Jan 7 01:27:47 prd-ubuntu1804-docker-4c-4g-2640 passwd[958]: password for 'ubuntu' changed by 'root' Jan 7 01:27:47 prd-ubuntu1804-docker-4c-4g-2640 systemd-logind[1016]: Watching system buttons on /dev/input/event0 (Power Button) Jan 7 01:27:47 prd-ubuntu1804-docker-4c-4g-2640 systemd-logind[1016]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jan 7 01:27:47 prd-ubuntu1804-docker-4c-4g-2640 systemd-logind[1016]: New seat seat0. Jan 7 01:27:48 prd-ubuntu1804-docker-4c-4g-2640 sshd[1260]: Server listening on 0.0.0.0 port 22. Jan 7 01:27:48 prd-ubuntu1804-docker-4c-4g-2640 sshd[1260]: Server listening on :: port 22. Jan 7 01:27:48 prd-ubuntu1804-docker-4c-4g-2640 sshd[1304]: Did not receive identification string from 10.32.4.5 port 43140 Jan 7 01:27:51 prd-ubuntu1804-docker-4c-4g-2640 sshd[1472]: Invalid user jenkins from 10.32.4.5 port 43144 Jan 7 01:27:51 prd-ubuntu1804-docker-4c-4g-2640 sshd[1472]: Received disconnect from 10.32.4.5 port 43144:11: Closed due to user request. [preauth] Jan 7 01:27:51 prd-ubuntu1804-docker-4c-4g-2640 sshd[1472]: Disconnected from invalid user jenkins 10.32.4.5 port 43144 [preauth] Jan 7 01:27:53 prd-ubuntu1804-docker-4c-4g-2640 sshd[1497]: Invalid user jenkins from 10.32.4.5 port 43148 Jan 7 01:27:53 prd-ubuntu1804-docker-4c-4g-2640 sshd[1497]: Received disconnect from 10.32.4.5 port 43148:11: Closed due to user request. [preauth] Jan 7 01:27:53 prd-ubuntu1804-docker-4c-4g-2640 sshd[1497]: Disconnected from invalid user jenkins 10.32.4.5 port 43148 [preauth] Jan 7 01:27:56 prd-ubuntu1804-docker-4c-4g-2640 sshd[1514]: Invalid user jenkins from 10.32.4.5 port 43150 Jan 7 01:27:56 prd-ubuntu1804-docker-4c-4g-2640 sshd[1514]: Received disconnect from 10.32.4.5 port 43150:11: Closed due to user request. [preauth] Jan 7 01:27:56 prd-ubuntu1804-docker-4c-4g-2640 sshd[1514]: Disconnected from invalid user jenkins 10.32.4.5 port 43150 [preauth] Jan 7 01:27:58 prd-ubuntu1804-docker-4c-4g-2640 sshd[1516]: Invalid user jenkins from 10.32.4.5 port 43154 Jan 7 01:27:58 prd-ubuntu1804-docker-4c-4g-2640 sshd[1516]: Received disconnect from 10.32.4.5 port 43154:11: Closed due to user request. [preauth] Jan 7 01:27:58 prd-ubuntu1804-docker-4c-4g-2640 sshd[1516]: Disconnected from invalid user jenkins 10.32.4.5 port 43154 [preauth] Jan 7 01:28:00 prd-ubuntu1804-docker-4c-4g-2640 sshd[1518]: Invalid user jenkins from 10.32.4.5 port 43162 Jan 7 01:28:00 prd-ubuntu1804-docker-4c-4g-2640 sshd[1518]: Received disconnect from 10.32.4.5 port 43162:11: Closed due to user request. [preauth] Jan 7 01:28:00 prd-ubuntu1804-docker-4c-4g-2640 sshd[1518]: Disconnected from invalid user jenkins 10.32.4.5 port 43162 [preauth] Jan 7 01:28:01 prd-ubuntu1804-docker-4c-4g-2640 CRON[1520]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 7 01:28:01 prd-ubuntu1804-docker-4c-4g-2640 CRON[1520]: pam_unix(cron:session): session closed for user root Jan 7 01:28:02 prd-ubuntu1804-docker-4c-4g-2640 sshd[1528]: Invalid user jenkins from 10.32.4.5 port 43164 Jan 7 01:28:02 prd-ubuntu1804-docker-4c-4g-2640 sshd[1528]: Received disconnect from 10.32.4.5 port 43164:11: Closed due to user request. [preauth] Jan 7 01:28:02 prd-ubuntu1804-docker-4c-4g-2640 sshd[1528]: Disconnected from invalid user jenkins 10.32.4.5 port 43164 [preauth] Jan 7 01:28:04 prd-ubuntu1804-docker-4c-4g-2640 sshd[1530]: Invalid user jenkins from 10.32.4.5 port 43166 Jan 7 01:28:04 prd-ubuntu1804-docker-4c-4g-2640 sshd[1530]: Received disconnect from 10.32.4.5 port 43166:11: Closed due to user request. [preauth] Jan 7 01:28:04 prd-ubuntu1804-docker-4c-4g-2640 sshd[1530]: Disconnected from invalid user jenkins 10.32.4.5 port 43166 [preauth] Jan 7 01:28:06 prd-ubuntu1804-docker-4c-4g-2640 sshd[1532]: Invalid user jenkins from 10.32.4.5 port 43172 Jan 7 01:28:06 prd-ubuntu1804-docker-4c-4g-2640 sshd[1532]: Received disconnect from 10.32.4.5 port 43172:11: Closed due to user request. [preauth] Jan 7 01:28:06 prd-ubuntu1804-docker-4c-4g-2640 sshd[1532]: Disconnected from invalid user jenkins 10.32.4.5 