Mar 2 08:13:39 prd-ubuntu1804-docker-4c-4g-1600 passwd[894]: password for 'ubuntu' changed by 'root' Mar 2 08:13:39 prd-ubuntu1804-docker-4c-4g-1600 systemd-logind[1045]: Watching system buttons on /dev/input/event0 (Power Button) Mar 2 08:13:39 prd-ubuntu1804-docker-4c-4g-1600 systemd-logind[1045]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Mar 2 08:13:39 prd-ubuntu1804-docker-4c-4g-1600 systemd-logind[1045]: New seat seat0. Mar 2 08:13:39 prd-ubuntu1804-docker-4c-4g-1600 sshd[1207]: Server listening on 0.0.0.0 port 22. Mar 2 08:13:39 prd-ubuntu1804-docker-4c-4g-1600 sshd[1207]: Server listening on :: port 22. Mar 2 08:13:44 prd-ubuntu1804-docker-4c-4g-1600 sshd[1443]: Did not receive identification string from 10.32.4.5 port 34798 Mar 2 08:13:52 prd-ubuntu1804-docker-4c-4g-1600 sshd[1487]: Invalid user jenkins from 10.32.4.5 port 34804 Mar 2 08:13:52 prd-ubuntu1804-docker-4c-4g-1600 sshd[1487]: Received disconnect from 10.32.4.5 port 34804:11: Closed due to user request. [preauth] Mar 2 08:13:52 prd-ubuntu1804-docker-4c-4g-1600 sshd[1487]: Disconnected from invalid user jenkins 10.32.4.5 port 34804 [preauth] Mar 2 08:13:54 prd-ubuntu1804-docker-4c-4g-1600 sshd[1491]: Invalid user jenkins from 10.32.4.5 port 34806 Mar 2 08:13:54 prd-ubuntu1804-docker-4c-4g-1600 sshd[1491]: Received disconnect from 10.32.4.5 port 34806:11: Closed due to user request. [preauth] Mar 2 08:13:54 prd-ubuntu1804-docker-4c-4g-1600 sshd[1491]: Disconnected from invalid user jenkins 10.32.4.5 port 34806 [preauth] Mar 2 08:13:56 prd-ubuntu1804-docker-4c-4g-1600 sshd[1493]: Invalid user jenkins from 10.32.4.5 port 34808 Mar 2 08:13:57 prd-ubuntu1804-docker-4c-4g-1600 sshd[1493]: Received disconnect from 10.32.4.5 port 34808:11: Closed due to user request. [preauth] Mar 2 08:13:57 prd-ubuntu1804-docker-4c-4g-1600 sshd[1493]: Disconnected from invalid user jenkins 10.32.4.5 port 34808 [preauth] Mar 2 08:13:59 prd-ubuntu1804-docker-4c-4g-1600 sshd[1495]: Invalid user jenkins from 10.32.4.5 port 34810 Mar 2 08:13:59 prd-ubuntu1804-docker-4c-4g-1600 sshd[1495]: Received disconnect from 10.32.4.5 port 34810:11: Closed due to user request. [preauth] Mar 2 08:13:59 prd-ubuntu1804-docker-4c-4g-1600 sshd[1495]: Disconnected from invalid user jenkins 10.32.4.5 port 34810 [preauth] Mar 2 08:14:01 prd-ubuntu1804-docker-4c-4g-1600 sshd[1507]: Invalid user jenkins from 10.32.4.5 port 34812 Mar 2 08:14:01 prd-ubuntu1804-docker-4c-4g-1600 sshd[1507]: Received disconnect from 10.32.4.5 port 34812:11: Closed due to user request. [preauth] Mar 2 08:14:01 prd-ubuntu1804-docker-4c-4g-1600 sshd[1507]: Disconnected from invalid user jenkins 10.32.4.5 port 34812 [preauth] Mar 2 08:14:01 prd-ubuntu1804-docker-4c-4g-1600 CRON[1510]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 2 08:14:01 prd-ubuntu1804-docker-4c-4g-1600 CRON[1510]: pam_unix(cron:session): session closed for user root Mar 2 08:14:03 prd-ubuntu1804-docker-4c-4g-1600 sshd[1724]: Invalid user jenkins from 10.32.4.5 port 34814 Mar 2 08:14:03 prd-ubuntu1804-docker-4c-4g-1600 