Jun 23 01:35:46 prd-ubuntu1804-docker-4c-4g-3526 passwd[940]: password for 'ubuntu' changed by 'root' Jun 23 01:35:47 prd-ubuntu1804-docker-4c-4g-3526 systemd-logind[1077]: Watching system buttons on /dev/input/event0 (Power Button) Jun 23 01:35:47 prd-ubuntu1804-docker-4c-4g-3526 systemd-logind[1077]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jun 23 01:35:47 prd-ubuntu1804-docker-4c-4g-3526 systemd-logind[1077]: New seat seat0. Jun 23 01:35:47 prd-ubuntu1804-docker-4c-4g-3526 sshd[1269]: Server listening on 0.0.0.0 port 22. Jun 23 01:35:47 prd-ubuntu1804-docker-4c-4g-3526 sshd[1269]: Server listening on :: port 22. Jun 23 01:35:49 prd-ubuntu1804-docker-4c-4g-3526 sshd[1387]: Did not receive identification string from 10.32.4.5 port 48966 Jun 23 01:35:55 prd-ubuntu1804-docker-4c-4g-3526 sshd[1565]: Invalid user jenkins from 10.32.4.5 port 48968 Jun 23 01:35:55 prd-ubuntu1804-docker-4c-4g-3526 sshd[1565]: Received disconnect from 10.32.4.5 port 48968:11: Closed due to user request. [preauth] Jun 23 01:35:55 prd-ubuntu1804-docker-4c-4g-3526 sshd[1565]: Disconnected from invalid user jenkins 10.32.4.5 port 48968 [preauth] Jun 23 01:35:57 prd-ubuntu1804-docker-4c-4g-3526 sshd[1569]: Invalid user jenkins from 10.32.4.5 port 48970 Jun 23 01:35:57 prd-ubuntu1804-docker-4c-4g-3526 sshd[1569]: Received disconnect from 10.32.4.5 port 48970:11: Closed due to user request. [preauth] Jun 23 01:35:57 prd-ubuntu1804-docker-4c-4g-3526 sshd[1569]: Disconnected from invalid user jenkins 10.32.4.5 port 48970 [preauth] Jun 23 01:35:59 prd-ubuntu1804-docker-4c-4g-3526 sshd[1571]: Invalid user jenkins from 10.32.4.5 port 48972 Jun 23 01:35:59 prd-ubuntu1804-docker-4c-4g-3526 sshd[1571]: Received disconnect from 10.32.4.5 port 48972:11: Closed due to user request. [preauth] Jun 23 01:35:59 prd-ubuntu1804-docker-4c-4g-3526 sshd[1571]: Disconnected from invalid user jenkins 10.32.4.5 port 48972 [preauth] Jun 23 01:36:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[1573]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 23 01:36:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[1573]: pam_unix(cron:session): session closed for user root Jun 23 01:36:01 prd-ubuntu1804-docker-4c-4g-3526 sshd[1581]: Invalid user jenkins from 10.32.4.5 port 48974 Jun 23 01:36:01 prd-ubuntu1804-docker-4c-4g-3526 sshd[1581]: Received disconnect from 10.32.4.5 port 48974:11: Closed due to user request. [preauth] Jun 23 01:36:01 prd-ubuntu1804-docker-4c-4g-3526 sshd[1581]: Disconnected from invalid user jenkins 10.32.4.5 port 48974 [preauth] Jun 23 01:36:03 prd-ubuntu1804-docker-4c-4g-3526 sshd[1583]: Invalid user jenkins from 10.32.4.5 port 48978 Jun 23 01:36:03 prd-ubuntu1804-docker-4c-4g-3526 sshd[1583]: Received disconnect from 10.32.4.5 port 48978:11: Closed due to user request. [preauth] Jun 23 01:36:03 prd-ubuntu1804-docker-4c-4g-3526 sshd[1583]: Disconnected from invalid user jenkins 10.32.4.5 port 48978 [preauth] Jun 23 01:36:05 prd-ubuntu1804-docker-4c-4g-3526 sshd[1585]: Invalid user jenkins from 10.32.4.5 port 48982 Jun 23 01:36:05 prd-ubuntu1804-docker-4c-4g-3526 sshd[1585]: Received disconnect from 10.32.4.5 port 48982:11: Closed due to user request. [preauth] Jun 23 01:36:05 prd-ubuntu1804-docker-4c-4g-3526 sshd[1585]: Disconnected from invalid user jenkins 10.32.4.5 port 48982 [preauth] Jun 23 01:36:08 prd-ubuntu1804-docker-4c-4g-3526 sshd[1587]: Invalid user jenkins from 10.32.4.5 port 48986 Jun 23 01:36:08 prd-ubuntu1804-docker-4c-4g-3526 sshd[1587]: Received disconnect from 10.32.4.5 port 48986:11: Closed due to user request. [preauth] Jun 23 01:36:08 prd-ubuntu1804-docker-4c-4g-3526 sshd[1587]: Disconnected from invalid user jenkins 10.32.4.5 port 48986 [preauth] Jun 23 01:36:10 prd-ubuntu1804-docker-4c-4g-3526 sshd[1720]: Invalid user jenkins from 10.32.4.5 port 48988 Jun 23 01:36:10 prd-ubuntu1804-docker-4c-4g-3526 sshd[1720]: Received disconnect from 10.32.4.5 port 48988:11: Closed due to user request. [preauth] Jun 23 01:36:10 prd-ubuntu1804-docker-4c-4g-3526 sshd[1720]: Disconnected from invalid user jenkins 10.32.4.5 port 48988 [preauth] Jun 23 01:36:12 prd-ubuntu1804-docker-4c-4g-3526 sshd[1825]: Invalid user jenkins from 10.32.4.5 port 48996 Jun 23 01:36:12 prd-ubuntu1804-docker-4c-4g-3526 sshd[1825]: Received disconnect from 10.32.4.5 port 48996:11: Closed due to user request. [preauth] Jun 23 01:36:12 prd-ubuntu1804-docker-4c-4g-3526 sshd[1825]: Disconnected from invalid user jenkins 10.32.4.5 port 48996 [preauth] Jun 23 01:36:15 prd-ubuntu1804-docker-4c-4g-3526 sshd[1864]: Invalid user jenkins from 10.32.4.5 port 48998 Jun 23 01:36:15 prd-ubuntu1804-docker-4c-4g-3526 sshd[1864]: Received disconnect from 10.32.4.5 port 48998:11: Closed due to user request. [preauth] Jun 23 01:36:15 prd-ubuntu1804-docker-4c-4g-3526 sshd[1864]: Disconnected from invalid user jenkins 10.32.4.5 port 48998 [preauth] Jun 23 01:36:17 prd-ubuntu1804-docker-4c-4g-3526 sshd[1868]: Invalid user jenkins from 10.32.4.5 port 49000 Jun 23 01:36:17 prd-ubuntu1804-docker-4c-4g-3526 sshd[1868]: Received disconnect from 10.32.4.5 port 49000:11: Closed due to user request. [preauth] Jun 23 01:36:17 prd-ubuntu1804-docker-4c-4g-3526 sshd[1868]: Disconnected from invalid user jenkins 10.32.4.5 port 49000 [preauth] Jun 23 01:36:19 prd-ubuntu1804-docker-4c-4g-3526 useradd[1895]: new group: name=jenkins, GID=1001 Jun 23 01:36:19 prd-ubuntu1804-docker-4c-4g-3526 useradd[1895]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Jun 23 01:36:19 prd-ubuntu1804-docker-4c-4g-3526 usermod[1902]: add 'jenkins' to group 'docker' Jun 23 01:36:19 prd-ubuntu1804-docker-4c-4g-3526 usermod[1902]: add 'jenkins' to shadow group 'docker' Jun 23 01:36:19 prd-ubuntu1804-docker-4c-4g-3526 sshd[1913]: Accepted publickey for jenkins from 10.32.4.5 port 49004 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Jun 23 01:36:19 prd-ubuntu1804-docker-4c-4g-3526 sshd[1913]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jun 23 01:36:19 prd-ubuntu1804-docker-4c-4g-3526 systemd-logind[1077]: New session 2 of user jenkins. Jun 23 01:36:19 prd-ubuntu1804-docker-4c-4g-3526 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jun 23 01:37:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[2463]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 23 01:37:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[2463]: pam_unix(cron:session): session closed for user root Jun 23 01:38:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[2508]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 23 01:38:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[2508]: pam_unix(cron:session): session closed for user root Jun 23 01:39:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[2918]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 23 01:39:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[2918]: pam_unix(cron:session): session closed for user root Jun 23 01:40:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[10387]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 23 01:40:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[10387]: pam_unix(cron:session): session closed for user root Jun 23 01:41:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[14593]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 23 01:41:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[14593]: pam_unix(cron:session): session closed for user root Jun 23 01:42:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[15798]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 23 01:42:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[15798]: pam_unix(cron:session): session closed for user root Jun 23 01:43:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[16346]: pam_unix(cron:session): session opened for user root by (uid=0) Jun 23 01:43:01 prd-ubuntu1804-docker-4c-4g-3526 CRON[16346]: pam_unix(cron:session): session closed for user root Jun 23 01:43:04 prd-ubuntu1804-docker-4c-4g-3526 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-plt-alarm-go-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Jun 23 01:43:04 prd-ubuntu1804-docker-4c-4g-3526 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)