Sep 9 08:43:50 prd-ubuntu1804-docker-4c-4g-3250 passwd[924]: password for 'ubuntu' changed by 'root' Sep 9 08:43:50 prd-ubuntu1804-docker-4c-4g-3250 systemd-logind[1005]: Watching system buttons on /dev/input/event0 (Power Button) Sep 9 08:43:50 prd-ubuntu1804-docker-4c-4g-3250 systemd-logind[1005]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Sep 9 08:43:50 prd-ubuntu1804-docker-4c-4g-3250 systemd-logind[1005]: New seat seat0. Sep 9 08:43:50 prd-ubuntu1804-docker-4c-4g-3250 sshd[1239]: Server listening on 0.0.0.0 port 22. Sep 9 08:43:50 prd-ubuntu1804-docker-4c-4g-3250 sshd[1239]: Server listening on :: port 22. Sep 9 08:43:55 prd-ubuntu1804-docker-4c-4g-3250 sshd[1489]: Did not receive identification string from 10.32.4.5 port 59052 Sep 9 08:43:55 prd-ubuntu1804-docker-4c-4g-3250 sshd[1494]: Invalid user jenkins from 10.32.4.5 port 59054 Sep 9 08:43:55 prd-ubuntu1804-docker-4c-4g-3250 sshd[1494]: Received disconnect from 10.32.4.5 port 59054:11: Closed due to user request. [preauth] Sep 9 08:43:55 prd-ubuntu1804-docker-4c-4g-3250 sshd[1494]: Disconnected from invalid user jenkins 10.32.4.5 port 59054 [preauth] Sep 9 08:43:57 prd-ubuntu1804-docker-4c-4g-3250 sshd[1515]: Invalid user jenkins from 10.32.4.5 port 59056 Sep 9 08:43:57 prd-ubuntu1804-docker-4c-4g-3250 sshd[1515]: Received disconnect from 10.32.4.5 port 59056:11: Closed due to user request. [preauth] Sep 9 08:43:57 prd-ubuntu1804-docker-4c-4g-3250 sshd[1515]: Disconnected from invalid user jenkins 10.32.4.5 port 59056 [preauth] Sep 9 08:43:59 prd-ubuntu1804-docker-4c-4g-3250 sshd[1517]: Invalid user jenkins from 10.32.4.5 port 59064 Sep 9 08:43:59 prd-ubuntu1804-docker-4c-4g-3250 sshd[1517]: Received disconnect from 10.32.4.5 port 59064:11: Closed due to user request. [preauth] Sep 9 08:43:59 prd-ubuntu1804-docker-4c-4g-3250 sshd[1517]: Disconnected from invalid user jenkins 10.32.4.5 port 59064 [preauth] Sep 9 08:44:01 prd-ubuntu1804-docker-4c-4g-3250 CRON[1520]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 9 08:44:01 prd-ubuntu1804-docker-4c-4g-3250 CRON[1520]: pam_unix(cron:session): session closed for user root Sep 9 08:44:01 prd-ubuntu1804-docker-4c-4g-3250 sshd[1528]: Invalid user jenkins from 10.32.4.5 port 59066 Sep 9 08:44:02 prd-ubuntu1804-docker-4c-4g-3250 sshd[1528]: Received disconnect from 10.32.4.5 port 59066:11: Closed due to user request. [preauth] Sep 9 08:44:02 prd-ubuntu1804-docker-4c-4g-3250 sshd[1528]: Disconnected from invalid user jenkins 10.32.4.5 port 59066 [preauth] Sep 9 08:44:04 prd-ubuntu1804-docker-4c-4g-3250 sshd[1530]: Invalid user jenkins from 10.32.4.5 port 59068 Sep 9 08:44:04 prd-ubuntu1804-docker-4c-4g-3250 sshd[1530]: Received disconnect from 10.32.4.5 port 59068:11: Closed due to user request. [preauth] Sep 9 08:44:04 prd-ubuntu1804-docker-4c-4g-3250 sshd[1530]: Disconnected from invalid user jenkins 10.32.4.5 port 59068 [preauth] Sep 9 08:44:06 prd-ubuntu1804-docker-4c-4g-3250 sshd[1532]: Invalid user jenkins from 10.32.4.5 port 59070 Sep 9 08:44:06 prd-ubuntu1804-docker-4c-4g-3250 sshd[1532]: Received disconnect from 10.32.4.5 port 59070:11: Closed due to user request. [preauth] Sep 9 08:44:06 prd-ubuntu1804-docker-4c-4g-3250 sshd[1532]: Disconnected from invalid user jenkins 10.32.4.5 port 59070 [preauth] Sep 9 08:44:08 prd-ubuntu1804-docker-4c-4g-3250 sshd[1534]: Invalid user jenkins from 10.32.4.5 port 59074 Sep 9 08:44:08 prd-ubuntu1804-docker-4c-4g-3250 sshd[1534]: Received disconnect from 10.32.4.5 port 59074:11: Closed due to user request. [preauth] Sep 9 08:44:08 prd-ubuntu1804-docker-4c-4g-3250 sshd[1534]: Disconnected from invalid user jenkins 10.32.4.5 port 59074 [preauth] Sep 9 08:44:10 prd-ubuntu1804-docker-4c-4g-3250 sshd[1543]: Invalid user jenkins from 10.32.4.5 port 59076 Sep 9 08:44:10 prd-ubuntu1804-docker-4c-4g-3250 sshd[1543]: Received disconnect from 10.32.4.5 port 59076:11: Closed due to user request. [preauth] Sep 9 08:44:10 prd-ubuntu1804-docker-4c-4g-3250 sshd[1543]: Disconnected from invalid user jenkins 10.32.4.5 