May 24 17:53:45 prd-ubuntu1804-docker-4c-4g-1768 passwd[923]: password for 'ubuntu' changed by 'root' May 24 17:53:45 prd-ubuntu1804-docker-4c-4g-1768 systemd-logind[970]: Watching system buttons on /dev/input/event0 (Power Button) May 24 17:53:45 prd-ubuntu1804-docker-4c-4g-1768 systemd-logind[970]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) May 24 17:53:45 prd-ubuntu1804-docker-4c-4g-1768 systemd-logind[970]: New seat seat0. May 24 17:53:45 prd-ubuntu1804-docker-4c-4g-1768 sshd[1039]: Server listening on 0.0.0.0 port 22. May 24 17:53:45 prd-ubuntu1804-docker-4c-4g-1768 sshd[1039]: Server listening on :: port 22. May 24 17:53:48 prd-ubuntu1804-docker-4c-4g-1768 sshd[1414]: Did not receive identification string from 10.32.4.5 port 33588 May 24 17:53:51 prd-ubuntu1804-docker-4c-4g-1768 sshd[1456]: Invalid user jenkins from 10.32.4.5 port 33596 May 24 17:53:51 prd-ubuntu1804-docker-4c-4g-1768 sshd[1456]: Received disconnect from 10.32.4.5 port 33596:11: Closed due to user request. [preauth] May 24 17:53:51 prd-ubuntu1804-docker-4c-4g-1768 sshd[1456]: Disconnected from invalid user jenkins 10.32.4.5 port 33596 [preauth] May 24 17:53:53 prd-ubuntu1804-docker-4c-4g-1768 sshd[1475]: Invalid user jenkins from 10.32.4.5 port 33598 May 24 17:53:53 prd-ubuntu1804-docker-4c-4g-1768 sshd[1475]: Received disconnect from 10.32.4.5 port 33598:11: Closed due to user request. [preauth] May 24 17:53:53 prd-ubuntu1804-docker-4c-4g-1768 sshd[1475]: Disconnected from invalid user jenkins 10.32.4.5 port 33598 [preauth] May 24 17:53:55 prd-ubuntu1804-docker-4c-4g-1768 sshd[1477]: Invalid user jenkins from 10.32.4.5 port 33600 May 24 17:53:55 prd-ubuntu1804-docker-4c-4g-1768 sshd[1477]: Received disconnect from 10.32.4.5 port 33600:11: Closed due to user request. [preauth] May 24 17:53:55 prd-ubuntu1804-docker-4c-4g-1768 sshd[1477]: Disconnected from invalid user jenkins 10.32.4.5 port 33600 [preauth] May 24 17:53:57 prd-ubuntu1804-docker-4c-4g-1768 sshd[1479]: Invalid user jenkins from 10.32.4.5 port 33602 May 24 17:53:57 prd-ubuntu1804-docker-4c-4g-1768 sshd[1479]: Received disconnect from 10.32.4.5 port 33602:11: Closed due to user request. [preauth] May 24 17:53:57 prd-ubuntu1804-docker-4c-4g-1768 sshd[1479]: Disconnected from invalid user jenkins 10.32.4.5 port 33602 [preauth] May 24 17:53:59 prd-ubuntu1804-docker-4c-4g-1768 sshd[1481]: Invalid user jenkins from 10.32.4.5 port 33606 May 24 17:53:59 prd-ubuntu1804-docker-4c-4g-1768 sshd[1481]: Received disconnect from 10.32.4.5 port 33606:11: Closed due to user request. [preauth] May 24 17:53:59 prd-ubuntu1804-docker-4c-4g-1768 sshd[1481]: Disconnected from invalid user jenkins 10.32.4.5 port 33606 [preauth] May 24 17:54:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[1502]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 17:54:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[1502]: pam_unix(cron:session): session closed for user root May 24 17:54:01 prd-ubuntu1804-docker-4c-4g-1768 sshd[1511]: Invalid user jenkins from 10.32.4.5 port 33608 May 24 17:54:01 prd-ubuntu1804-docker-4c-4g-1768 sshd[1511]: Received disconnect from 10.32.4.5 port 33608:11: Closed due to user request. [preauth] May 24 17:54:01 prd-ubuntu1804-docker-4c-4g-1768 sshd[1511]: Disconnected from invalid user jenkins 10.32.4.5 port 33608 [preauth] May 24 17:54:03 prd-ubuntu1804-docker-4c-4g-1768 sshd[1513]: Invalid user jenkins from 10.32.4.5 port 33610 May 24 17:54:03 prd-ubuntu1804-docker-4c-4g-1768 sshd[1513]: Received disconnect from 10.32.4.5 port 33610:11: Closed due to user request. [preauth] May 24 17:54:03 prd-ubuntu1804-docker-4c-4g-1768 sshd[1513]: Disconnected from invalid user jenkins 10.32.4.5 port 33610 [preauth] May 24 17:54:05 prd-ubuntu1804-docker-4c-4g-1768 sshd[1515]: Invalid user jenkins from 10.32.4.5 port 33612 May 24 17:54:05 prd-ubuntu1804-docker-4c-4g-1768 sshd[1515]: Received disconnect from 10.32.4.5 port 33612:11: Closed due to user request. [preauth] May 24 17:54:05 prd-ubuntu1804-docker-4c-4g-1768 sshd[1515]: Disconnected from invalid user jenkins 10.32.4.5 