May 20 03:10:48 prd-ubuntu1804-docker-4c-4g-1275 passwd[905]: password for 'ubuntu' changed by 'root' May 20 03:10:48 prd-ubuntu1804-docker-4c-4g-1275 systemd-logind[1023]: Watching system buttons on /dev/input/event0 (Power Button) May 20 03:10:48 prd-ubuntu1804-docker-4c-4g-1275 systemd-logind[1023]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) May 20 03:10:48 prd-ubuntu1804-docker-4c-4g-1275 systemd-logind[1023]: New seat seat0. May 20 03:10:49 prd-ubuntu1804-docker-4c-4g-1275 sshd[1289]: Server listening on 0.0.0.0 port 22. May 20 03:10:49 prd-ubuntu1804-docker-4c-4g-1275 sshd[1289]: Server listening on :: port 22. May 20 03:10:53 prd-ubuntu1804-docker-4c-4g-1275 sshd[1512]: Did not receive identification string from 10.32.4.5 port 60370 May 20 03:10:55 prd-ubuntu1804-docker-4c-4g-1275 sshd[1541]: Invalid user jenkins from 10.32.4.5 port 60372 May 20 03:10:55 prd-ubuntu1804-docker-4c-4g-1275 sshd[1541]: Received disconnect from 10.32.4.5 port 60372:11: Closed due to user request. [preauth] May 20 03:10:55 prd-ubuntu1804-docker-4c-4g-1275 sshd[1541]: Disconnected from invalid user jenkins 10.32.4.5 port 60372 [preauth] May 20 03:10:57 prd-ubuntu1804-docker-4c-4g-1275 sshd[1560]: Invalid user jenkins from 10.32.4.5 port 60374 May 20 03:10:57 prd-ubuntu1804-docker-4c-4g-1275 sshd[1560]: Received disconnect from 10.32.4.5 port 60374:11: Closed due to user request. [preauth] May 20 03:10:57 prd-ubuntu1804-docker-4c-4g-1275 sshd[1560]: Disconnected from invalid user jenkins 10.32.4.5 port 60374 [preauth] May 20 03:10:59 prd-ubuntu1804-docker-4c-4g-1275 sshd[1562]: Invalid user jenkins from 10.32.4.5 port 60376 May 20 03:10:59 prd-ubuntu1804-docker-4c-4g-1275 sshd[1562]: Received disconnect from 10.32.4.5 port 60376:11: Closed due to user request. [preauth] May 20 03:10:59 prd-ubuntu1804-docker-4c-4g-1275 sshd[1562]: Disconnected from invalid user jenkins 10.32.4.5 port 60376 [preauth] May 20 03:11:01 prd-ubuntu1804-docker-4c-4g-1275 sshd[1585]: Invalid user jenkins from 10.32.4.5 port 60378 May 20 03:11:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[1587]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 03:11:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[1587]: pam_unix(cron:session): session closed for user root May 20 03:11:02 prd-ubuntu1804-docker-4c-4g-1275 sshd[1585]: Received disconnect from 10.32.4.5 port 60378:11: Closed due to user request. [preauth] May 20 03:11:02 prd-ubuntu1804-docker-4c-4g-1275 sshd[1585]: Disconnected from invalid user jenkins 10.32.4.5 port 60378 [preauth] May 20 03:11:04 prd-ubuntu1804-docker-4c-4g-1275 sshd[1596]: Invalid user jenkins from 10.32.4.5 port 60382 May 20 03:11:04 prd-ubuntu1804-docker-4c-4g-1275 sshd[1596]: Received disconnect from 10.32.4.5 port 60382:11: Closed due to user request. [preauth] May 20 03:11:04 prd-ubuntu1804-docker-4c-4g-1275 sshd[1596]: Disconnected from invalid user jenkins 10.32.4.5 port 60382 [preauth] May 20 03:11:06 prd-ubuntu1804-docker-4c-4g-1275 sshd[1598]: Invalid user jenkins from 10.32.4.5 port 60386 May 20 03:11:06 prd-ubuntu1804-docker-4c-4g-1275 sshd[1598]: Received disconnect from 10.32.4.5 port 60386:11: Closed due to user request. [preauth] May 20 03:11:06 prd-ubuntu1804-docker-4c-4g-1275 sshd[1598]: Disconnected from invalid user jenkins 10.32.4.5 port 60386 [preauth] May 20 03:11:08 prd-ubuntu1804-docker-4c-4g-1275 sshd[1600]: Invalid user jenkins from 10.32.4.5 port 60388 May 20 03:11:08 prd-ubuntu1804-docker-4c-4g-1275 sshd[1600]: Received disconnect from 10.32.4.5 port 60388:11: Closed due to user request. [preauth] May 20 03:11:08 prd-ubuntu1804-docker-4c-4g-1275 sshd[1600]: Disconnected from invalid user jenkins 10.32.4.5 port 60388 [preauth] May 20 03:11:10 prd-ubuntu1804-docker-4c-4g-1275 sshd[1604]: Invalid user jenkins from 10.32.4.5 port 60392 May 20 03:11:10 prd-ubuntu1804-docker-4c-4g-1275 sshd[1604]: Received disconnect from 10.32.4.5 port 60392:11: Closed due to user request. [preauth] May 20 03:11:10 prd-ubuntu1804-docker-4c-4g-1275 sshd[1604]: Disconnected from invalid user jenkins 10.32.4.5 