Aug 21 02:51:49 prd-ubuntu1804-docker-4c-4g-1555 passwd[937]: password for 'ubuntu' changed by 'root' Aug 21 02:51:49 prd-ubuntu1804-docker-4c-4g-1555 systemd-logind[974]: Watching system buttons on /dev/input/event0 (Power Button) Aug 21 02:51:49 prd-ubuntu1804-docker-4c-4g-1555 systemd-logind[974]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Aug 21 02:51:49 prd-ubuntu1804-docker-4c-4g-1555 systemd-logind[974]: New seat seat0. Aug 21 02:51:49 prd-ubuntu1804-docker-4c-4g-1555 sshd[1224]: Server listening on 0.0.0.0 port 22. Aug 21 02:51:49 prd-ubuntu1804-docker-4c-4g-1555 sshd[1224]: Server listening on :: port 22. Aug 21 02:51:52 prd-ubuntu1804-docker-4c-4g-1555 sshd[1422]: Did not receive identification string from 10.32.4.5 port 36698 Aug 21 02:51:56 prd-ubuntu1804-docker-4c-4g-1555 sshd[1478]: Invalid user jenkins from 10.32.4.5 port 36700 Aug 21 02:51:56 prd-ubuntu1804-docker-4c-4g-1555 sshd[1478]: Received disconnect from 10.32.4.5 port 36700:11: Closed due to user request. [preauth] Aug 21 02:51:56 prd-ubuntu1804-docker-4c-4g-1555 sshd[1478]: Disconnected from invalid user jenkins 10.32.4.5 port 36700 [preauth] Aug 21 02:51:58 prd-ubuntu1804-docker-4c-4g-1555 sshd[1496]: Invalid user jenkins from 10.32.4.5 port 36702 Aug 21 02:51:58 prd-ubuntu1804-docker-4c-4g-1555 sshd[1496]: Received disconnect from 10.32.4.5 port 36702:11: Closed due to user request. [preauth] Aug 21 02:51:58 prd-ubuntu1804-docker-4c-4g-1555 sshd[1496]: Disconnected from invalid user jenkins 10.32.4.5 port 36702 [preauth] Aug 21 02:52:00 prd-ubuntu1804-docker-4c-4g-1555 sshd[1498]: Invalid user jenkins from 10.32.4.5 port 36710 Aug 21 02:52:00 prd-ubuntu1804-docker-4c-4g-1555 sshd[1498]: Received disconnect from 10.32.4.5 port 36710:11: Closed due to user request. [preauth] Aug 21 02:52:00 prd-ubuntu1804-docker-4c-4g-1555 sshd[1498]: Disconnected from invalid user jenkins 10.32.4.5 port 36710 [preauth] Aug 21 02:52:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[1501]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 02:52:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[1501]: pam_unix(cron:session): session closed for user root Aug 21 02:52:02 prd-ubuntu1804-docker-4c-4g-1555 sshd[1509]: Invalid user jenkins from 10.32.4.5 port 36712 Aug 21 02:52:02 prd-ubuntu1804-docker-4c-4g-1555 sshd[1509]: Received disconnect from 10.32.4.5 port 36712:11: Closed due to user request. [preauth] Aug 21 02:52:02 prd-ubuntu1804-docker-4c-4g-1555 sshd[1509]: Disconnected from invalid user jenkins 10.32.4.5 port 36712 [preauth] Aug 21 02:52:04 prd-ubuntu1804-docker-4c-4g-1555 sshd[1511]: Invalid user jenkins from 10.32.4.5 port 36714 Aug 21 02:52:04 prd-ubuntu1804-docker-4c-4g-1555 sshd[1511]: Received disconnect from 10.32.4.5 port 36714:11: Closed due to user request. [preauth] Aug 21 02:52:04 prd-ubuntu1804-docker-4c-4g-1555 sshd[1511]: Disconnected from invalid user jenkins 10.32.4.5 port 36714 [preauth] Aug 21 02:52:06 prd-ubuntu1804-docker-4c-4g-1555 sshd[1513]: Invalid user jenkins from 10.32.4.5 port 36716 Aug 21 02:52:06 prd-ubuntu1804-docker-4c-4g-1555 sshd[1513]: Received disconnect from 10.32.4.5 port 36716:11: Closed due to user request. [preauth] Aug 21 02:52:06 prd-ubuntu1804-docker-4c-4g-1555 sshd[1513]: Disconnected from invalid user jenkins 10.32.4.5 port 36716 [preauth] Aug 21 02:52:08 prd-ubuntu1804-docker-4c-4g-1555 sshd[1515]: Invalid user jenkins from 10.32.4.5 port 36720 Aug 21 02:52:08 prd-ubuntu1804-docker-4c-4g-1555 sshd[1515]: Received disconnect from 10.32.4.5 port 36720:11: Closed due to user request. [preauth] Aug 21 02:52:08 prd-ubuntu1804-docker-4c-4g-1555 sshd[1515]: Disconnected from invalid user jenkins 10.32.4.5 port 36720 [preauth] Aug 21 02:52:10 prd-ubuntu1804-docker-4c-4g-1555 sshd[1517]: Invalid user jenkins from 10.32.4.5 port 36722 Aug 21 02:52:11 prd-ubuntu1804-docker-4c-4g-1555 sshd[1517]: Received disconnect from 10.32.4.5 port 36722:11: Closed due to user request. [preauth] Aug 21 02:52:11 prd-ubuntu1804-docker-4c-4g-1555 sshd[1517]: Disconnected from invalid user jenkins 10.32.4.5 port 36722 [preauth] Aug 21 02:52:13 prd-ubuntu1804-docker-4c-4g-1555 sshd[1727]: Invalid user jenkins from 10.32.4.5 port 36724 Aug 21 02:52:13 prd-ubuntu1804-docker-4c-4g-1555 sshd[1727]: Received disconnect from 10.32.4.5 port 36724:11: Closed due to user request. [preauth] Aug 21 02:52:13 prd-ubuntu1804-docker-4c-4g-1555 sshd[1727]: Disconnected from invalid user jenkins 10.32.4.5 port 36724 [preauth] Aug 21 02:52:15 prd-ubuntu1804-docker-4c-4g-1555 sshd[1782]: Invalid user jenkins from 10.32.4.5 port 36726 Aug 21 02:52:15 prd-ubuntu1804-docker-4c-4g-1555 sshd[1782]: Received disconnect from 10.32.4.5 port 36726:11: Closed due to user request. [preauth] Aug 21 02:52:15 prd-ubuntu1804-docker-4c-4g-1555 sshd[1782]: Disconnected from invalid user jenkins 10.32.4.5 port 36726 [preauth] Aug 21 02:52:17 prd-ubuntu1804-docker-4c-4g-1555 sshd[1800]: Invalid user jenkins from 10.32.4.5 port 36728 Aug 21 02:52:17 prd-ubuntu1804-docker-4c-4g-1555 sshd[1800]: Received disconnect from 10.32.4.5 port 36728:11: Closed due to user