Aug 5 07:05:40 prd-ubuntu1804-docker-4c-4g-153 passwd[948]: password for 'ubuntu' changed by 'root' Aug 5 07:05:40 prd-ubuntu1804-docker-4c-4g-153 systemd-logind[1063]: Watching system buttons on /dev/input/event0 (Power Button) Aug 5 07:05:40 prd-ubuntu1804-docker-4c-4g-153 systemd-logind[1063]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Aug 5 07:05:40 prd-ubuntu1804-docker-4c-4g-153 systemd-logind[1063]: New seat seat0. Aug 5 07:05:41 prd-ubuntu1804-docker-4c-4g-153 sshd[1218]: Server listening on 0.0.0.0 port 22. Aug 5 07:05:41 prd-ubuntu1804-docker-4c-4g-153 sshd[1218]: Server listening on :: port 22. Aug 5 07:05:46 prd-ubuntu1804-docker-4c-4g-153 sshd[1464]: Did not receive identification string from 10.32.4.5 port 36470 Aug 5 07:05:55 prd-ubuntu1804-docker-4c-4g-153 sshd[1505]: Invalid user jenkins from 10.32.4.5 port 36474 Aug 5 07:05:55 prd-ubuntu1804-docker-4c-4g-153 sshd[1505]: Received disconnect from 10.32.4.5 port 36474:11: Closed due to user request. [preauth] Aug 5 07:05:55 prd-ubuntu1804-docker-4c-4g-153 sshd[1505]: Disconnected from invalid user jenkins 10.32.4.5 port 36474 [preauth] Aug 5 07:05:57 prd-ubuntu1804-docker-4c-4g-153 sshd[1509]: Invalid user jenkins from 10.32.4.5 port 36476 Aug 5 07:05:57 prd-ubuntu1804-docker-4c-4g-153 sshd[1509]: Received disconnect from 10.32.4.5 port 36476:11: Closed due to user request. [preauth] Aug 5 07:05:57 prd-ubuntu1804-docker-4c-4g-153 sshd[1509]: Disconnected from invalid user jenkins 10.32.4.5 port 36476 [preauth] Aug 5 07:06:00 prd-ubuntu1804-docker-4c-4g-153 sshd[1511]: Invalid user jenkins from 10.32.4.5 port 36484 Aug 5 07:06:00 prd-ubuntu1804-docker-4c-4g-153 sshd[1511]: Received disconnect from 10.32.4.5 port 36484:11: Closed due to user request. [preauth] Aug 5 07:06:00 prd-ubuntu1804-docker-4c-4g-153 sshd[1511]: Disconnected from invalid user jenkins 10.32.4.5 port 36484 [preauth] Aug 5 07:06:01 prd-ubuntu1804-docker-4c-4g-153 CRON[1522]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 5 07:06:01 prd-ubuntu1804-docker-4c-4g-153 CRON[1522]: pam_unix(cron:session): session closed for user root Aug 5 07:06:02 prd-ubuntu1804-docker-4c-4g-153 sshd[1536]: Invalid user jenkins from 10.32.4.5 port 36486 Aug 5 07:06:02 prd-ubuntu1804-docker-4c-4g-153 sshd[1536]: Received disconnect from 10.32.4.5 port 36486:11: Closed due to user request. [preauth] Aug 5 07:06:02 prd-ubuntu1804-docker-4c-4g-153 sshd[1536]: Disconnected from invalid user jenkins 10.32.4.5 port 36486 [preauth] Aug 5 07:06:05 prd-ubuntu1804-docker-4c-4g-153 sshd[1691]: Invalid user jenkins from 10.32.4.5 port 36488 Aug 5 07:06:05 prd-ubuntu1804-docker-4c-4g-153 sshd[1691]: Received disconnect from 10.32.4.5 port 36488:11: Closed due to user request. [preauth] Aug 5 07:06:05 prd-ubuntu1804-docker-4c-4g-153 sshd[1691]: Disconnected from invalid user jenkins 10.32.4.5 port 36488 [preauth] Aug 5 07:06:07 prd-ubuntu1804-docker-4c-4g-153 sshd[1764]: Invalid user jenkins from 10.32.4.5 port 36490 Aug 5 07:06:07 prd-ubuntu1804-docker-4c-4g-153 sshd[1764]: Received disconnect