May 24 10:04:54 prd-ubuntu1804-docker-4c-4g-1678 passwd[965]: password for 'ubuntu' changed by 'root' May 24 10:04:54 prd-ubuntu1804-docker-4c-4g-1678 systemd-logind[1036]: Watching system buttons on /dev/input/event0 (Power Button) May 24 10:04:54 prd-ubuntu1804-docker-4c-4g-1678 systemd-logind[1036]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) May 24 10:04:54 prd-ubuntu1804-docker-4c-4g-1678 systemd-logind[1036]: New seat seat0. May 24 10:04:54 prd-ubuntu1804-docker-4c-4g-1678 sshd[1311]: Server listening on 0.0.0.0 port 22. May 24 10:04:54 prd-ubuntu1804-docker-4c-4g-1678 sshd[1311]: Server listening on :: port 22. May 24 10:04:55 prd-ubuntu1804-docker-4c-4g-1678 sshd[1318]: Did not receive identification string from 10.32.4.5 port 50880 May 24 10:05:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[1584]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 10:05:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[1584]: pam_unix(cron:session): session closed for user root May 24 10:05:02 prd-ubuntu1804-docker-4c-4g-1678 sshd[1603]: Invalid user jenkins from 10.32.4.5 port 50892 May 24 10:05:02 prd-ubuntu1804-docker-4c-4g-1678 sshd[1603]: Received disconnect from 10.32.4.5 port 50892:11: Closed due to user request. [preauth] May 24 10:05:02 prd-ubuntu1804-docker-4c-4g-1678 sshd[1603]: Disconnected from invalid user jenkins 10.32.4.5 port 50892 [preauth] May 24 10:05:04 prd-ubuntu1804-docker-4c-4g-1678 sshd[1610]: Invalid user jenkins from 10.32.4.5 port 50902 May 24 10:05:04 prd-ubuntu1804-docker-4c-4g-1678 sshd[1610]: Received disconnect from 10.32.4.5 port 50902:11: Closed due to user request. [preauth] May 24 10:05:04 prd-ubuntu1804-docker-4c-4g-1678 sshd[1610]: Disconnected from invalid user jenkins 10.32.4.5 port 50902 [preauth] May 24 10:05:06 prd-ubuntu1804-docker-4c-4g-1678 sshd[1612]: Invalid user jenkins from 10.32.4.5 port 50908 May 24 10:05:06 prd-ubuntu1804-docker-4c-4g-1678 sshd[1612]: Received disconnect from 10.32.4.5 port 50908:11: Closed due to user request. [preauth] May 24 10:05:06 prd-ubuntu1804-docker-4c-4g-1678 sshd[1612]: Disconnected from invalid user jenkins 10.32.4.5 port 50908 [preauth] May 24 10:05:08 prd-ubuntu1804-docker-4c-4g-1678 sshd[1614]: Invalid user jenkins from 10.32.4.5 port 50918 May 24 10:05:09 prd-ubuntu1804-docker-4c-4g-1678 sshd[1614]: Received disconnect from 10.32.4.5 port 50918:11: Closed due to user request. [preauth] May 24 10:05:09 prd-ubuntu1804-docker-4c-4g-1678 sshd[1614]: Disconnected from invalid user jenkins 10.32.4.5 port 50918 [preauth] May 24 10:05:11 prd-ubuntu1804-docker-4c-4g-1678 sshd[1616]: Invalid user jenkins from 10.32.4.5 port 50924 May 24 10:05:11 prd-ubuntu1804-docker-4c-4g-1678 sshd[1616]: Received disconnect from 10.32.4.5 port 50924:11: Closed due to user request. [preauth] May 24 10:05:11 prd-ubuntu1804-docker-4c-4g-1678 sshd[1616]: Disconnected from invalid user jenkins 10.32.4.5 port 50924 [preauth] May 24 10:05:13 prd-ubuntu1804-docker-4c-4g-1678 sshd[1618]: Invalid user jenkins from 10.32.4.5 port 50930 May 24 10:05:13 prd-ubuntu1804-docker-4c-4g-1678 sshd[1618]: Received disconnect from 10.32.4.5 port 50930:11: Closed due to user request. [preauth] May 24 10:05:13 prd-ubuntu1804-docker-4c-4g-1678 sshd[1618]: Disconnected from invalid user jenkins 10.32.4.5 port 50930 [preauth] May 24 10:05:15 prd-ubuntu1804-docker-4c-4g-1678 sshd[1620]: Invalid user jenkins from 10.32.4.5 port 50936 May 24 10:05:15 prd-ubuntu1804-docker-4c-4g-1678 sshd[1620]: Received disconnect from 10.32.4.5 port 50936:11: Closed due to user request. [preauth] May 24 10:05:15 prd-ubuntu1804-docker-4c-4g-1678 sshd[1620]: Disconnected from invalid user jenkins 10.32.4.5 port 50936 [preauth] May 24 10:05:18 prd-ubuntu1804-docker-4c-4g-1678 sshd[1724]: Invalid user jenkins from 10.32.4.5 port 50950 May 24 10:05:18 prd-ubuntu1804-docker-4c-4g-1678 sshd[1724]: Received disconnect from 10.32.4.5 port 50950:11: Closed due to user request. [preauth] May 24 10:05:18 prd-ubuntu1804-docker-4c-4g-1678 sshd[1724]: Disconnected from invalid user jenkins 