May 28 03:10:43 prd-ubuntu1804-docker-4c-4g-2045 passwd[924]: password for 'ubuntu' changed by 'root' May 28 03:10:43 prd-ubuntu1804-docker-4c-4g-2045 systemd-logind[969]: Watching system buttons on /dev/input/event0 (Power Button) May 28 03:10:43 prd-ubuntu1804-docker-4c-4g-2045 systemd-logind[969]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) May 28 03:10:43 prd-ubuntu1804-docker-4c-4g-2045 systemd-logind[969]: New seat seat0. May 28 03:10:44 prd-ubuntu1804-docker-4c-4g-2045 sshd[1265]: Server listening on 0.0.0.0 port 22. May 28 03:10:44 prd-ubuntu1804-docker-4c-4g-2045 sshd[1265]: Server listening on :: port 22. May 28 03:10:47 prd-ubuntu1804-docker-4c-4g-2045 sshd[1479]: Did not receive identification string from 10.32.4.5 port 58920 May 28 03:10:51 prd-ubuntu1804-docker-4c-4g-2045 sshd[1541]: Invalid user jenkins from 10.32.4.5 port 58930 May 28 03:10:51 prd-ubuntu1804-docker-4c-4g-2045 sshd[1541]: Received disconnect from 10.32.4.5 port 58930:11: Closed due to user request. [preauth] May 28 03:10:51 prd-ubuntu1804-docker-4c-4g-2045 sshd[1541]: Disconnected from invalid user jenkins 10.32.4.5 port 58930 [preauth] May 28 03:10:53 prd-ubuntu1804-docker-4c-4g-2045 sshd[1548]: Invalid user jenkins from 10.32.4.5 port 58932 May 28 03:10:54 prd-ubuntu1804-docker-4c-4g-2045 sshd[1548]: Received disconnect from 10.32.4.5 port 58932:11: Closed due to user request. [preauth] May 28 03:10:54 prd-ubuntu1804-docker-4c-4g-2045 sshd[1548]: Disconnected from invalid user jenkins 10.32.4.5 port 58932 [preauth] May 28 03:10:56 prd-ubuntu1804-docker-4c-4g-2045 sshd[1550]: Invalid user jenkins from 10.32.4.5 port 58934 May 28 03:10:56 prd-ubuntu1804-docker-4c-4g-2045 sshd[1550]: Received disconnect from 10.32.4.5 port 58934:11: Closed due to user request. [preauth] May 28 03:10:56 prd-ubuntu1804-docker-4c-4g-2045 sshd[1550]: Disconnected from invalid user jenkins 10.32.4.5 port 58934 [preauth] May 28 03:10:58 prd-ubuntu1804-docker-4c-4g-2045 sshd[1552]: Invalid user jenkins from 10.32.4.5 port 58936 May 28 03:10:58 prd-ubuntu1804-docker-4c-4g-2045 sshd[1552]: Received disconnect from 10.32.4.5 port 58936:11: Closed due to user request. [preauth] May 28 03:10:58 prd-ubuntu1804-docker-4c-4g-2045 sshd[1552]: Disconnected from invalid user jenkins 10.32.4.5 port 58936 [preauth] May 28 03:11:00 prd-ubuntu1804-docker-4c-4g-2045 sshd[1554]: Invalid user jenkins from 10.32.4.5 port 58940 May 28 03:11:00 prd-ubuntu1804-docker-4c-4g-2045 sshd[1554]: Received disconnect from 10.32.4.5 port 58940:11: Closed due to user request. [preauth] May 28 03:11:00 prd-ubuntu1804-docker-4c-4g-2045 sshd[1554]: Disconnected from invalid user jenkins 10.32.4.5 port 58940 [preauth] May 28 03:11:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[1557]: pam_unix(cron:session): session opened for user root by (uid=0) May 28 03:11:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[1557]: pam_unix(cron:session): session closed for user root May 28 03:11:02 prd-ubuntu1804-docker-4c-4g-2045 sshd[1564]: Invalid user jenkins from 10.32.4.5 port 58942 May 28 03:11:02 prd-ubuntu1804-docker-4c-4g-2045 sshd[1564]: Received disconnect from 10.32.4.5 port 58942:11: Closed due to user request. [preauth] May 28 03:11:02 prd-ubuntu1804-docker-4c-4g-2045 sshd[1564]: Disconnected from invalid user jenkins 10.32.4.5 port 58942 [preauth] May 28 03:11:04 prd-ubuntu1804-docker-4c-4g-2045 sshd[1566]: Invalid user jenkins from 10.32.4.5 port 58944 May 28 03:11:04 prd-ubuntu1804-docker-4c-4g-2045 sshd[1566]: Received disconnect from 10.32.4.5 port 58944:11: Closed due to user request. [preauth] May 28 03:11:04 prd-ubuntu1804-docker-4c-4g-2045 sshd[1566]: Disconnected from invalid user jenkins 10.32.4.5 port 58944 [preauth] May 28 03:11:06 prd-ubuntu1804-docker-4c-4g-2045 sshd[1627]: Invalid user jenkins from 10.32.4.5 port 58946 May 28 03:11:06 prd-ubuntu1804-docker-4c-4g-2045 sshd[1627]: Received disconnect from 10.32.4.5 port 58946:11: Closed due to user request. [preauth] May 28 03:11:06 prd-ubuntu1804-docker-4c-4g-2045 sshd[1627]: Disconnected from invalid user jenkins 10.32.4.5 port 58946 [preauth] May 28 03:11:08 prd-ubuntu1804-docker-4c-4g-2045 