port 59076 [preauth] Sep 9 08:44:13 prd-ubuntu1804-docker-4c-4g-3250 sshd[1684]: Invalid user jenkins from 10.32.4.5 port 59078 Sep 9 08:44:13 prd-ubuntu1804-docker-4c-4g-3250 sshd[1684]: Received disconnect from 10.32.4.5 port 59078:11: Closed due to user request. [preauth] Sep 9 08:44:13 prd-ubuntu1804-docker-4c-4g-3250 sshd[1684]: Disconnected from invalid user jenkins 10.32.4.5 port 59078 [preauth] Sep 9 08:44:15 prd-ubuntu1804-docker-4c-4g-3250 sshd[1771]: Invalid user jenkins from 10.32.4.5 port 59080 Sep 9 08:44:15 prd-ubuntu1804-docker-4c-4g-3250 sshd[1771]: Received disconnect from 10.32.4.5 port 59080:11: Closed due to user request. [preauth] Sep 9 08:44:15 prd-ubuntu1804-docker-4c-4g-3250 sshd[1771]: Disconnected from invalid user jenkins 10.32.4.5 port 59080 [preauth] Sep 9 08:44:17 prd-ubuntu1804-docker-4c-4g-3250 sshd[1807]: Invalid user jenkins from 10.32.4.5 port 59082 Sep 9 08:44:17 prd-ubuntu1804-docker-4c-4g-3250 sshd[1807]: Received disconnect from 10.32.4.5 port 59082:11: Closed due to user request. [preauth] Sep 9 08:44:17 prd-ubuntu1804-docker-4c-4g-3250 sshd[1807]: Disconnected from invalid user jenkins 10.32.4.5 port 59082 [preauth] Sep 9 08:44:19 prd-ubuntu1804-docker-4c-4g-3250 sshd[1815]: Invalid user jenkins from 10.32.4.5 port 59084 Sep 9 08:44:19 prd-ubuntu1804-docker-4c-4g-3250 sshd[1815]: Received disconnect from 10.32.4.5 port 59084:11: Closed due to user request. [preauth] Sep 9 08:44:19 prd-ubuntu1804-docker-4c-4g-3250 sshd[1815]: Disconnected from invalid user jenkins 10.32.4.5 port 59084 [preauth] Sep 9 08:44:22 prd-ubuntu1804-docker-4c-4g-3250 sshd[1840]: Invalid user jenkins from 10.32.4.5 port 59086 Sep 9 08:44:22 prd-ubuntu1804-docker-4c-4g-3250 sshd[1840]: Received disconnect from 10.32.4.5 port 59086:11: Closed due to user request. [preauth] Sep 9 08:44:22 prd-ubuntu1804-docker-4c-4g-3250 sshd[1840]: Disconnected from invalid user jenkins 10.32.4.5 port 59086 [preauth] Sep 9 08:44:22 prd-ubuntu1804-docker-4c-4g-3250 useradd[1850]: new group: name=jenkins, GID=1001 Sep 9 08:44:22 prd-ubuntu1804-docker-4c-4g-3250 useradd[1850]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Sep 9 08:44:22 prd-ubuntu1804-docker-4c-4g-3250 usermod[1857]: add 'jenkins' to group 'docker' Sep 9 08:44:22 prd-ubuntu1804-docker-4c-4g-3250 usermod[1857]: add 'jenkins' to shadow group 'docker' Sep 9 08:44:24 prd-ubuntu1804-docker-4c-4g-3250 sshd[1901]: Accepted publickey for jenkins from 10.32.4.5 port 59090 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Sep 9 08:44:24 prd-ubuntu1804-docker-4c-4g-3250 sshd[1901]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Sep 9 08:44:24 prd-ubuntu1804-docker-4c-4g-3250 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Sep 9 08:44:24 prd-ubuntu1804-docker-4c-4g-3250 systemd-logind[1005]: New session 2 of user jenkins. Sep 9 08:45:02 prd-ubuntu1804-docker-4c-4g-3250 CRON[2397]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 9 08:45:02 prd-ubuntu1804-docker-4c-4g-3250 CRON[2397]: pam_unix(cron:session): session closed for user root Sep 9 08:46:01 prd-ubuntu1804-docker-4c-4g-3250 CRON[2452]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 9 08:46:01 prd-ubuntu1804-docker-4c-4g-3250 CRON[2452]: pam_unix(cron:session): session closed for user root Sep 9 08:47:01 prd-ubuntu1804-docker-4c-4g-3250 CRON[2938]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 9 08:47:01 prd-ubuntu1804-docker-4c-4g-3250 CRON[2938]: pam_unix(cron:session): session closed for user root Sep 9 08:48:01 prd-ubuntu1804-docker-4c-4g-3250 CRON[3553]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 9 08:48:01 prd-ubuntu1804-docker-4c-4g-3250 CRON[3553]: pam_unix(cron:session): session closed for user root Sep 9 08:48:12 prd-ubuntu1804-docker-4c-4g-3250 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/nonrtric-plt-auth-token-fetch-docker-merge-i-release ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Sep 9 08:48:12 prd-ubuntu1804-docker-4c-4g-3250 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)