Jan 23 01:49:44 prd-ubuntu1804-docker-4c-4g-2553 passwd[954]: password for 'ubuntu' changed by 'root' Jan 23 01:49:44 prd-ubuntu1804-docker-4c-4g-2553 sshd[1078]: Server listening on 0.0.0.0 port 22. Jan 23 01:49:44 prd-ubuntu1804-docker-4c-4g-2553 sshd[1078]: Server listening on :: port 22. Jan 23 01:49:45 prd-ubuntu1804-docker-4c-4g-2553 systemd-logind[1065]: Watching system buttons on /dev/input/event0 (Power Button) Jan 23 01:49:45 prd-ubuntu1804-docker-4c-4g-2553 systemd-logind[1065]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jan 23 01:49:45 prd-ubuntu1804-docker-4c-4g-2553 systemd-logind[1065]: New seat seat0. Jan 23 01:49:48 prd-ubuntu1804-docker-4c-4g-2553 sshd[1425]: Did not receive identification string from 10.32.4.5 port 34390 Jan 23 01:49:58 prd-ubuntu1804-docker-4c-4g-2553 sshd[1468]: Invalid user jenkins from 10.32.4.5 port 34398 Jan 23 01:49:58 prd-ubuntu1804-docker-4c-4g-2553 sshd[1468]: Received disconnect from 10.32.4.5 port 34398:11: Closed due to user request. [preauth] Jan 23 01:49:58 prd-ubuntu1804-docker-4c-4g-2553 sshd[1468]: Disconnected from invalid user jenkins 10.32.4.5 port 34398 [preauth] Jan 23 01:50:00 prd-ubuntu1804-docker-4c-4g-2553 sshd[1472]: Invalid user jenkins from 10.32.4.5 port 34402 Jan 23 01:50:00 prd-ubuntu1804-docker-4c-4g-2553 sshd[1472]: Received disconnect from 10.32.4.5 port 34402:11: Closed due to user request. [preauth] Jan 23 01:50:00 prd-ubuntu1804-docker-4c-4g-2553 sshd[1472]: Disconnected from invalid user jenkins 10.32.4.5 port 34402 [preauth] Jan 23 01:50:01 prd-ubuntu1804-docker-4c-4g-2553 CRON[1475]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 23 01:50:01 prd-ubuntu1804-docker-4c-4g-2553 CRON[1475]: pam_unix(cron:session): session closed for user root Jan 23 01:50:02 prd-ubuntu1804-docker-4c-4g-2553 sshd[1482]: Invalid user jenkins from 10.32.4.5 port 34410 Jan 23 01:50:02 prd-ubuntu1804-docker-4c-4g-2553 sshd[1482]: Received disconnect from 10.32.4.5 port 34410:11: Closed due to user request. [preauth] Jan 23 01:50:02 prd-ubuntu1804-docker-4c-4g-2553 sshd[1482]: Disconnected from invalid user jenkins 10.32.4.5 port 34410 [preauth] Jan 23 01:50:04 prd-ubuntu1804-docker-4c-4g-2553 sshd[1484]: Invalid user jenkins from 10.32.4.5 port 34412 Jan 23 01:50:04 prd-ubuntu1804-docker-4c-4g-2553 sshd[1484]: Received disconnect from 10.32.4.5 port 34412:11: Closed due to user request. [preauth] Jan 23 01:50:04 prd-ubuntu1804-docker-4c-4g-2553 sshd[1484]: Disconnected from invalid user jenkins 10.32.4.5 port 34412 [preauth] Jan 23 01:50:06 prd-ubuntu1804-docker-4c-4g-2553 sshd[1569]: Invalid user jenkins from 10.32.4.5 port 34414 Jan 23 01:50:07 prd-ubuntu1804-docker-4c-4g-2553 sshd[1569]: Received disconnect from 10.32.4.5 port 34414:11: Closed due to user request. [preauth] Jan 23 01:50:07 prd-ubuntu1804-docker-4c-4g-2553 sshd[1569]: Disconnected from invalid user jenkins 10.32.4.5 port 34414 [preauth] Jan 23 01:50:09 prd-ubuntu1804-docker-4c-4g-2553 sshd[1726]: Invalid user