request. [preauth] Aug 21 02:52:17 prd-ubuntu1804-docker-4c-4g-1555 sshd[1800]: Disconnected from invalid user jenkins 10.32.4.5 port 36728 [preauth] Aug 21 02:52:19 prd-ubuntu1804-docker-4c-4g-1555 sshd[1804]: Invalid user jenkins from 10.32.4.5 port 36730 Aug 21 02:52:20 prd-ubuntu1804-docker-4c-4g-1555 sshd[1804]: Received disconnect from 10.32.4.5 port 36730:11: Closed due to user request. [preauth] Aug 21 02:52:20 prd-ubuntu1804-docker-4c-4g-1555 sshd[1804]: Disconnected from invalid user jenkins 10.32.4.5 port 36730 [preauth] Aug 21 02:52:20 prd-ubuntu1804-docker-4c-4g-1555 useradd[1820]: new group: name=jenkins, GID=1001 Aug 21 02:52:20 prd-ubuntu1804-docker-4c-4g-1555 useradd[1820]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Aug 21 02:52:20 prd-ubuntu1804-docker-4c-4g-1555 usermod[1827]: add 'jenkins' to group 'docker' Aug 21 02:52:20 prd-ubuntu1804-docker-4c-4g-1555 usermod[1827]: add 'jenkins' to shadow group 'docker' Aug 21 02:52:22 prd-ubuntu1804-docker-4c-4g-1555 sshd[1871]: Accepted publickey for jenkins from 10.32.4.5 port 36732 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Aug 21 02:52:22 prd-ubuntu1804-docker-4c-4g-1555 sshd[1871]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Aug 21 02:52:22 prd-ubuntu1804-docker-4c-4g-1555 systemd-logind[974]: New session 2 of user jenkins. Aug 21 02:52:22 prd-ubuntu1804-docker-4c-4g-1555 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Aug 21 02:53:02 prd-ubuntu1804-docker-4c-4g-1555 CRON[2387]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 02:53:02 prd-ubuntu1804-docker-4c-4g-1555 CRON[2387]: pam_unix(cron:session): session closed for user root Aug 21 02:54:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[2439]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 02:54:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[2439]: pam_unix(cron:session): session closed for user root Aug 21 02:55:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[3886]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 02:55:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[3886]: pam_unix(cron:session): session closed for user root Aug 21 02:56:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[8332]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 02:56:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[8332]: pam_unix(cron:session): session closed for user root Aug 21 02:57:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[9945]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 02:57:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[9945]: pam_unix(cron:session): session closed for user root Aug 21 02:58:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[16764]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 02:58:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[16764]: pam_unix(cron:session): session closed for user root Aug 21 02:59:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[18815]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 02:59:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[18815]: pam_unix(cron:session): session closed for user root Aug 21 03:00:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[19659]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 03:00:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[19659]: pam_unix(cron:session): session closed for user root Aug 21 03:01:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[20642]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 03:01:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[20642]: pam_unix(cron:session): session closed for user root Aug 21 03:02:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[21392]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 03:02:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[21392]: pam_unix(cron:session): session closed for user root Aug 21 03:03:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[25095]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 03:03:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[25095]: pam_unix(cron:session): session closed for user root Aug 21 03:04:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[27098]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 03:04:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[27098]: pam_unix(cron:session): session closed for user root Aug 21 03:05:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[27367]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 03:05:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[27367]: pam_unix(cron:session): session closed for user root Aug 21 03:06:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[27572]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 21 03:06:01 prd-ubuntu1804-docker-4c-4g-1555 CRON[27572]: pam_unix(cron:session): session closed for user root Aug 21 03:06:26 prd-ubuntu1804-docker-4c-4g-1555 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-app-hw-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Aug 21 03:06:26 prd-ubuntu1804-docker-4c-4g-1555 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)