port 33612 [preauth] May 24 17:54:08 prd-ubuntu1804-docker-4c-4g-1768 sshd[1682]: Invalid user jenkins from 10.32.4.5 port 33614 May 24 17:54:08 prd-ubuntu1804-docker-4c-4g-1768 sshd[1682]: Received disconnect from 10.32.4.5 port 33614:11: Closed due to user request. [preauth] May 24 17:54:08 prd-ubuntu1804-docker-4c-4g-1768 sshd[1682]: Disconnected from invalid user jenkins 10.32.4.5 port 33614 [preauth] May 24 17:54:10 prd-ubuntu1804-docker-4c-4g-1768 sshd[1780]: Invalid user jenkins from 10.32.4.5 port 33618 May 24 17:54:10 prd-ubuntu1804-docker-4c-4g-1768 sshd[1780]: Received disconnect from 10.32.4.5 port 33618:11: Closed due to user request. [preauth] May 24 17:54:10 prd-ubuntu1804-docker-4c-4g-1768 sshd[1780]: Disconnected from invalid user jenkins 10.32.4.5 port 33618 [preauth] May 24 17:54:12 prd-ubuntu1804-docker-4c-4g-1768 sshd[1799]: Invalid user jenkins from 10.32.4.5 port 33620 May 24 17:54:12 prd-ubuntu1804-docker-4c-4g-1768 sshd[1799]: Received disconnect from 10.32.4.5 port 33620:11: Closed due to user request. [preauth] May 24 17:54:12 prd-ubuntu1804-docker-4c-4g-1768 sshd[1799]: Disconnected from invalid user jenkins 10.32.4.5 port 33620 [preauth] May 24 17:54:14 prd-ubuntu1804-docker-4c-4g-1768 useradd[1817]: new group: name=jenkins, GID=1001 May 24 17:54:14 prd-ubuntu1804-docker-4c-4g-1768 useradd[1817]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash May 24 17:54:14 prd-ubuntu1804-docker-4c-4g-1768 usermod[1824]: add 'jenkins' to group 'docker' May 24 17:54:14 prd-ubuntu1804-docker-4c-4g-1768 usermod[1824]: add 'jenkins' to shadow group 'docker' May 24 17:54:14 prd-ubuntu1804-docker-4c-4g-1768 sshd[1865]: Accepted publickey for jenkins from 10.32.4.5 port 33624 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI May 24 17:54:14 prd-ubuntu1804-docker-4c-4g-1768 sshd[1865]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) May 24 17:54:14 prd-ubuntu1804-docker-4c-4g-1768 systemd-logind[970]: New session 2 of user jenkins. May 24 17:54:14 prd-ubuntu1804-docker-4c-4g-1768 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) May 24 17:55:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[2492]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 17:55:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[2492]: pam_unix(cron:session): session closed for user root May 24 17:56:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[3077]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 17:56:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[3077]: pam_unix(cron:session): session closed for user root May 24 17:57:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[15672]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 17:57:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[15672]: pam_unix(cron:session): session closed for user root May 24 17:58:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[18622]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 17:58:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[18622]: pam_unix(cron:session): session closed for user root May 24 17:59:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[26089]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 17:59:02 prd-ubuntu1804-docker-4c-4g-1768 CRON[26089]: pam_unix(cron:session): session closed for user root May 24 18:00:02 prd-ubuntu1804-docker-4c-4g-1768 CRON[2440]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 18:00:02 prd-ubuntu1804-docker-4c-4g-1768 CRON[2440]: pam_unix(cron:session): session closed for user root May 24 18:01:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[2655]: pam_unix(cron:session): session opened for user root by (uid=0) May 24 18:01:01 prd-ubuntu1804-docker-4c-4g-1768 CRON[2655]: pam_unix(cron:session): session closed for user root May 24 18:01:16 prd-ubuntu1804-docker-4c-4g-1768 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/o-du-l2-docker-merge-sch_slice_based ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp May 24 18:01:16 prd-ubuntu1804-docker-4c-4g-1768 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)