10.32.4.5 port 50950 [preauth] May 24 10:05:20 prd-ubuntu1804-docker-4c-4g-1678 sshd[1858]: Invalid user jenkins from 10.32.4.5 port 50956 May 24 10:05:20 prd-ubuntu1804-docker-4c-4g-1678 sshd[1858]: Received disconnect from 10.32.4.5 port 50956:11: Closed due to user request. [preauth] May 24 10:05:20 prd-ubuntu1804-docker-4c-4g-1678 sshd[1858]: Disconnected from invalid user jenkins 10.32.4.5 port 50956 [preauth] May 24 10:05:22 prd-ubuntu1804-docker-4c-4g-1678 sshd[1896]: Invalid user jenkins from 10.32.4.5 port 50958 May 24 10:05:22 prd-ubuntu1804-docker-4c-4g-1678 sshd[1896]: Received disconnect from 10.32.4.5 port 50958:11: Closed due to user request. [preauth] May 24 10:05:22 prd-ubuntu1804-docker-4c-4g-1678 sshd[1896]: Disconnected from invalid user jenkins 10.32.4.5 port 50958 [preauth] May 24 10:05:24 prd-ubuntu1804-docker-4c-4g-1678 sshd[1902]: Invalid user jenkins from 10.32.4.5 port 50960 May 24 10:05:24 prd-ubuntu1804-docker-4c-4g-1678 sshd[1902]: Received disconnect from 10.32.4.5 port 50960:11: Closed due to user request. [preauth] May 24 10:05:24 prd-ubuntu1804-docker-4c-4g-1678 sshd[1902]: Disconnected from invalid user jenkins 10.32.4.5 port 50960 [preauth] May 24 10:05:26 prd-ubuntu1804-docker-4c-4g-1678 useradd[1923]: new group: name=jenkins, GID=1001 May 24 10:05:26 prd-ubuntu1804-docker-4c-4g-1678 useradd[1923]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash May 24 10:05:26 prd-ubuntu1804-docker-4c-4g-1678 usermod[1931]: add 'jenkins' to group 'docker' May 24 10:05:26 prd-ubuntu1804-docker-4c-4g-1678 usermod[1931]: add 'jenkins' to shadow group 'docker' May 24 10:05:27 prd-ubuntu1804-docker-4c-4g-1678 sshd[1945]: Accepted publickey for jenkins from 10.32.4.5 port 50966 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI May 24 10:05:27 prd-ubuntu1804-docker-4c-4g-1678 sshd[1945]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) May 24 10:05:27 prd-ubuntu1804-docker-4c-4g-1678 systemd-logind[1036]: New session 2 of user jenkins. May 24 10:05:27 prd-ubuntu1804-docker-4c-4g-1678 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) May 24 10:06:02 prd-ubuntu1804-docker-4c-4g-1678 CRON[2476]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 10:06:02 prd-ubuntu1804-docker-4c-4g-1678 CRON[2476]: pam_unix(cron:session): session closed for user root May 24 10:07:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[2527]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 10:07:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[2527]: pam_unix(cron:session): session closed for user root May 24 10:08:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[2940]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 10:08:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[2940]: pam_unix(cron:session): session closed for user root May 24 10:09:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[3563]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 10:09:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[3563]: pam_unix(cron:session): session closed for user root May 24 10:10:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[3688]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 10:10:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[3688]: pam_unix(cron:session): session closed for user root May 24 10:11:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[4870]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 10:11:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[4870]: pam_unix(cron:session): session closed for user root May 24 10:12:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[6842]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 10:12:01 prd-ubuntu1804-docker-4c-4g-1678 CRON[6842]: pam_unix(cron:session): session closed for user root May 24 10:12:51 prd-ubuntu1804-docker-4c-4g-1678 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/it-test-ric-benchmarking-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp May 24 10:12:51 prd-ubuntu1804-docker-4c-4g-1678 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)