port 43172 [preauth] Jan 7 01:28:08 prd-ubuntu1804-docker-4c-4g-2640 sshd[1534]: Invalid user jenkins from 10.32.4.5 port 43176 Jan 7 01:28:08 prd-ubuntu1804-docker-4c-4g-2640 sshd[1534]: Received disconnect from 10.32.4.5 port 43176:11: Closed due to user request. [preauth] Jan 7 01:28:08 prd-ubuntu1804-docker-4c-4g-2640 sshd[1534]: Disconnected from invalid user jenkins 10.32.4.5 port 43176 [preauth] Jan 7 01:28:11 prd-ubuntu1804-docker-4c-4g-2640 sshd[1736]: Invalid user jenkins from 10.32.4.5 port 43178 Jan 7 01:28:11 prd-ubuntu1804-docker-4c-4g-2640 sshd[1736]: Received disconnect from 10.32.4.5 port 43178:11: Closed due to user request. [preauth] Jan 7 01:28:11 prd-ubuntu1804-docker-4c-4g-2640 sshd[1736]: Disconnected from invalid user jenkins 10.32.4.5 port 43178 [preauth] Jan 7 01:28:13 prd-ubuntu1804-docker-4c-4g-2640 sshd[1801]: Invalid user jenkins from 10.32.4.5 port 43182 Jan 7 01:28:13 prd-ubuntu1804-docker-4c-4g-2640 sshd[1801]: Received disconnect from 10.32.4.5 port 43182:11: Closed due to user request. [preauth] Jan 7 01:28:13 prd-ubuntu1804-docker-4c-4g-2640 sshd[1801]: Disconnected from invalid user jenkins 10.32.4.5 port 43182 [preauth] Jan 7 01:28:15 prd-ubuntu1804-docker-4c-4g-2640 sshd[1827]: Invalid user jenkins from 10.32.4.5 port 43184 Jan 7 01:28:16 prd-ubuntu1804-docker-4c-4g-2640 sshd[1827]: Received disconnect from 10.32.4.5 port 43184:11: Closed due to user request. [preauth] Jan 7 01:28:16 prd-ubuntu1804-docker-4c-4g-2640 sshd[1827]: Disconnected from invalid user jenkins 10.32.4.5 port 43184 [preauth] Jan 7 01:28:18 prd-ubuntu1804-docker-4c-4g-2640 sshd[1837]: Invalid user jenkins from 10.32.4.5 port 43186 Jan 7 01:28:18 prd-ubuntu1804-docker-4c-4g-2640 sshd[1837]: Received disconnect from 10.32.4.5 port 43186:11: Closed due to user request. [preauth] Jan 7 01:28:18 prd-ubuntu1804-docker-4c-4g-2640 sshd[1837]: Disconnected from invalid user jenkins 10.32.4.5 port 43186 [preauth] Jan 7 01:28:18 prd-ubuntu1804-docker-4c-4g-2640 useradd[1847]: new group: name=jenkins, GID=1001 Jan 7 01:28:18 prd-ubuntu1804-docker-4c-4g-2640 useradd[1847]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Jan 7 01:28:18 prd-ubuntu1804-docker-4c-4g-2640 usermod[1854]: add 'jenkins' to group 'docker' Jan 7 01:28:18 prd-ubuntu1804-docker-4c-4g-2640 usermod[1854]: add 'jenkins' to shadow group 'docker' Jan 7 01:28:20 prd-ubuntu1804-docker-4c-4g-2640 sshd[1904]: Accepted publickey for jenkins from 10.32.4.5 port 43188 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Jan 7 01:28:20 prd-ubuntu1804-docker-4c-4g-2640 sshd[1904]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jan 7 01:28:20 prd-ubuntu1804-docker-4c-4g-2640 systemd-logind[1016]: New session 2 of user jenkins. Jan 7 01:28:20 prd-ubuntu1804-docker-4c-4g-2640 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jan 7 01:29:02 prd-ubuntu1804-docker-4c-4g-2640 CRON[2434]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 7 01:29:02 prd-ubuntu1804-docker-4c-4g-2640 CRON[2434]: pam_unix(cron:session): session closed for user root Jan 7 01:30:01 prd-ubuntu1804-docker-4c-4g-2640 CRON[2469]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 7 01:30:01 prd-ubuntu1804-docker-4c-4g-2640 CRON[2469]: pam_unix(cron:session): session closed for user root Jan 7 01:31:01 prd-ubuntu1804-docker-4c-4g-2640 CRON[3402]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 7 01:31:01 prd-ubuntu1804-docker-4c-4g-2640 CRON[3402]: pam_unix(cron:session): session closed for user root Jan 7 01:32:01 prd-ubuntu1804-docker-4c-4g-2640 CRON[3997]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 7 01:32:01 prd-ubuntu1804-docker-4c-4g-2640 CRON[3997]: pam_unix(cron:session): session closed for user root Jan 7 01:32:01 prd-ubuntu1804-docker-4c-4g-2640 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/nonrtric-plt-sme-servicemanager-docker-merge-k-release ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Jan 7 01:32:01 prd-ubuntu1804-docker-4c-4g-2640 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)