port 60392 [preauth] May 20 03:11:12 prd-ubuntu1804-docker-4c-4g-1275 sshd[1815]: Invalid user jenkins from 10.32.4.5 port 60400 May 20 03:11:12 prd-ubuntu1804-docker-4c-4g-1275 sshd[1815]: Received disconnect from 10.32.4.5 port 60400:11: Closed due to user request. [preauth] May 20 03:11:12 prd-ubuntu1804-docker-4c-4g-1275 sshd[1815]: Disconnected from invalid user jenkins 10.32.4.5 port 60400 [preauth] May 20 03:11:15 prd-ubuntu1804-docker-4c-4g-1275 sshd[1872]: Invalid user jenkins from 10.32.4.5 port 60402 May 20 03:11:15 prd-ubuntu1804-docker-4c-4g-1275 sshd[1872]: Received disconnect from 10.32.4.5 port 60402:11: Closed due to user request. [preauth] May 20 03:11:15 prd-ubuntu1804-docker-4c-4g-1275 sshd[1872]: Disconnected from invalid user jenkins 10.32.4.5 port 60402 [preauth] May 20 03:11:17 prd-ubuntu1804-docker-4c-4g-1275 sshd[1881]: Invalid user jenkins from 10.32.4.5 port 60404 May 20 03:11:17 prd-ubuntu1804-docker-4c-4g-1275 sshd[1881]: Received disconnect from 10.32.4.5 port 60404:11: Closed due to user request. [preauth] May 20 03:11:17 prd-ubuntu1804-docker-4c-4g-1275 sshd[1881]: Disconnected from invalid user jenkins 10.32.4.5 port 60404 [preauth] May 20 03:11:18 prd-ubuntu1804-docker-4c-4g-1275 useradd[1897]: new group: name=jenkins, GID=1001 May 20 03:11:18 prd-ubuntu1804-docker-4c-4g-1275 useradd[1897]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash May 20 03:11:18 prd-ubuntu1804-docker-4c-4g-1275 usermod[1904]: add 'jenkins' to group 'docker' May 20 03:11:18 prd-ubuntu1804-docker-4c-4g-1275 usermod[1904]: add 'jenkins' to shadow group 'docker' May 20 03:11:19 prd-ubuntu1804-docker-4c-4g-1275 sshd[1946]: Accepted publickey for jenkins from 10.32.4.5 port 60406 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI May 20 03:11:19 prd-ubuntu1804-docker-4c-4g-1275 sshd[1946]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) May 20 03:11:19 prd-ubuntu1804-docker-4c-4g-1275 systemd-logind[1023]: New session 2 of user jenkins. May 20 03:11:19 prd-ubuntu1804-docker-4c-4g-1275 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) May 20 03:12:02 prd-ubuntu1804-docker-4c-4g-1275 CRON[2499]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 03:12:02 prd-ubuntu1804-docker-4c-4g-1275 CRON[2499]: pam_unix(cron:session): session closed for user root May 20 03:13:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[3235]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 03:13:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[3235]: pam_unix(cron:session): session closed for user root May 20 03:14:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[3558]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 03:14:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[3558]: pam_unix(cron:session): session closed for user root May 20 03:15:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[3628]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 03:15:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[3628]: pam_unix(cron:session): session closed for user root May 20 03:16:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[3741]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 03:16:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[3741]: pam_unix(cron:session): session closed for user root May 20 03:17:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[4183]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 03:17:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[4182]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 03:17:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[4182]: pam_unix(cron:session): session closed for user root May 20 03:17:01 prd-ubuntu1804-docker-4c-4g-1275 CRON[4183]: pam_unix(cron:session): session closed for user root May 20 03:17:13 prd-ubuntu1804-docker-4c-4g-1275 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/portal-nonrtric-controlpanel-docker-merge-i-release ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp May 20 03:17:13 prd-ubuntu1804-docker-4c-4g-1275 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)