Oct 10 01:49:35 prd-ubuntu1804-docker-4c-4g-7240 passwd[929]: password for 'ubuntu' changed by 'root' Oct 10 01:49:35 prd-ubuntu1804-docker-4c-4g-7240 systemd-logind[991]: Watching system buttons on /dev/input/event0 (Power Button) Oct 10 01:49:35 prd-ubuntu1804-docker-4c-4g-7240 systemd-logind[991]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Oct 10 01:49:35 prd-ubuntu1804-docker-4c-4g-7240 systemd-logind[991]: New seat seat0. Oct 10 01:49:35 prd-ubuntu1804-docker-4c-4g-7240 sshd[1090]: Server listening on 0.0.0.0 port 22. Oct 10 01:49:35 prd-ubuntu1804-docker-4c-4g-7240 sshd[1090]: Server listening on :: port 22. Oct 10 01:49:40 prd-ubuntu1804-docker-4c-4g-7240 sshd[1429]: Did not receive identification string from 10.32.4.5 port 60842 Oct 10 01:49:50 prd-ubuntu1804-docker-4c-4g-7240 sshd[1506]: Invalid user jenkins from 10.32.4.5 port 60852 Oct 10 01:49:50 prd-ubuntu1804-docker-4c-4g-7240 sshd[1506]: Received disconnect from 10.32.4.5 port 60852:11: Closed due to user request. [preauth] Oct 10 01:49:50 prd-ubuntu1804-docker-4c-4g-7240 sshd[1506]: Disconnected from invalid user jenkins 10.32.4.5 port 60852 [preauth] Oct 10 01:49:52 prd-ubuntu1804-docker-4c-4g-7240 sshd[1510]: Invalid user jenkins from 10.32.4.5 port 60856 Oct 10 01:49:52 prd-ubuntu1804-docker-4c-4g-7240 sshd[1510]: Received disconnect from 10.32.4.5 port 60856:11: Closed due to user request. [preauth] Oct 10 01:49:52 prd-ubuntu1804-docker-4c-4g-7240 sshd[1510]: Disconnected from invalid user jenkins 10.32.4.5 port 60856 [preauth] Oct 10 01:49:54 prd-ubuntu1804-docker-4c-4g-7240 sshd[1512]: Invalid user jenkins from 10.32.4.5 port 60858 Oct 10 01:49:54 prd-ubuntu1804-docker-4c-4g-7240 sshd[1512]: Received disconnect from 10.32.4.5 port 60858:11: Closed due to user request. [preauth] Oct 10 01:49:54 prd-ubuntu1804-docker-4c-4g-7240 sshd[1512]: Disconnected from invalid user jenkins 10.32.4.5 port 60858 [preauth] Oct 10 01:49:56 prd-ubuntu1804-docker-4c-4g-7240 sshd[1514]: Invalid user jenkins from 10.32.4.5 port 60860 Oct 10 01:49:56 prd-ubuntu1804-docker-4c-4g-7240 sshd[1514]: Received disconnect from 10.32.4.5 port 60860:11: Closed due to user request. [preauth] Oct 10 01:49:56 prd-ubuntu1804-docker-4c-4g-7240 sshd[1514]: Disconnected from invalid user jenkins 10.32.4.5 port 60860 [preauth] Oct 10 01:49:59 prd-ubuntu1804-docker-4c-4g-7240 sshd[1719]: Invalid user jenkins from 10.32.4.5 port 60862 Oct 10 01:49:59 prd-ubuntu1804-docker-4c-4g-7240 sshd[1719]: Received disconnect from 10.32.4.5 port 60862:11: Closed due to user request. [preauth] Oct 10 01:49:59 prd-ubuntu1804-docker-4c-4g-7240 sshd[1719]: Disconnected from invalid user jenkins 10.32.4.5 port 60862 [preauth] Oct 10 01:50:01 prd-ubuntu1804-docker-4c-4g-7240 sshd[1773]: Invalid user jenkins from 10.32.4.5 port 60864 Oct 10 01:50:01 prd-ubuntu1804-docker-4c-4g-7240 sshd[1773]: Received disconnect from 10.32.4.5 port 60864:11: Closed due to user request. [preauth] Oct 10 01:50:01 prd-ubuntu1804-docker-4c-4g-7240 sshd[1773]: Disconnected from invalid user jenkins 10.32.4.5 port 60864 [preauth] Oct 10 01:50:02 prd-ubuntu1804-docker-4c-4g-7240 CRON[1792]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 10 01:50:02 prd-ubuntu1804-docker-4c-4g-7240 CRON[1792]: pam_unix(cron:session): session closed for user root Oct 10 01:50:03 prd-ubuntu1804-docker-4c-4g-7240 sshd[1802]: Invalid user jenkins from 10.32.4.5 port 60872 Oct 10 01:50:03 prd-ubuntu1804-docker-4c-4g-7240 sshd[1802]: Received disconnect from 10.32.4.5 port 60872:11: Closed due to user request. [preauth] Oct 10 01:50:03 prd-ubuntu1804-docker-4c-4g-7240 sshd[1802]: Disconnected from invalid user jenkins 10.32.4.5 port 60872 [preauth] Oct 10 01:50:04 prd-ubuntu1804-docker-4c-4g-7240 useradd[1818]: new group: name=jenkins, GID=1001 Oct 10 01:50:04 prd-ubuntu1804-docker-4c-4g-7240 useradd[1818]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Oct 10 01:50:05 prd-ubuntu1804-docker-4c-4g-7240 usermod[1825]: add 'jenkins' to group 'docker' Oct 10 01:50:05 prd-ubuntu1804-docker-4c-4g-7240 usermod[1825]: add 'jenkins' to shadow group 'docker' Oct 10 01:50:06 prd-ubuntu1804-docker-4c-4g-7240 sshd[1859]: Accepted publickey for jenkins from 10.32.4.5 port 60874 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Oct 10 01:50:06 prd-ubuntu1804-docker-4c-4g-7240 sshd[1859]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Oct 10 01:50:06 prd-ubuntu1804-docker-4c-4g-7240 systemd-logind[991]: New session 2 of user jenkins. Oct 10 01:50:06 prd-ubuntu1804-docker-4c-4g-7240 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Oct 10 01:51:01 prd-ubuntu1804-docker-4c-4g-7240 CRON[2593]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 10 01:51:01 prd-ubuntu1804-docker-4c-4g-7240 CRON[2593]: pam_unix(cron:session): session closed for user root Oct 10 01:52:01 prd-ubuntu1804-docker-4c-4g-7240 CRON[5391]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 10 01:52:01 prd-ubuntu1804-docker-4c-4g-7240 CRON[5391]: pam_unix(cron:session): session closed for user root Oct 10 01:53:01 prd-ubuntu1804-docker-4c-4g-7240 CRON[5394]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 10 01:53:01 prd-ubuntu1804-docker-4c-4g-7240 CRON[5394]: pam_unix(cron:session): session closed for user root Oct 10 01:54:01 prd-ubuntu1804-docker-4c-4g-7240 CRON[5453]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 10 01:54:01 prd-ubuntu1804-docker-4c-4g-7240 CRON[5453]: pam_unix(cron:session): session closed for user root Oct 10 01:55:01 prd-ubuntu1804-docker-4c-4g-7240 CRON[6098]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 10 01:55:01 prd-ubuntu1804-docker-4c-4g-7240 CRON[6098]: pam_unix(cron:session): session closed for user root Oct 10 01:55:02 prd-ubuntu1804-docker-4c-4g-7240 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/it-otf-service-api-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Oct 10 01:55:02 prd-ubuntu1804-docker-4c-4g-7240 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)