Jun 18 03:10:46 prd-ubuntu1804-docker-4c-4g-3763 passwd[939]: password for 'ubuntu' changed by 'root' Jun 18 03:10:46 prd-ubuntu1804-docker-4c-4g-3763 systemd-logind[994]: Watching system buttons on /dev/input/event0 (Power Button) Jun 18 03:10:46 prd-ubuntu1804-docker-4c-4g-3763 systemd-logind[994]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jun 18 03:10:46 prd-ubuntu1804-docker-4c-4g-3763 systemd-logind[994]: New seat seat0. Jun 18 03:10:46 prd-ubuntu1804-docker-4c-4g-3763 sshd[1096]: Server listening on 0.0.0.0 port 22. Jun 18 03:10:46 prd-ubuntu1804-docker-4c-4g-3763 sshd[1096]: Server listening on :: port 22. Jun 18 03:10:49 prd-ubuntu1804-docker-4c-4g-3763 sshd[1437]: Did not receive identification string from 10.32.4.5 port 33788 Jun 18 03:10:51 prd-ubuntu1804-docker-4c-4g-3763 sshd[1482]: Invalid user jenkins from 10.32.4.5 port 33796 Jun 18 03:10:51 prd-ubuntu1804-docker-4c-4g-3763 sshd[1482]: Received disconnect from 10.32.4.5 port 33796:11: Closed due to user request. [preauth] Jun 18 03:10:51 prd-ubuntu1804-docker-4c-4g-3763 sshd[1482]: Disconnected from invalid user jenkins 10.32.4.5 port 33796 [preauth] Jun 18 03:10:53 prd-ubuntu1804-docker-4c-4g-3763 sshd[1502]: Invalid user jenkins from 10.32.4.5 port 33798 Jun 18 03:10:53 prd-ubuntu1804-docker-4c-4g-3763 sshd[1502]: Received disconnect from 10.32.4.5 port 33798:11: Closed due to user request. [preauth] Jun 18 03:10:53 prd-ubuntu1804-docker-4c-4g-3763 sshd[1502]: Disconnected from invalid user jenkins 10.32.4.5 port 33798 [preauth] Jun 18 03:10:55 prd-ubuntu1804-docker-4c-4g-3763 sshd[1504]: Invalid user jenkins from 10.32.4.5 port 33800 Jun 18 03:10:56 prd-ubuntu1804-docker-4c-4g-3763 sshd[1504]: Received disconnect from 10.32.4.5 port 33800:11: Closed due to user request. [preauth] Jun 18 03:10:56 prd-ubuntu1804-docker-4c-4g-3763 sshd[1504]: Disconnected from invalid user jenkins 10.32.4.5 port 33800 [preauth] Jun 18 03:10:58 prd-ubuntu1804-docker-4c-4g-3763 sshd[1506]: Invalid user jenkins from 10.32.4.5 port 33802 Jun 18 03:10:58 prd-ubuntu1804-docker-4c-4g-3763 sshd[1506]: Received disconnect from 10.32.4.5 port 33802:11: Closed due to user request. [preauth] Jun 18 03:10:58 prd-ubuntu1804-docker-4c-4g-3763 sshd[1506]: Disconnected from invalid user jenkins 10.32.4.5 port 33802 [preauth] Jun 18 03:11:00 prd-ubuntu1804-docker-4c-4g-3763 sshd[1508]: Invalid user jenkins from 10.32.4.5 port 33806 Jun 18 03:11:00 prd-ubuntu1804-docker-4c-4g-3763 sshd[1508]: Received disconnect from 10.32.4.5 port 33806:11: Closed due to user request. [preauth] Jun 18 03:11:00 prd-ubuntu1804-docker-4c-4g-3763 sshd[1508]: Disconnected from invalid user jenkins 10.32.4.5 port 33806 [preauth] Jun 18 03:11:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[1510]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 18 03:11:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[1510]: pam_unix(cron:session): session closed for user root Jun 18 03:11:02 prd-ubuntu1804-docker-4c-4g-3763 sshd[1519]: Invalid user jenkins from 10.32.4.5 port 33808 Jun 18 03:11:02 prd-ubuntu1804-docker-4c-4g-3763 sshd[1519]: Received disconnect from 10.32.4.5 port 33808:11: Closed due to user request. [preauth] Jun 18 03:11:02 prd-ubuntu1804-docker-4c-4g-3763 sshd[1519]: Disconnected from invalid user jenkins 10.32.4.5 port 33808 [preauth] Jun 18 03:11:04 prd-ubuntu1804-docker-4c-4g-3763 sshd[1521]: Invalid user jenkins from 10.32.4.5 port 33810 Jun 18 03:11:04 prd-ubuntu1804-docker-4c-4g-3763 sshd[1521]: Received disconnect from 10.32.4.5 port 33810:11: Closed due to user request. [preauth] Jun 18 03:11:04 prd-ubuntu1804-docker-4c-4g-3763 sshd[1521]: Disconnected from invalid user jenkins 10.32.4.5 port 33810 [preauth] Jun 18 03:11:06 prd-ubuntu1804-docker-4c-4g-3763 sshd[1523]: Invalid user jenkins from 10.32.4.5 port 33812 Jun 18 03:11:06 prd-ubuntu1804-docker-4c-4g-3763 sshd[1523]: Received disconnect from 10.32.4.5 port 33812:11: Closed due to user request. [preauth] Jun 18 03:11:06 prd-ubuntu1804-docker-4c-4g-3763 sshd[1523]: Disconnected from invalid user jenkins 10.32.4.5 port 33812 [preauth] Jun 