sshd[1799]: Invalid user jenkins from 10.32.4.5 port 58948 May 28 03:11:08 prd-ubuntu1804-docker-4c-4g-2045 sshd[1799]: Received disconnect from 10.32.4.5 port 58948:11: Closed due to user request. [preauth] May 28 03:11:08 prd-ubuntu1804-docker-4c-4g-2045 sshd[1799]: Disconnected from invalid user jenkins 10.32.4.5 port 58948 [preauth] May 28 03:11:10 prd-ubuntu1804-docker-4c-4g-2045 sshd[1838]: Invalid user jenkins from 10.32.4.5 port 58950 May 28 03:11:10 prd-ubuntu1804-docker-4c-4g-2045 sshd[1838]: Received disconnect from 10.32.4.5 port 58950:11: Closed due to user request. [preauth] May 28 03:11:10 prd-ubuntu1804-docker-4c-4g-2045 sshd[1838]: Disconnected from invalid user jenkins 10.32.4.5 port 58950 [preauth] May 28 03:11:12 prd-ubuntu1804-docker-4c-4g-2045 sshd[1854]: Invalid user jenkins from 10.32.4.5 port 58952 May 28 03:11:12 prd-ubuntu1804-docker-4c-4g-2045 sshd[1854]: Received disconnect from 10.32.4.5 port 58952:11: Closed due to user request. [preauth] May 28 03:11:12 prd-ubuntu1804-docker-4c-4g-2045 sshd[1854]: Disconnected from invalid user jenkins 10.32.4.5 port 58952 [preauth] May 28 03:11:12 prd-ubuntu1804-docker-4c-4g-2045 useradd[1858]: new group: name=jenkins, GID=1001 May 28 03:11:12 prd-ubuntu1804-docker-4c-4g-2045 useradd[1858]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash May 28 03:11:13 prd-ubuntu1804-docker-4c-4g-2045 usermod[1865]: add 'jenkins' to group 'docker' May 28 03:11:13 prd-ubuntu1804-docker-4c-4g-2045 usermod[1865]: add 'jenkins' to shadow group 'docker' May 28 03:11:15 prd-ubuntu1804-docker-4c-4g-2045 sshd[1899]: Accepted publickey for jenkins from 10.32.4.5 port 58956 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI May 28 03:11:15 prd-ubuntu1804-docker-4c-4g-2045 sshd[1899]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) May 28 03:11:15 prd-ubuntu1804-docker-4c-4g-2045 systemd-logind[969]: New session 2 of user jenkins. May 28 03:11:15 prd-ubuntu1804-docker-4c-4g-2045 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) May 28 03:12:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[2633]: pam_unix(cron:session): session opened for user root by (uid=0) May 28 03:12:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[2633]: pam_unix(cron:session): session closed for user root May 28 03:13:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[3388]: pam_unix(cron:session): session opened for user root by (uid=0) May 28 03:13:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[3388]: pam_unix(cron:session): session closed for user root May 28 03:14:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[3702]: pam_unix(cron:session): session opened for user root by (uid=0) May 28 03:14:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[3702]: pam_unix(cron:session): session closed for user root May 28 03:15:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[3770]: pam_unix(cron:session): session opened for user root by (uid=0) May 28 03:15:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[3770]: pam_unix(cron:session): session closed for user root May 28 03:16:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[3859]: pam_unix(cron:session): session opened for user root by (uid=0) May 28 03:16:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[3859]: pam_unix(cron:session): session closed for user root May 28 03:17:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[3961]: pam_unix(cron:session): session opened for user root by (uid=0) May 28 03:17:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[3962]: pam_unix(cron:session): session opened for user root by (uid=0) May 28 03:17:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[3961]: pam_unix(cron:session): session closed for user root May 28 03:17:01 prd-ubuntu1804-docker-4c-4g-2045 CRON[3962]: pam_unix(cron:session): session closed for user root May 28 03:17:30 prd-ubuntu1804-docker-4c-4g-2045 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/portal-nonrtric-controlpanel-docker-merge-i-release ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp May 28 03:17:30 prd-ubuntu1804-docker-4c-4g-2045 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)