from 10.32.4.5 port 36490:11: Closed due to user request. [preauth] Aug 5 07:06:07 prd-ubuntu1804-docker-4c-4g-153 sshd[1764]: Disconnected from invalid user jenkins 10.32.4.5 port 36490 [preauth] Aug 5 07:06:09 prd-ubuntu1804-docker-4c-4g-153 sshd[1803]: Invalid user jenkins from 10.32.4.5 port 36494 Aug 5 07:06:09 prd-ubuntu1804-docker-4c-4g-153 sshd[1803]: Received disconnect from 10.32.4.5 port 36494:11: Closed due to user request. [preauth] Aug 5 07:06:09 prd-ubuntu1804-docker-4c-4g-153 sshd[1803]: Disconnected from invalid user jenkins 10.32.4.5 port 36494 [preauth] Aug 5 07:06:11 prd-ubuntu1804-docker-4c-4g-153 sshd[1807]: Invalid user jenkins from 10.32.4.5 port 36498 Aug 5 07:06:11 prd-ubuntu1804-docker-4c-4g-153 sshd[1807]: Received disconnect from 10.32.4.5 port 36498:11: Closed due to user request. [preauth] Aug 5 07:06:11 prd-ubuntu1804-docker-4c-4g-153 sshd[1807]: Disconnected from invalid user jenkins 10.32.4.5 port 36498 [preauth] Aug 5 07:06:13 prd-ubuntu1804-docker-4c-4g-153 useradd[1833]: new group: name=jenkins, GID=1001 Aug 5 07:06:13 prd-ubuntu1804-docker-4c-4g-153 useradd[1833]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Aug 5 07:06:13 prd-ubuntu1804-docker-4c-4g-153 sshd[1834]: Received disconnect from 10.32.4.5 port 36500:11: Closed due to user request. [preauth] Aug 5 07:06:13 prd-ubuntu1804-docker-4c-4g-153 sshd[1834]: Disconnected from authenticating user jenkins 10.32.4.5 port 36500 [preauth] Aug 5 07:06:13 prd-ubuntu1804-docker-4c-4g-153 usermod[1842]: add 'jenkins' to group 'docker' Aug 5 07:06:13 prd-ubuntu1804-docker-4c-4g-153 usermod[1842]: add 'jenkins' to shadow group 'docker' Aug 5 07:06:15 prd-ubuntu1804-docker-4c-4g-153 sshd[1895]: Accepted publickey for jenkins from 10.32.4.5 port 36502 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Aug 5 07:06:15 prd-ubuntu1804-docker-4c-4g-153 sshd[1895]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Aug 5 07:06:15 prd-ubuntu1804-docker-4c-4g-153 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Aug 5 07:06:15 prd-ubuntu1804-docker-4c-4g-153 systemd-logind[1063]: New session 2 of user jenkins. Aug 5 07:07:02 prd-ubuntu1804-docker-4c-4g-153 CRON[2412]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 5 07:07:02 prd-ubuntu1804-docker-4c-4g-153 CRON[2412]: pam_unix(cron:session): session closed for user root Aug 5 07:08:01 prd-ubuntu1804-docker-4c-4g-153 CRON[2454]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 5 07:08:01 prd-ubuntu1804-docker-4c-4g-153 CRON[2454]: pam_unix(cron:session): session closed for user root Aug 5 07:09:01 prd-ubuntu1804-docker-4c-4g-153 CRON[3049]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 5 07:09:01 prd-ubuntu1804-docker-4c-4g-153 CRON[3049]: pam_unix(cron:session): session closed for user root Aug 5 07:09:49 prd-ubuntu1804-docker-4c-4g-153 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/it-otf-ping-test-head-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Aug 5 07:09:49 prd-ubuntu1804-docker-4c-4g-153 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)