Jun 17 03:10:49 prd-ubuntu1804-docker-4c-4g-2972 passwd[931]: password for 'ubuntu' changed by 'root' Jun 17 03:10:49 prd-ubuntu1804-docker-4c-4g-2972 systemd-logind[970]: Watching system buttons on /dev/input/event0 (Power Button) Jun 17 03:10:49 prd-ubuntu1804-docker-4c-4g-2972 systemd-logind[970]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jun 17 03:10:49 prd-ubuntu1804-docker-4c-4g-2972 systemd-logind[970]: New seat seat0. Jun 17 03:10:49 prd-ubuntu1804-docker-4c-4g-2972 sshd[1272]: Server listening on 0.0.0.0 port 22. Jun 17 03:10:49 prd-ubuntu1804-docker-4c-4g-2972 sshd[1272]: Server listening on :: port 22. Jun 17 03:10:52 prd-ubuntu1804-docker-4c-4g-2972 sshd[1486]: Did not receive identification string from 10.32.4.5 port 35898 Jun 17 03:10:56 prd-ubuntu1804-docker-4c-4g-2972 sshd[1527]: Invalid user jenkins from 10.32.4.5 port 35900 Jun 17 03:10:56 prd-ubuntu1804-docker-4c-4g-2972 sshd[1527]: Received disconnect from 10.32.4.5 port 35900:11: Closed due to user request. [preauth] Jun 17 03:10:56 prd-ubuntu1804-docker-4c-4g-2972 sshd[1527]: Disconnected from invalid user jenkins 10.32.4.5 port 35900 [preauth] Jun 17 03:10:58 prd-ubuntu1804-docker-4c-4g-2972 sshd[1546]: Invalid user jenkins from 10.32.4.5 port 35902 Jun 17 03:10:58 prd-ubuntu1804-docker-4c-4g-2972 sshd[1546]: Received disconnect from 10.32.4.5 port 35902:11: Closed due to user request. [preauth] Jun 17 03:10:58 prd-ubuntu1804-docker-4c-4g-2972 sshd[1546]: Disconnected from invalid user jenkins 10.32.4.5 port 35902 [preauth] Jun 17 03:11:00 prd-ubuntu1804-docker-4c-4g-2972 sshd[1548]: Invalid user jenkins from 10.32.4.5 port 35904 Jun 17 03:11:00 prd-ubuntu1804-docker-4c-4g-2972 sshd[1548]: Received disconnect from 10.32.4.5 port 35904:11: Closed due to user request. [preauth] Jun 17 03:11:00 prd-ubuntu1804-docker-4c-4g-2972 sshd[1548]: Disconnected from invalid user jenkins 10.32.4.5 port 35904 [preauth] Jun 17 03:11:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[1551]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 17 03:11:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[1551]: pam_unix(cron:session): session closed for user root Jun 17 03:11:02 prd-ubuntu1804-docker-4c-4g-2972 sshd[1558]: Invalid user jenkins from 10.32.4.5 port 35906 Jun 17 03:11:02 prd-ubuntu1804-docker-4c-4g-2972 sshd[1558]: Received disconnect from 10.32.4.5 port 35906:11: Closed due to user request. [preauth] Jun 17 03:11:02 prd-ubuntu1804-docker-4c-4g-2972 sshd[1558]: Disconnected from invalid user jenkins 10.32.4.5 port 35906 [preauth] Jun 17 03:11:04 prd-ubuntu1804-docker-4c-4g-2972 sshd[1560]: Invalid user jenkins from 10.32.4.5 port 35910 Jun 17 03:11:04 prd-ubuntu1804-docker-4c-4g-2972 sshd[1560]: Received disconnect from 10.32.4.5 port 35910:11: Closed due to user request. [preauth] Jun 17 03:11:04 prd-ubuntu1804-docker-4c-4g-2972 sshd[1560]: Disconnected from invalid user jenkins 10.32.4.5 port 35910 [preauth] Jun 17 03:11:06 prd-ubuntu1804-docker-4c-4g-2972 sshd[1562]: Invalid user jenkins from 10.32.4.5 port 35912 Jun 17 03:11:06 prd-ubuntu1804-docker-4c-4g-2972 sshd[1562]: Received disconnect from 10.32.4.5 port 35912:11: Closed due to user request. [preauth] Jun 17 03:11:06 prd-ubuntu1804-docker-4c-4g-2972 sshd[1562]: Disconnected from invalid user jenkins 10.32.4.5 port 35912 [preauth] Jun 17 03:11:08 prd-ubuntu1804-docker-4c-4g-2972 sshd[1564]: Invalid user jenkins from 10.32.4.5 port 35914 Jun 17 03:11:08 prd-ubuntu1804-docker-4c-4g-2972 sshd[1564]: Received disconnect from 10.32.4.5 port 35914:11: Closed due to user request. [preauth] Jun 17 03:11:08 prd-ubuntu1804-docker-4c-4g-2972 sshd[1564]: Disconnected from invalid user jenkins 10.32.4.5 port 35914 [preauth] Jun 17 03:11:10 prd-ubuntu1804-docker-4c-4g-2972 sshd[1575]: Invalid user jenkins from 10.32.4.5 port 35916 Jun 17 03:11:10 prd-ubuntu1804-docker-4c-4g-2972 sshd[1575]: Received disconnect from 10.32.4.5 port 35916:11: Closed due to user request. [preauth] Jun 17 03:11:10 prd-ubuntu1804-docker-4c-4g-2972 sshd[1575]: Disconnected from invalid user jenkins 10.32.4.5 port 35916 [preauth] Jun 