18 03:11:08 prd-ubuntu1804-docker-4c-4g-3763 sshd[1688]: Invalid user jenkins from 10.32.4.5 port 33814 Jun 18 03:11:08 prd-ubuntu1804-docker-4c-4g-3763 sshd[1688]: Received disconnect from 10.32.4.5 port 33814:11: Closed due to user request. [preauth] Jun 18 03:11:08 prd-ubuntu1804-docker-4c-4g-3763 sshd[1688]: Disconnected from invalid user jenkins 10.32.4.5 port 33814 [preauth] Jun 18 03:11:10 prd-ubuntu1804-docker-4c-4g-3763 sshd[1780]: Invalid user jenkins from 10.32.4.5 port 33816 Jun 18 03:11:10 prd-ubuntu1804-docker-4c-4g-3763 sshd[1780]: Received disconnect from 10.32.4.5 port 33816:11: Closed due to user request. [preauth] Jun 18 03:11:10 prd-ubuntu1804-docker-4c-4g-3763 sshd[1780]: Disconnected from invalid user jenkins 10.32.4.5 port 33816 [preauth] Jun 18 03:11:12 prd-ubuntu1804-docker-4c-4g-3763 sshd[1799]: Invalid user jenkins from 10.32.4.5 port 33818 Jun 18 03:11:12 prd-ubuntu1804-docker-4c-4g-3763 sshd[1799]: Received disconnect from 10.32.4.5 port 33818:11: Closed due to user request. [preauth] Jun 18 03:11:12 prd-ubuntu1804-docker-4c-4g-3763 sshd[1799]: Disconnected from invalid user jenkins 10.32.4.5 port 33818 [preauth] Jun 18 03:11:14 prd-ubuntu1804-docker-4c-4g-3763 useradd[1817]: new group: name=jenkins, GID=1001 Jun 18 03:11:14 prd-ubuntu1804-docker-4c-4g-3763 useradd[1817]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Jun 18 03:11:14 prd-ubuntu1804-docker-4c-4g-3763 usermod[1824]: add 'jenkins' to group 'docker' Jun 18 03:11:14 prd-ubuntu1804-docker-4c-4g-3763 usermod[1824]: add 'jenkins' to shadow group 'docker' Jun 18 03:11:14 prd-ubuntu1804-docker-4c-4g-3763 sshd[1858]: Accepted publickey for jenkins from 10.32.4.5 port 33822 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Jun 18 03:11:14 prd-ubuntu1804-docker-4c-4g-3763 sshd[1858]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jun 18 03:11:14 prd-ubuntu1804-docker-4c-4g-3763 systemd-logind[994]: New session 2 of user jenkins. Jun 18 03:11:14 prd-ubuntu1804-docker-4c-4g-3763 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jun 18 03:12:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[2591]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 18 03:12:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[2591]: pam_unix(cron:session): session closed for user root Jun 18 03:13:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[3332]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 18 03:13:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[3332]: pam_unix(cron:session): session closed for user root Jun 18 03:14:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[3652]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 18 03:14:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[3652]: pam_unix(cron:session): session closed for user root Jun 18 03:15:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[3718]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 18 03:15:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[3718]: pam_unix(cron:session): session closed for user root Jun 18 03:16:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[3831]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 18 03:16:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[3831]: pam_unix(cron:session): session closed for user root Jun 18 03:17:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[4108]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 18 03:17:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[4109]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 18 03:17:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[4108]: pam_unix(cron:session): session closed for user root Jun 18 03:17:01 prd-ubuntu1804-docker-4c-4g-3763 CRON[4109]: pam_unix(cron:session): session closed for user root Jun 18 03:17:18 prd-ubuntu1804-docker-4c-4g-3763 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/portal-nonrtric-controlpanel-docker-merge-i-release ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Jun 18 03:17:18 prd-ubuntu1804-docker-4c-4g-3763 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)