closed for user root Nov 20 22:18:17 prd-ubuntu1804-docker-4c-4g-10875 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/it-otf-a1-mediator-vth-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Nov 20 22:18:17 prd-ubuntu1804-docker-4c-4g-10875 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)