17 03:11:13 prd-ubuntu1804-docker-4c-4g-2972 sshd[1789]: Invalid user jenkins from 10.32.4.5 port 35924 Jun 17 03:11:13 prd-ubuntu1804-docker-4c-4g-2972 sshd[1789]: Received disconnect from 10.32.4.5 port 35924:11: Closed due to user request. [preauth] Jun 17 03:11:13 prd-ubuntu1804-docker-4c-4g-2972 sshd[1789]: Disconnected from invalid user jenkins 10.32.4.5 port 35924 [preauth] Jun 17 03:11:15 prd-ubuntu1804-docker-4c-4g-2972 sshd[1838]: Invalid user jenkins from 10.32.4.5 port 35926 Jun 17 03:11:15 prd-ubuntu1804-docker-4c-4g-2972 sshd[1838]: Received disconnect from 10.32.4.5 port 35926:11: Closed due to user request. [preauth] Jun 17 03:11:15 prd-ubuntu1804-docker-4c-4g-2972 sshd[1838]: Disconnected from invalid user jenkins 10.32.4.5 port 35926 [preauth] Jun 17 03:11:17 prd-ubuntu1804-docker-4c-4g-2972 sshd[1845]: Invalid user jenkins from 10.32.4.5 port 35928 Jun 17 03:11:17 prd-ubuntu1804-docker-4c-4g-2972 sshd[1845]: Received disconnect from 10.32.4.5 port 35928:11: Closed due to user request. [preauth] Jun 17 03:11:17 prd-ubuntu1804-docker-4c-4g-2972 sshd[1845]: Disconnected from invalid user jenkins 10.32.4.5 port 35928 [preauth] Jun 17 03:11:17 prd-ubuntu1804-docker-4c-4g-2972 useradd[1861]: new group: name=jenkins, GID=1001 Jun 17 03:11:17 prd-ubuntu1804-docker-4c-4g-2972 useradd[1861]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Jun 17 03:11:18 prd-ubuntu1804-docker-4c-4g-2972 usermod[1868]: add 'jenkins' to group 'docker' Jun 17 03:11:18 prd-ubuntu1804-docker-4c-4g-2972 usermod[1868]: add 'jenkins' to shadow group 'docker' Jun 17 03:11:19 prd-ubuntu1804-docker-4c-4g-2972 sshd[1909]: Accepted publickey for jenkins from 10.32.4.5 port 35930 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Jun 17 03:11:19 prd-ubuntu1804-docker-4c-4g-2972 sshd[1909]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jun 17 03:11:19 prd-ubuntu1804-docker-4c-4g-2972 systemd-logind[970]: New session 2 of user jenkins. Jun 17 03:11:19 prd-ubuntu1804-docker-4c-4g-2972 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jun 17 03:12:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[2472]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 17 03:12:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[2472]: pam_unix(cron:session): session closed for user root Jun 17 03:13:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[3212]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 17 03:13:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[3212]: pam_unix(cron:session): session closed for user root Jun 17 03:14:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[3533]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 17 03:14:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[3533]: pam_unix(cron:session): session closed for user root Jun 17 03:15:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[3604]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 17 03:15:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[3604]: pam_unix(cron:session): session closed for user root Jun 17 03:16:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[3738]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 17 03:16:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[3738]: pam_unix(cron:session): session closed for user root Jun 17 03:17:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[4010]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 17 03:17:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[4011]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 17 03:17:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[4010]: pam_unix(cron:session): session closed for user root Jun 17 03:17:01 prd-ubuntu1804-docker-4c-4g-2972 CRON[4011]: pam_unix(cron:session): session closed for user root Jun 17 03:17:20 prd-ubuntu1804-docker-4c-4g-2972 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/portal-nonrtric-controlpanel-docker-merge-i-release ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Jun 17 03:17:20 prd-ubuntu1804-docker-4c-4g-2972 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)