Oct 27 01:35:56 prd-ubuntu1804-docker-4c-4g-7490 passwd[976]: password for 'ubuntu' changed by 'root' Oct 27 01:35:56 prd-ubuntu1804-docker-4c-4g-7490 systemd-logind[1058]: Watching system buttons on /dev/input/event0 (Power Button) Oct 27 01:35:56 prd-ubuntu1804-docker-4c-4g-7490 systemd-logind[1058]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Oct 27 01:35:56 prd-ubuntu1804-docker-4c-4g-7490 systemd-logind[1058]: New seat seat0. Oct 27 01:35:56 prd-ubuntu1804-docker-4c-4g-7490 sshd[1234]: Server listening on 0.0.0.0 port 22. Oct 27 01:35:56 prd-ubuntu1804-docker-4c-4g-7490 sshd[1234]: Server listening on :: port 22. Oct 27 01:36:00 prd-ubuntu1804-docker-4c-4g-7490 sshd[1465]: Did not receive identification string from 10.32.4.5 port 34190 Oct 27 01:36:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[1486]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 27 01:36:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[1486]: pam_unix(cron:session): session closed for user root Oct 27 01:36:06 prd-ubuntu1804-docker-4c-4g-7490 sshd[1525]: Invalid user jenkins from 10.32.4.5 port 34192 Oct 27 01:36:06 prd-ubuntu1804-docker-4c-4g-7490 sshd[1525]: Received disconnect from 10.32.4.5 port 34192:11: Closed due to user request. [preauth] Oct 27 01:36:06 prd-ubuntu1804-docker-4c-4g-7490 sshd[1525]: Disconnected from invalid user jenkins 10.32.4.5 port 34192 [preauth] Oct 27 01:36:08 prd-ubuntu1804-docker-4c-4g-7490 sshd[1529]: Invalid user jenkins from 10.32.4.5 port 34196 Oct 27 01:36:08 prd-ubuntu1804-docker-4c-4g-7490 sshd[1529]: Received disconnect from 10.32.4.5 port 34196:11: Closed due to user request. [preauth] Oct 27 01:36:08 prd-ubuntu1804-docker-4c-4g-7490 sshd[1529]: Disconnected from invalid user jenkins 10.32.4.5 port 34196 [preauth] Oct 27 01:36:11 prd-ubuntu1804-docker-4c-4g-7490 sshd[1531]: Invalid user jenkins from 10.32.4.5 port 34198 Oct 27 01:36:11 prd-ubuntu1804-docker-4c-4g-7490 sshd[1531]: Received disconnect from 10.32.4.5 port 34198:11: Closed due to user request. [preauth] Oct 27 01:36:11 prd-ubuntu1804-docker-4c-4g-7490 sshd[1531]: Disconnected from invalid user jenkins 10.32.4.5 port 34198 [preauth] Oct 27 01:36:13 prd-ubuntu1804-docker-4c-4g-7490 sshd[1533]: Invalid user jenkins from 10.32.4.5 port 34200 Oct 27 01:36:13 prd-ubuntu1804-docker-4c-4g-7490 sshd[1533]: Received disconnect from 10.32.4.5 port 34200:11: Closed due to user request. [preauth] Oct 27 01:36:13 prd-ubuntu1804-docker-4c-4g-7490 sshd[1533]: Disconnected from invalid user jenkins 10.32.4.5 port 34200 [preauth] Oct 27 01:36:15 prd-ubuntu1804-docker-4c-4g-7490 sshd[1544]: Invalid user jenkins from 10.32.4.5 port 34202 Oct 27 01:36:15 prd-ubuntu1804-docker-4c-4g-7490 sshd[1544]: Received disconnect from 10.32.4.5 port 34202:11: Closed due to user request. [preauth] Oct 27 01:36:15 prd-ubuntu1804-docker-4c-4g-7490 sshd[1544]: Disconnected from invalid user jenkins 10.32.4.5 port 34202 [preauth] Oct 27 01:36:17 prd-ubuntu1804-docker-4c-4g-7490 sshd[1546]: Invalid user jenkins from 10.32.4.5 port 34206 Oct 27 01:36:17 prd-ubuntu1804-docker-4c-4g-7490 sshd[1546]: Received disconnect from 10.32.4.5 port 34206:11: Closed due to user request. [preauth] Oct 27 01:36:17 prd-ubuntu1804-docker-4c-4g-7490 sshd[1546]: Disconnected from invalid user jenkins 10.32.4.5 port 34206 [preauth] Oct 27 01:36:19 prd-ubuntu1804-docker-4c-4g-7490 sshd[1750]: Invalid user jenkins from 10.32.4.5 port 34208 Oct 27 01:36:19 prd-ubuntu1804-docker-4c-4g-7490 sshd[1750]: Received disconnect from 10.32.4.5 port 34208:11: Closed due to user request. [preauth] Oct 27 01:36:19 prd-ubuntu1804-docker-4c-4g-7490 sshd[1750]: Disconnected from invalid user jenkins 10.32.4.5 port 34208 [preauth] Oct 27 01:36:21 prd-ubuntu1804-docker-4c-4g-7490 sshd[1788]: Invalid user jenkins from 10.32.4.5 port 34210 Oct 27 01:36:21 prd-ubuntu1804-docker-4c-4g-7490 sshd[1788]: Received disconnect from 10.32.4.5 port 34210:11: Closed due to user request. [preauth] Oct 27 01:36:21 prd-ubuntu1804-docker-4c-4g-7490 sshd[1788]: Disconnected from invalid user jenkins 10.32.4.5 