Jan 24 17:53:43 prd-ubuntu1804-docker-4c-4g-2680 passwd[939]: password for 'ubuntu' changed by 'root' Jan 24 17:53:43 prd-ubuntu1804-docker-4c-4g-2680 systemd-logind[1002]: Watching system buttons on /dev/input/event0 (Power Button) Jan 24 17:53:43 prd-ubuntu1804-docker-4c-4g-2680 systemd-logind[1002]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jan 24 17:53:43 prd-ubuntu1804-docker-4c-4g-2680 systemd-logind[1002]: New seat seat0. Jan 24 17:53:43 prd-ubuntu1804-docker-4c-4g-2680 sshd[1090]: Server listening on 0.0.0.0 port 22. Jan 24 17:53:43 prd-ubuntu1804-docker-4c-4g-2680 sshd[1090]: Server listening on :: port 22. Jan 24 17:53:47 prd-ubuntu1804-docker-4c-4g-2680 sshd[1481]: Did not receive identification string from 10.32.4.5 port 41686 Jan 24 17:53:48 prd-ubuntu1804-docker-4c-4g-2680 sshd[1506]: Invalid user jenkins from 10.32.4.5 port 41688 Jan 24 17:53:48 prd-ubuntu1804-docker-4c-4g-2680 sshd[1506]: Received disconnect from 10.32.4.5 port 41688:11: Closed due to user request. [preauth] Jan 24 17:53:48 prd-ubuntu1804-docker-4c-4g-2680 sshd[1506]: Disconnected from invalid user jenkins 10.32.4.5 port 41688 [preauth] Jan 24 17:53:50 prd-ubuntu1804-docker-4c-4g-2680 sshd[1525]: Invalid user jenkins from 10.32.4.5 port 41690 Jan 24 17:53:50 prd-ubuntu1804-docker-4c-4g-2680 sshd[1525]: Received disconnect from 10.32.4.5 port 41690:11: Closed due to user request. [preauth] Jan 24 17:53:50 prd-ubuntu1804-docker-4c-4g-2680 sshd[1525]: Disconnected from invalid user jenkins 10.32.4.5 port 41690 [preauth] Jan 24 17:53:52 prd-ubuntu1804-docker-4c-4g-2680 sshd[1527]: Invalid user jenkins from 10.32.4.5 port 41698 Jan 24 17:53:52 prd-ubuntu1804-docker-4c-4g-2680 sshd[1527]: Received disconnect from 10.32.4.5 port 41698:11: Closed due to user request. [preauth] Jan 24 17:53:52 prd-ubuntu1804-docker-4c-4g-2680 sshd[1527]: Disconnected from invalid user jenkins 10.32.4.5 port 41698 [preauth] Jan 24 17:53:54 prd-ubuntu1804-docker-4c-4g-2680 sshd[1529]: Invalid user jenkins from 10.32.4.5 port 41700 Jan 24 17:53:54 prd-ubuntu1804-docker-4c-4g-2680 sshd[1529]: Received disconnect from 10.32.4.5 port 41700:11: Closed due to user request. [preauth] Jan 24 17:53:54 prd-ubuntu1804-docker-4c-4g-2680 sshd[1529]: Disconnected from invalid user jenkins 10.32.4.5 port 41700 [preauth] Jan 24 17:53:57 prd-ubuntu1804-docker-4c-4g-2680 sshd[1531]: Invalid user jenkins from 10.32.4.5 port 41702 Jan 24 17:53:57 prd-ubuntu1804-docker-4c-4g-2680 sshd[1531]: Received disconnect from 10.32.4.5 port 41702:11: Closed due to user request. [preauth] Jan 24 17:53:57 prd-ubuntu1804-docker-4c-4g-2680 sshd[1531]: Disconnected from invalid user jenkins 10.32.4.5 port 41702 [preauth] Jan 24 17:53:59 prd-ubuntu1804-docker-4c-4g-2680 sshd[1533]: Invalid user jenkins from 10.32.4.5 port 41706 Jan 24 17:53:59 prd-ubuntu1804-docker-4c-4g-2680 sshd[1533]: Received disconnect from 10.32.4.5 port 41706:11: Closed due to user request. [preauth] Jan 24 17:53:59 prd-ubuntu1804-docker-4c-4g-2680 sshd[1533]: Disconnected from invalid user jenkins 10.32.4.5 port 41706 [preauth] Jan 24 17:54:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[1537]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 24 17:54:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[1537]: pam_unix(cron:session): session closed for user root Jan 24 17:54:01 prd-ubuntu1804-docker-4c-4g-2680 sshd[1535]: Invalid user jenkins from 10.32.4.5 port 41710 Jan 24 17:54:01 prd-ubuntu1804-docker-4c-4g-2680 sshd[1535]: Received disconnect from 10.32.4.5 port 41710:11: Closed due to user request. [preauth] Jan 24 17:54:01 prd-ubuntu1804-docker-4c-4g-2680 sshd[1535]: Disconnected from invalid user jenkins 10.32.4.5 port 41710 [preauth] Jan 24 17:54:03 prd-ubuntu1804-docker-4c-4g-2680 sshd[1566]: Invalid user jenkins from 10.32.4.5 port 41712 Jan 24 17:54:03 prd-ubuntu1804-docker-4c-4g-2680 sshd[1566]: Received disconnect from 10.32.4.5 port 41712:11: Closed due to user request. [preauth] Jan 24 17:54:03 prd-ubuntu1804-docker-4c-4g-2680 sshd[1566]: Disconnected from invalid user jenkins 10.32.4.5 port 41712 [preauth] Jan 24 17:54:05 prd-ubuntu1804-docker-4c-4g-2680 sshd[1649]: Invalid user jenkins from 10.32.4.5 port 41714 Jan 24 17:54:05 prd-ubuntu1804-docker-4c-4g-2680 sshd[1649]: Received disconnect from 10.32.4.5 port 41714:11: Closed due to user request. [preauth] Jan 24 17:54:05 prd-ubuntu1804-docker-4c-4g-2680 sshd[1649]: Disconnected from invalid user jenkins 10.32.4.5 port 41714 [preauth] Jan 24 17:54:07 prd-ubuntu1804-docker-4c-4g-2680 sshd[1812]: Invalid user jenkins from 10.32.4.5 port 41716 Jan 24 17:54:07 prd-ubuntu1804-docker-4c-4g-2680 sshd[1812]: Received disconnect from 10.32.4.5 port 41716:11: Closed due to user request. [preauth] Jan 24 17:54:07 prd-ubuntu1804-docker-4c-4g-2680 sshd[1812]: Disconnected from invalid user jenkins 10.32.4.5 port 41716 [preauth] Jan 24 17:54:09 prd-ubuntu1804-docker-4c-4g-2680 sshd[1846]: Invalid user jenkins from 10.32.4.5 port 41718 Jan 24 17:54:09 prd-ubuntu1804-docker-4c-4g-2680 sshd[1846]: Received disconnect from 10.32.4.5 port 41718:11: Closed due to user request. [preauth] Jan 24 17:54:09 prd-ubuntu1804-docker-4c-4g-2680 sshd[1846]: Disconnected from invalid user jenkins 10.32.4.5 port 41718 [preauth] Jan 24 17:54:11 prd-ubuntu1804-docker-4c-4g-2680 useradd[1864]: new group: name=jenkins, GID=1001 Jan 24 17:54:11 prd-ubuntu1804-docker-4c-4g-2680 useradd[1864]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Jan 24 17:54:11 prd-ubuntu1804-docker-4c-4g-2680 usermod[1871]: add 'jenkins' to group 'docker' Jan 24 17:54:11 prd-ubuntu1804-docker-4c-4g-2680 usermod[1871]: add 'jenkins' to shadow group 'docker' Jan 24 17:54:11 prd-ubuntu1804-docker-4c-4g-2680 sshd[1905]: Accepted publickey for jenkins from 10.32.4.5 port 41720 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Jan 24 17:54:11 prd-ubuntu1804-docker-4c-4g-2680 sshd[1905]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jan 24 17:54:11 prd-ubuntu1804-docker-4c-4g-2680 systemd-logind[1002]: New session 2 of user jenkins. Jan 24 17:54:11 prd-ubuntu1804-docker-4c-4g-2680 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jan 24 17:55:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[2465]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 24 17:55:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[2465]: pam_unix(cron:session): session closed for user root Jan 24 17:56:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[2946]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 24 17:56:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[2946]: pam_unix(cron:session): session closed for user root Jan 24 17:57:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[16466]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 24 17:57:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[16466]: pam_unix(cron:session): session closed for user root Jan 24 17:58:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[20395]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 24 17:58:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[20395]: pam_unix(cron:session): session closed for user root Jan 24 17:59:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[27900]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 24 17:59:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[27900]: pam_unix(cron:session): session closed for user root Jan 24 18:00:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[2223]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 24 18:00:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[2223]: pam_unix(cron:session): session closed for user root Jan 24 18:01:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[2609]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 24 18:01:01 prd-ubuntu1804-docker-4c-4g-2680 CRON[2609]: pam_unix(cron:session): session closed for user root Jan 24 18:01:01 prd-ubuntu1804-docker-4c-4g-2680 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/o-du-l2-docker-merge-sch_slice_based ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Jan 24 18:01:01 prd-ubuntu1804-docker-4c-4g-2680 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)