jenkins from 10.32.4.5 port 34416 Jan 23 01:50:09 prd-ubuntu1804-docker-4c-4g-2553 sshd[1726]: Received disconnect from 10.32.4.5 port 34416:11: Closed due to user request. [preauth] Jan 23 01:50:09 prd-ubuntu1804-docker-4c-4g-2553 sshd[1726]: Disconnected from invalid user jenkins 10.32.4.5 port 34416 [preauth] Jan 23 01:50:11 prd-ubuntu1804-docker-4c-4g-2553 sshd[1763]: Invalid user jenkins from 10.32.4.5 port 34418 Jan 23 01:50:11 prd-ubuntu1804-docker-4c-4g-2553 sshd[1763]: Received disconnect from 10.32.4.5 port 34418:11: Closed due to user request. [preauth] Jan 23 01:50:11 prd-ubuntu1804-docker-4c-4g-2553 sshd[1763]: Disconnected from invalid user jenkins 10.32.4.5 port 34418 [preauth] Jan 23 01:50:12 prd-ubuntu1804-docker-4c-4g-2553 useradd[1781]: new group: name=jenkins, GID=1001 Jan 23 01:50:12 prd-ubuntu1804-docker-4c-4g-2553 useradd[1781]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Jan 23 01:50:13 prd-ubuntu1804-docker-4c-4g-2553 usermod[1788]: add 'jenkins' to group 'docker' Jan 23 01:50:13 prd-ubuntu1804-docker-4c-4g-2553 usermod[1788]: add 'jenkins' to shadow group 'docker' Jan 23 01:50:13 prd-ubuntu1804-docker-4c-4g-2553 sshd[1822]: Accepted publickey for jenkins from 10.32.4.5 port 34420 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Jan 23 01:50:13 prd-ubuntu1804-docker-4c-4g-2553 sshd[1822]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jan 23 01:50:13 prd-ubuntu1804-docker-4c-4g-2553 systemd-logind[1065]: New session 2 of user jenkins. Jan 23 01:50:13 prd-ubuntu1804-docker-4c-4g-2553 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jan 23 01:51:01 prd-ubuntu1804-docker-4c-4g-2553 CRON[2413]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 23 01:51:01 prd-ubuntu1804-docker-4c-4g-2553 CRON[2413]: pam_unix(cron:session): session closed for user root Jan 23 01:52:01 prd-ubuntu1804-docker-4c-4g-2553 CRON[5222]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 23 01:52:01 prd-ubuntu1804-docker-4c-4g-2553 CRON[5222]: pam_unix(cron:session): session closed for user root Jan 23 01:53:01 prd-ubuntu1804-docker-4c-4g-2553 CRON[5226]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 23 01:53:01 prd-ubuntu1804-docker-4c-4g-2553 CRON[5226]: pam_unix(cron:session): session closed for user root Jan 23 01:54:01 prd-ubuntu1804-docker-4c-4g-2553 CRON[5271]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 23 01:54:01 prd-ubuntu1804-docker-4c-4g-2553 CRON[5271]: pam_unix(cron:session): session closed for user root Jan 23 01:55:01 prd-ubuntu1804-docker-4c-4g-2553 CRON[5752]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 23 01:55:01 prd-ubuntu1804-docker-4c-4g-2553 CRON[5752]: pam_unix(cron:session): session closed for user root Jan 23 01:55:17 prd-ubuntu1804-docker-4c-4g-2553 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/it-otf-service-api-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Jan 23 01:55:17 prd-ubuntu1804-docker-4c-4g-2553 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)