May 23 10:59:45 prd-ubuntu1804-docker-4c-4g-1470 passwd[928]: password for 'ubuntu' changed by 'root' May 23 10:59:45 prd-ubuntu1804-docker-4c-4g-1470 systemd-logind[1089]: Watching system buttons on /dev/input/event0 (Power Button) May 23 10:59:45 prd-ubuntu1804-docker-4c-4g-1470 systemd-logind[1089]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) May 23 10:59:45 prd-ubuntu1804-docker-4c-4g-1470 systemd-logind[1089]: New seat seat0. May 23 10:59:46 prd-ubuntu1804-docker-4c-4g-1470 sshd[1241]: Server listening on 0.0.0.0 port 22. May 23 10:59:46 prd-ubuntu1804-docker-4c-4g-1470 sshd[1241]: Server listening on :: port 22. May 23 10:59:48 prd-ubuntu1804-docker-4c-4g-1470 sshd[1430]: Did not receive identification string from 10.32.4.5 port 45552 May 23 10:59:55 prd-ubuntu1804-docker-4c-4g-1470 sshd[1488]: Invalid user jenkins from 10.32.4.5 port 45556 May 23 10:59:55 prd-ubuntu1804-docker-4c-4g-1470 sshd[1488]: Received disconnect from 10.32.4.5 port 45556:11: Closed due to user request. [preauth] May 23 10:59:55 prd-ubuntu1804-docker-4c-4g-1470 sshd[1488]: Disconnected from invalid user jenkins 10.32.4.5 port 45556 [preauth] May 23 10:59:57 prd-ubuntu1804-docker-4c-4g-1470 sshd[1492]: Invalid user jenkins from 10.32.4.5 port 45560 May 23 10:59:57 prd-ubuntu1804-docker-4c-4g-1470 sshd[1492]: Received disconnect from 10.32.4.5 port 45560:11: Closed due to user request. [preauth] May 23 10:59:57 prd-ubuntu1804-docker-4c-4g-1470 sshd[1492]: Disconnected from invalid user jenkins 10.32.4.5 port 45560 [preauth] May 23 10:59:59 prd-ubuntu1804-docker-4c-4g-1470 sshd[1494]: Invalid user jenkins from 10.32.4.5 port 45562 May 23 10:59:59 prd-ubuntu1804-docker-4c-4g-1470 sshd[1494]: Received disconnect from 10.32.4.5 port 45562:11: Closed due to user request. [preauth] May 23 10:59:59 prd-ubuntu1804-docker-4c-4g-1470 sshd[1494]: Disconnected from invalid user jenkins 10.32.4.5 port 45562 [preauth] May 23 11:00:01 prd-ubuntu1804-docker-4c-4g-1470 CRON[1514]: pam_unix(cron:session): session opened for user root by (uid=0) May 23 11:00:01 prd-ubuntu1804-docker-4c-4g-1470 CRON[1514]: pam_unix(cron:session): session closed for user root May 23 11:00:01 prd-ubuntu1804-docker-4c-4g-1470 sshd[1522]: Invalid user jenkins from 10.32.4.5 port 45570 May 23 11:00:01 prd-ubuntu1804-docker-4c-4g-1470 sshd[1522]: Received disconnect from 10.32.4.5 port 45570:11: Closed due to user request. [preauth] May 23 11:00:01 prd-ubuntu1804-docker-4c-4g-1470 sshd[1522]: Disconnected from invalid user jenkins 10.32.4.5 port 45570 [preauth] May 23 11:00:03 prd-ubuntu1804-docker-4c-4g-1470 sshd[1524]: Invalid user jenkins from 10.32.4.5 port 45598 May 23 11:00:03 prd-ubuntu1804-docker-4c-4g-1470 sshd[1524]: Received disconnect from 10.32.4.5 port 45598:11: Closed due to user request. [preauth] May 23 11:00:03 prd-ubuntu1804-docker-4c-4g-1470 sshd[1524]: Disconnected from invalid user jenkins 10.32.4.5 port 45598 [preauth] May 23 11:00:06 prd-ubuntu1804-docker-4c-4g-1470 sshd[1526]: Invalid user jenkins from 10.32.4.5 port 45600 May 23 11:00:06 prd-ubuntu1804-docker-4c-4g-1470 