May 7 08:44:43 prd-ubuntu1804-docker-4c-4g-448 passwd[924]: password for 'ubuntu' changed by 'root' May 7 08:44:43 prd-ubuntu1804-docker-4c-4g-448 systemd-logind[973]: Watching system buttons on /dev/input/event0 (Power Button) May 7 08:44:43 prd-ubuntu1804-docker-4c-4g-448 systemd-logind[973]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) May 7 08:44:43 prd-ubuntu1804-docker-4c-4g-448 systemd-logind[973]: New seat seat0. May 7 08:44:43 prd-ubuntu1804-docker-4c-4g-448 sshd[1261]: Server listening on 0.0.0.0 port 22. May 7 08:44:43 prd-ubuntu1804-docker-4c-4g-448 sshd[1261]: Server listening on :: port 22. May 7 08:44:48 prd-ubuntu1804-docker-4c-4g-448 sshd[1507]: Did not receive identification string from 10.32.4.5 port 39688 May 7 08:44:55 prd-ubuntu1804-docker-4c-4g-448 sshd[1533]: Invalid user jenkins from 10.32.4.5 port 39690 May 7 08:44:55 prd-ubuntu1804-docker-4c-4g-448 sshd[1533]: Received disconnect from 10.32.4.5 port 39690:11: Closed due to user request. [preauth] May 7 08:44:55 prd-ubuntu1804-docker-4c-4g-448 sshd[1533]: Disconnected from invalid user jenkins 10.32.4.5 port 39690 [preauth] May 7 08:44:57 prd-ubuntu1804-docker-4c-4g-448 sshd[1537]: Invalid user jenkins from 10.32.4.5 port 39692 May 7 08:44:57 prd-ubuntu1804-docker-4c-4g-448 sshd[1537]: Received disconnect from 10.32.4.5 port 39692:11: Closed due to user request. [preauth] May 7 08:44:57 prd-ubuntu1804-docker-4c-4g-448 sshd[1537]: Disconnected from invalid user jenkins 10.32.4.5 port 39692 [preauth] May 7 08:44:59 prd-ubuntu1804-docker-4c-4g-448 sshd[1539]: Invalid user jenkins from 10.32.4.5 port 39694 May 7 08:44:59 prd-ubuntu1804-docker-4c-4g-448 sshd[1539]: Received disconnect from 10.32.4.5 port 39694:11: Closed due to user request. [preauth] May 7 08:44:59 prd-ubuntu1804-docker-4c-4g-448 sshd[1539]: Disconnected from invalid user jenkins 10.32.4.5 port 39694 [preauth] May 7 08:45:01 prd-ubuntu1804-docker-4c-4g-448 CRON[1541]: pam_unix(cron:session): session opened for user root by (uid=0) May 7 08:45:01 prd-ubuntu1804-docker-4c-4g-448 CRON[1541]: pam_unix(cron:session): session closed for user root May 7 08:45:01 prd-ubuntu1804-docker-4c-4g-448 sshd[1550]: Invalid user jenkins from 10.32.4.5 port 39704 May 7 08:45:01 prd-ubuntu1804-docker-4c-4g-448 sshd[1550]: Received disconnect from 10.32.4.5 port 39704:11: Closed due to user request. [preauth] May 7 08:45:01 prd-ubuntu1804-docker-4c-4g-448 sshd[1550]: Disconnected from invalid user jenkins 10.32.4.5 port 39704 [preauth] May 7 08:45:03 prd-ubuntu1804-docker-4c-4g-448 sshd[1552]: Invalid user jenkins from 10.32.4.5 port 39730 May 7 08:45:03 prd-ubuntu1804-docker-4c-4g-448 sshd[1552]: Received disconnect from 10.32.4.5 port 39730:11: Closed due to user request. [preauth] May 7 08:45:03 prd-ubuntu1804-docker-4c-4g-448 sshd[1552]: Disconnected from invalid user jenkins 10.32.4.5 port 39730 [preauth] May 7 08:45:05 prd-ubuntu1804-docker-4c-4g-448 sshd[1564]: Invalid user jenkins from 10.32.4.5 port 39732 May 7 08:45:05 prd-ubuntu1804-docker-4c-4g-448 