Apr 7 08:56:40 prd-ubuntu1804-docker-4c-4g-4497 passwd[915]: password for 'ubuntu' changed by 'root' Apr 7 08:56:40 prd-ubuntu1804-docker-4c-4g-4497 systemd-logind[968]: Watching system buttons on /dev/input/event0 (Power Button) Apr 7 08:56:40 prd-ubuntu1804-docker-4c-4g-4497 systemd-logind[968]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Apr 7 08:56:40 prd-ubuntu1804-docker-4c-4g-4497 systemd-logind[968]: New seat seat0. Apr 7 08:56:40 prd-ubuntu1804-docker-4c-4g-4497 sshd[1069]: Server listening on 0.0.0.0 port 22. Apr 7 08:56:40 prd-ubuntu1804-docker-4c-4g-4497 sshd[1069]: Server listening on :: port 22. Apr 7 08:56:44 prd-ubuntu1804-docker-4c-4g-4497 sshd[1402]: Did not receive identification string from 10.32.4.5 port 38504 Apr 7 08:56:51 prd-ubuntu1804-docker-4c-4g-4497 sshd[1483]: Invalid user jenkins from 10.32.4.5 port 38508 Apr 7 08:56:52 prd-ubuntu1804-docker-4c-4g-4497 sshd[1483]: Received disconnect from 10.32.4.5 port 38508:11: Closed due to user request. [preauth] Apr 7 08:56:52 prd-ubuntu1804-docker-4c-4g-4497 sshd[1483]: Disconnected from invalid user jenkins 10.32.4.5 port 38508 [preauth] Apr 7 08:56:54 prd-ubuntu1804-docker-4c-4g-4497 sshd[1487]: Invalid user jenkins from 10.32.4.5 port 38516 Apr 7 08:56:54 prd-ubuntu1804-docker-4c-4g-4497 sshd[1487]: Received disconnect from 10.32.4.5 port 38516:11: Closed due to user request. [preauth] Apr 7 08:56:54 prd-ubuntu1804-docker-4c-4g-4497 sshd[1487]: Disconnected from invalid user jenkins 10.32.4.5 port 38516 [preauth] Apr 7 08:56:56 prd-ubuntu1804-docker-4c-4g-4497 sshd[1489]: Invalid user jenkins from 10.32.4.5 port 38518 Apr 7 08:56:56 prd-ubuntu1804-docker-4c-4g-4497 sshd[1489]: Received disconnect from 10.32.4.5 port 38518:11: Closed due to user request. [preauth] Apr 7 08:56:56 prd-ubuntu1804-docker-4c-4g-4497 sshd[1489]: Disconnected from invalid user jenkins 10.32.4.5 port 38518 [preauth] Apr 7 08:56:58 prd-ubuntu1804-docker-4c-4g-4497 sshd[1491]: Invalid user jenkins from 10.32.4.5 port 38520 Apr 7 08:56:58 prd-ubuntu1804-docker-4c-4g-4497 sshd[1491]: Received disconnect from 10.32.4.5 port 38520:11: Closed due to user request. [preauth] Apr 7 08:56:58 prd-ubuntu1804-docker-4c-4g-4497 sshd[1491]: Disconnected from invalid user jenkins 10.32.4.5 port 38520 [preauth] Apr 7 08:57:00 prd-ubuntu1804-docker-4c-4g-4497 sshd[1493]: Invalid user jenkins from 10.32.4.5 port 38522 Apr 7 08:57:00 prd-ubuntu1804-docker-4c-4g-4497 sshd[1493]: Received disconnect from 10.32.4.5 port 38522:11: Closed due to user request. [preauth] Apr 7 08:57:00 prd-ubuntu1804-docker-4c-4g-4497 sshd[1493]: Disconnected from invalid user jenkins 10.32.4.5 port 38522 [preauth] Apr 7 08:57:01 prd-ubuntu1804-docker-4c-4g-4497 CRON[1496]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 7 08:57:01 prd-ubuntu1804-docker-4c-4g-4497 CRON[1496]: pam_unix(cron:session): session closed for user root Apr 7 08:57:02 prd-ubuntu1804-docker-4c-4g-4497 sshd[1514]: Invalid user jenkins from 10.32.4.5 port 38524 Apr 7 08:57:02 