sshd[1526]: Received disconnect from 10.32.4.5 port 45600:11: Closed due to user request. [preauth] May 23 11:00:06 prd-ubuntu1804-docker-4c-4g-1470 sshd[1526]: Disconnected from invalid user jenkins 10.32.4.5 port 45600 [preauth] May 23 11:00:08 prd-ubuntu1804-docker-4c-4g-1470 sshd[1657]: Invalid user jenkins from 10.32.4.5 port 45602 May 23 11:00:08 prd-ubuntu1804-docker-4c-4g-1470 sshd[1657]: Received disconnect from 10.32.4.5 port 45602:11: Closed due to user request. [preauth] May 23 11:00:08 prd-ubuntu1804-docker-4c-4g-1470 sshd[1657]: Disconnected from invalid user jenkins 10.32.4.5 port 45602 [preauth] May 23 11:00:10 prd-ubuntu1804-docker-4c-4g-1470 sshd[1775]: Invalid user jenkins from 10.32.4.5 port 45604 May 23 11:00:10 prd-ubuntu1804-docker-4c-4g-1470 sshd[1775]: Received disconnect from 10.32.4.5 port 45604:11: Closed due to user request. [preauth] May 23 11:00:10 prd-ubuntu1804-docker-4c-4g-1470 sshd[1775]: Disconnected from invalid user jenkins 10.32.4.5 port 45604 [preauth] May 23 11:00:12 prd-ubuntu1804-docker-4c-4g-1470 sshd[1808]: Invalid user jenkins from 10.32.4.5 port 45612 May 23 11:00:12 prd-ubuntu1804-docker-4c-4g-1470 sshd[1808]: Received disconnect from 10.32.4.5 port 45612:11: Closed due to user request. [preauth] May 23 11:00:12 prd-ubuntu1804-docker-4c-4g-1470 sshd[1808]: Disconnected from invalid user jenkins 10.32.4.5 port 45612 [preauth] May 23 11:00:13 prd-ubuntu1804-docker-4c-4g-1470 useradd[1826]: new group: name=jenkins, GID=1001 May 23 11:00:13 prd-ubuntu1804-docker-4c-4g-1470 useradd[1826]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash May 23 11:00:14 prd-ubuntu1804-docker-4c-4g-1470 usermod[1833]: add 'jenkins' to group 'docker' May 23 11:00:14 prd-ubuntu1804-docker-4c-4g-1470 usermod[1833]: add 'jenkins' to shadow group 'docker' May 23 11:00:14 prd-ubuntu1804-docker-4c-4g-1470 sshd[1874]: Accepted publickey for jenkins from 10.32.4.5 port 45614 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI May 23 11:00:14 prd-ubuntu1804-docker-4c-4g-1470 sshd[1874]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) May 23 11:00:14 prd-ubuntu1804-docker-4c-4g-1470 systemd-logind[1089]: New session 2 of user jenkins. May 23 11:00:14 prd-ubuntu1804-docker-4c-4g-1470 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) May 23 11:01:01 prd-ubuntu1804-docker-4c-4g-1470 CRON[2425]: pam_unix(cron:session): session opened for user root by (uid=0) May 23 11:01:01 prd-ubuntu1804-docker-4c-4g-1470 CRON[2425]: pam_unix(cron:session): session closed for user root May 23 11:02:01 prd-ubuntu1804-docker-4c-4g-1470 CRON[3294]: pam_unix(cron:session): session opened for user root by (uid=0) May 23 11:02:01 prd-ubuntu1804-docker-4c-4g-1470 CRON[3294]: pam_unix(cron:session): session closed for user root May 23 11:02:23 prd-ubuntu1804-docker-4c-4g-1470 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/nonrtric-rapp-ransliceassurance-docker-merge-g-release ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp May 23 11:02:23 prd-ubuntu1804-docker-4c-4g-1470 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)