port 34210 [preauth] Oct 27 01:36:24 prd-ubuntu1804-docker-4c-4g-7490 sshd[1822]: Invalid user jenkins from 10.32.4.5 port 34214 Oct 27 01:36:24 prd-ubuntu1804-docker-4c-4g-7490 sshd[1822]: Received disconnect from 10.32.4.5 port 34214:11: Closed due to user request. [preauth] Oct 27 01:36:24 prd-ubuntu1804-docker-4c-4g-7490 sshd[1822]: Disconnected from invalid user jenkins 10.32.4.5 port 34214 [preauth] Oct 27 01:36:26 prd-ubuntu1804-docker-4c-4g-7490 sshd[1826]: Invalid user jenkins from 10.32.4.5 port 34216 Oct 27 01:36:26 prd-ubuntu1804-docker-4c-4g-7490 sshd[1826]: Received disconnect from 10.32.4.5 port 34216:11: Closed due to user request. [preauth] Oct 27 01:36:26 prd-ubuntu1804-docker-4c-4g-7490 sshd[1826]: Disconnected from invalid user jenkins 10.32.4.5 port 34216 [preauth] Oct 27 01:36:28 prd-ubuntu1804-docker-4c-4g-7490 useradd[1852]: new group: name=jenkins, GID=1001 Oct 27 01:36:28 prd-ubuntu1804-docker-4c-4g-7490 useradd[1852]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Oct 27 01:36:28 prd-ubuntu1804-docker-4c-4g-7490 sshd[1853]: Invalid user jenkins from 10.32.4.5 port 34218 Oct 27 01:36:28 prd-ubuntu1804-docker-4c-4g-7490 sshd[1853]: Received disconnect from 10.32.4.5 port 34218:11: Closed due to user request. [preauth] Oct 27 01:36:28 prd-ubuntu1804-docker-4c-4g-7490 sshd[1853]: Disconnected from invalid user jenkins 10.32.4.5 port 34218 [preauth] Oct 27 01:36:28 prd-ubuntu1804-docker-4c-4g-7490 usermod[1871]: add 'jenkins' to group 'docker' Oct 27 01:36:28 prd-ubuntu1804-docker-4c-4g-7490 usermod[1871]: add 'jenkins' to shadow group 'docker' Oct 27 01:36:30 prd-ubuntu1804-docker-4c-4g-7490 sshd[1912]: Accepted publickey for jenkins from 10.32.4.5 port 34226 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Oct 27 01:36:30 prd-ubuntu1804-docker-4c-4g-7490 sshd[1912]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Oct 27 01:36:30 prd-ubuntu1804-docker-4c-4g-7490 systemd-logind[1058]: New session 2 of user jenkins. Oct 27 01:36:30 prd-ubuntu1804-docker-4c-4g-7490 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Oct 27 01:37:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[2412]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 27 01:37:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[2412]: pam_unix(cron:session): session closed for user root Oct 27 01:38:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[2463]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 27 01:38:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[2463]: pam_unix(cron:session): session closed for user root Oct 27 01:39:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[2887]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 27 01:39:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[2887]: pam_unix(cron:session): session closed for user root Oct 27 01:40:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[9160]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 27 01:40:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[9160]: pam_unix(cron:session): session closed for user root Oct 27 01:41:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[12648]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 27 01:41:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[12648]: pam_unix(cron:session): session closed for user root Oct 27 01:42:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[15785]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 27 01:42:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[15785]: pam_unix(cron:session): session closed for user root Oct 27 01:43:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[16189]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 27 01:43:01 prd-ubuntu1804-docker-4c-4g-7490 CRON[16189]: pam_unix(cron:session): session closed for user root Oct 27 01:43:36 prd-ubuntu1804-docker-4c-4g-7490 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-plt-alarm-go-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Oct 27 01:43:36 prd-ubuntu1804-docker-4c-4g-7490 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)