sshd[1564]: Received disconnect from 10.32.4.5 port 39732:11: Closed due to user request. [preauth] May 7 08:45:05 prd-ubuntu1804-docker-4c-4g-448 sshd[1564]: Disconnected from invalid user jenkins 10.32.4.5 port 39732 [preauth] May 7 08:45:08 prd-ubuntu1804-docker-4c-4g-448 sshd[1794]: Invalid user jenkins from 10.32.4.5 port 39734 May 7 08:45:08 prd-ubuntu1804-docker-4c-4g-448 sshd[1794]: Received disconnect from 10.32.4.5 port 39734:11: Closed due to user request. [preauth] May 7 08:45:08 prd-ubuntu1804-docker-4c-4g-448 sshd[1794]: Disconnected from invalid user jenkins 10.32.4.5 port 39734 [preauth] May 7 08:45:10 prd-ubuntu1804-docker-4c-4g-448 sshd[1834]: Invalid user jenkins from 10.32.4.5 port 39736 May 7 08:45:10 prd-ubuntu1804-docker-4c-4g-448 sshd[1834]: Received disconnect from 10.32.4.5 port 39736:11: Closed due to user request. [preauth] May 7 08:45:10 prd-ubuntu1804-docker-4c-4g-448 sshd[1834]: Disconnected from invalid user jenkins 10.32.4.5 port 39736 [preauth] May 7 08:45:12 prd-ubuntu1804-docker-4c-4g-448 sshd[1846]: Invalid user jenkins from 10.32.4.5 port 39744 May 7 08:45:12 prd-ubuntu1804-docker-4c-4g-448 sshd[1846]: Received disconnect from 10.32.4.5 port 39744:11: Closed due to user request. [preauth] May 7 08:45:12 prd-ubuntu1804-docker-4c-4g-448 sshd[1846]: Disconnected from invalid user jenkins 10.32.4.5 port 39744 [preauth] May 7 08:45:13 prd-ubuntu1804-docker-4c-4g-448 useradd[1854]: new group: name=jenkins, GID=1001 May 7 08:45:13 prd-ubuntu1804-docker-4c-4g-448 useradd[1854]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash May 7 08:45:13 prd-ubuntu1804-docker-4c-4g-448 usermod[1861]: add 'jenkins' to group 'docker' May 7 08:45:13 prd-ubuntu1804-docker-4c-4g-448 usermod[1861]: add 'jenkins' to shadow group 'docker' May 7 08:45:15 prd-ubuntu1804-docker-4c-4g-448 sshd[1895]: Accepted publickey for jenkins from 10.32.4.5 port 39752 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI May 7 08:45:15 prd-ubuntu1804-docker-4c-4g-448 sshd[1895]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) May 7 08:45:15 prd-ubuntu1804-docker-4c-4g-448 systemd-logind[973]: New session 2 of user jenkins. May 7 08:45:15 prd-ubuntu1804-docker-4c-4g-448 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) May 7 08:46:01 prd-ubuntu1804-docker-4c-4g-448 CRON[2471]: pam_unix(cron:session): session opened for user root by (uid=0) May 7 08:46:02 prd-ubuntu1804-docker-4c-4g-448 CRON[2471]: pam_unix(cron:session): session closed for user root May 7 08:47:02 prd-ubuntu1804-docker-4c-4g-448 CRON[3351]: pam_unix(cron:session): session opened for user root by (uid=0) May 7 08:47:02 prd-ubuntu1804-docker-4c-4g-448 CRON[3351]: pam_unix(cron:session): session closed for user root May 7 08:47:26 prd-ubuntu1804-docker-4c-4g-448 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/nonrtric-sample-helloworld-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp May 7 08:47:26 prd-ubuntu1804-docker-4c-4g-448 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)