prd-ubuntu1804-docker-4c-4g-4497 sshd[1514]: Received disconnect from 10.32.4.5 port 38524:11: Closed due to user request. [preauth] Apr 7 08:57:02 prd-ubuntu1804-docker-4c-4g-4497 sshd[1514]: Disconnected from invalid user jenkins 10.32.4.5 port 38524 [preauth] Apr 7 08:57:05 prd-ubuntu1804-docker-4c-4g-4497 sshd[1743]: Invalid user jenkins from 10.32.4.5 port 38528 Apr 7 08:57:06 prd-ubuntu1804-docker-4c-4g-4497 sshd[1743]: Received disconnect from 10.32.4.5 port 38528:11: Closed due to user request. [preauth] Apr 7 08:57:06 prd-ubuntu1804-docker-4c-4g-4497 sshd[1743]: Disconnected from invalid user jenkins 10.32.4.5 port 38528 [preauth] Apr 7 08:57:08 prd-ubuntu1804-docker-4c-4g-4497 sshd[1783]: Invalid user jenkins from 10.32.4.5 port 38530 Apr 7 08:57:08 prd-ubuntu1804-docker-4c-4g-4497 sshd[1783]: Received disconnect from 10.32.4.5 port 38530:11: Closed due to user request. [preauth] Apr 7 08:57:08 prd-ubuntu1804-docker-4c-4g-4497 sshd[1783]: Disconnected from invalid user jenkins 10.32.4.5 port 38530 [preauth] Apr 7 08:57:10 prd-ubuntu1804-docker-4c-4g-4497 sshd[1793]: Invalid user jenkins from 10.32.4.5 port 38532 Apr 7 08:57:10 prd-ubuntu1804-docker-4c-4g-4497 sshd[1793]: Received disconnect from 10.32.4.5 port 38532:11: Closed due to user request. [preauth] Apr 7 08:57:10 prd-ubuntu1804-docker-4c-4g-4497 sshd[1793]: Disconnected from invalid user jenkins 10.32.4.5 port 38532 [preauth] Apr 7 08:57:10 prd-ubuntu1804-docker-4c-4g-4497 useradd[1803]: new group: name=jenkins, GID=1001 Apr 7 08:57:10 prd-ubuntu1804-docker-4c-4g-4497 useradd[1803]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Apr 7 08:57:10 prd-ubuntu1804-docker-4c-4g-4497 usermod[1810]: add 'jenkins' to group 'docker' Apr 7 08:57:10 prd-ubuntu1804-docker-4c-4g-4497 usermod[1810]: add 'jenkins' to shadow group 'docker' Apr 7 08:57:12 prd-ubuntu1804-docker-4c-4g-4497 sshd[1844]: Accepted publickey for jenkins from 10.32.4.5 port 38540 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Apr 7 08:57:12 prd-ubuntu1804-docker-4c-4g-4497 sshd[1844]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Apr 7 08:57:12 prd-ubuntu1804-docker-4c-4g-4497 systemd-logind[968]: New session 2 of user jenkins. Apr 7 08:57:12 prd-ubuntu1804-docker-4c-4g-4497 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Apr 7 08:58:02 prd-ubuntu1804-docker-4c-4g-4497 CRON[2397]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 7 08:58:02 prd-ubuntu1804-docker-4c-4g-4497 CRON[2397]: pam_unix(cron:session): session closed for user root Apr 7 08:59:01 prd-ubuntu1804-docker-4c-4g-4497 CRON[3194]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 7 08:59:01 prd-ubuntu1804-docker-4c-4g-4497 CRON[3194]: pam_unix(cron:session): session closed for user root Apr 7 08:59:11 prd-ubuntu1804-docker-4c-4g-4497 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/it-otf-dmaap-vth-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Apr 7 08:59:11 prd-ubuntu1804-docker-4c-4g-4497 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)