sshd[1724]: Received disconnect from 10.32.4.5 port 34814:11: Closed due to user request. [preauth] Mar 2 08:14:03 prd-ubuntu1804-docker-4c-4g-1600 sshd[1724]: Disconnected from invalid user jenkins 10.32.4.5 port 34814 [preauth] Mar 2 08:14:05 prd-ubuntu1804-docker-4c-4g-1600 sshd[1769]: Invalid user jenkins from 10.32.4.5 port 34818 Mar 2 08:14:06 prd-ubuntu1804-docker-4c-4g-1600 sshd[1769]: Received disconnect from 10.32.4.5 port 34818:11: Closed due to user request. [preauth] Mar 2 08:14:06 prd-ubuntu1804-docker-4c-4g-1600 sshd[1769]: Disconnected from invalid user jenkins 10.32.4.5 port 34818 [preauth] Mar 2 08:14:08 prd-ubuntu1804-docker-4c-4g-1600 sshd[1789]: Invalid user jenkins from 10.32.4.5 port 34820 Mar 2 08:14:08 prd-ubuntu1804-docker-4c-4g-1600 sshd[1789]: Received disconnect from 10.32.4.5 port 34820:11: Closed due to user request. [preauth] Mar 2 08:14:08 prd-ubuntu1804-docker-4c-4g-1600 sshd[1789]: Disconnected from invalid user jenkins 10.32.4.5 port 34820 [preauth] Mar 2 08:14:09 prd-ubuntu1804-docker-4c-4g-1600 useradd[1805]: new group: name=jenkins, GID=1001 Mar 2 08:14:09 prd-ubuntu1804-docker-4c-4g-1600 useradd[1805]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Mar 2 08:14:09 prd-ubuntu1804-docker-4c-4g-1600 usermod[1812]: add 'jenkins' to group 'docker' Mar 2 08:14:09 prd-ubuntu1804-docker-4c-4g-1600 usermod[1812]: add 'jenkins' to shadow group 'docker' Mar 2 08:14:10 prd-ubuntu1804-docker-4c-4g-1600 sshd[1846]: Accepted publickey for jenkins from 10.32.4.5 port 34822 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Mar 2 08:14:10 prd-ubuntu1804-docker-4c-4g-1600 sshd[1846]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Mar 2 08:14:10 prd-ubuntu1804-docker-4c-4g-1600 systemd-logind[1045]: New session 2 of user jenkins. Mar 2 08:14:10 prd-ubuntu1804-docker-4c-4g-1600 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Mar 2 08:15:01 prd-ubuntu1804-docker-4c-4g-1600 CRON[2405]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 2 08:15:01 prd-ubuntu1804-docker-4c-4g-1600 CRON[2405]: pam_unix(cron:session): session closed for user root Mar 2 08:16:01 prd-ubuntu1804-docker-4c-4g-1600 CRON[3160]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 2 08:16:02 prd-ubuntu1804-docker-4c-4g-1600 CRON[3160]: pam_unix(cron:session): session closed for user root Mar 2 08:17:01 prd-ubuntu1804-docker-4c-4g-1600 CRON[6102]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 2 08:17:01 prd-ubuntu1804-docker-4c-4g-1600 CRON[6103]: pam_unix(cron:session): session opened for user root by (uid=0) Mar 2 08:17:01 prd-ubuntu1804-docker-4c-4g-1600 CRON[6103]: pam_unix(cron:session): session closed for user root Mar 2 08:17:01 prd-ubuntu1804-docker-4c-4g-1600 CRON[6102]: pam_unix(cron:session): session closed for user root Mar 2 08:17:25 prd-ubuntu1804-docker-4c-4g-1600 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-app-rc-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Mar 2 08:17:25 prd-ubuntu1804-docker-4c-4g-1600 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)