Dec 1 01:35:48 prd-ubuntu1804-docker-4c-4g-10663 passwd[933]: password for 'ubuntu' changed by 'root' Dec 1 01:35:48 prd-ubuntu1804-docker-4c-4g-10663 systemd-logind[1056]: Watching system buttons on /dev/input/event0 (Power Button) Dec 1 01:35:48 prd-ubuntu1804-docker-4c-4g-10663 systemd-logind[1056]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Dec 1 01:35:48 prd-ubuntu1804-docker-4c-4g-10663 systemd-logind[1056]: New seat seat0. Dec 1 01:35:48 prd-ubuntu1804-docker-4c-4g-10663 sshd[1207]: Server listening on 0.0.0.0 port 22. Dec 1 01:35:48 prd-ubuntu1804-docker-4c-4g-10663 sshd[1207]: Server listening on :: port 22. Dec 1 01:35:52 prd-ubuntu1804-docker-4c-4g-10663 sshd[1446]: Did not receive identification string from 10.32.4.5 port 39262 Dec 1 01:35:56 prd-ubuntu1804-docker-4c-4g-10663 sshd[1496]: Invalid user jenkins from 10.32.4.5 port 39266 Dec 1 01:35:56 prd-ubuntu1804-docker-4c-4g-10663 sshd[1496]: Received disconnect from 10.32.4.5 port 39266:11: Closed due to user request. [preauth] Dec 1 01:35:56 prd-ubuntu1804-docker-4c-4g-10663 sshd[1496]: Disconnected from invalid user jenkins 10.32.4.5 port 39266 [preauth] Dec 1 01:35:58 prd-ubuntu1804-docker-4c-4g-10663 sshd[1500]: Invalid user jenkins from 10.32.4.5 port 39268 Dec 1 01:35:58 prd-ubuntu1804-docker-4c-4g-10663 sshd[1500]: Received disconnect from 10.32.4.5 port 39268:11: Closed due to user request. [preauth] Dec 1 01:35:58 prd-ubuntu1804-docker-4c-4g-10663 sshd[1500]: Disconnected from invalid user jenkins 10.32.4.5 port 39268 [preauth] Dec 1 01:36:00 prd-ubuntu1804-docker-4c-4g-10663 sshd[1502]: Invalid user jenkins from 10.32.4.5 port 39276 Dec 1 01:36:00 prd-ubuntu1804-docker-4c-4g-10663 sshd[1502]: Received disconnect from 10.32.4.5 port 39276:11: Closed due to user request. [preauth] Dec 1 01:36:00 prd-ubuntu1804-docker-4c-4g-10663 sshd[1502]: Disconnected from invalid user jenkins 10.32.4.5 port 39276 [preauth] Dec 1 01:36:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[1505]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 1 01:36:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[1505]: pam_unix(cron:session): session closed for user root Dec 1 01:36:02 prd-ubuntu1804-docker-4c-4g-10663 sshd[1512]: Invalid user jenkins from 10.32.4.5 port 39278 Dec 1 01:36:02 prd-ubuntu1804-docker-4c-4g-10663 sshd[1512]: Received disconnect from 10.32.4.5 port 39278:11: Closed due to user request. [preauth] Dec 1 01:36:02 prd-ubuntu1804-docker-4c-4g-10663 sshd[1512]: Disconnected from invalid user jenkins 10.32.4.5 port 39278 [preauth] Dec 1 01:36:05 prd-ubuntu1804-docker-4c-4g-10663 sshd[1514]: Invalid user jenkins from 10.32.4.5 port 39280 Dec 1 01:36:05 prd-ubuntu1804-docker-4c-4g-10663 sshd[1514]: Received disconnect from 10.32.4.5 port 39280:11: Closed due to user request. [preauth] Dec 1 01:36:05 prd-ubuntu1804-docker-4c-4g-10663 sshd[1514]: Disconnected from invalid user jenkins 10.32.4.5 port 39280 [preauth] Dec 1 01:36:07 prd-ubuntu1804-docker-4c-4g-10663 sshd[1516]: Invalid user jenkins from 10.32.4.5 port 39282 Dec 1 01:36:07 prd-ubuntu1804-docker-4c-4g-10663 sshd[1516]: Received disconnect from 10.32.4.5 port 39282:11: Closed due to user request. [preauth] Dec 1 01:36:07 prd-ubuntu1804-docker-4c-4g-10663 sshd[1516]: Disconnected from invalid user jenkins 10.32.4.5 port 39282 [preauth] Dec 1 01:36:09 prd-ubuntu1804-docker-4c-4g-10663 sshd[1518]: Invalid user jenkins from 10.32.4.5 port 39286 Dec 1 01:36:09 prd-ubuntu1804-docker-4c-4g-10663 sshd[1518]: Received disconnect from 10.32.4.5 port 39286:11: Closed due to user request. [preauth] Dec 1 01:36:09 prd-ubuntu1804-docker-4c-4g-10663 sshd[1518]: Disconnected from invalid user jenkins 10.32.4.5 port 39286 [preauth] Dec 1 01:36:11 prd-ubuntu1804-docker-4c-4g-10663 sshd[1647]: Invalid user jenkins from 10.32.4.5 port 39288 Dec 1 01:36:11 prd-ubuntu1804-docker-4c-4g-10663 sshd[1647]: Received disconnect from 10.32.4.5 port 39288:11: Closed due to user request. [preauth] Dec 1 01:36:11 prd-ubuntu1804-docker-4c-4g-10663 sshd[1647]: Disconnected from invalid user jenkins 10.32.4.5 port 39288 [preauth] Dec 1 01:36:13 prd-ubuntu1804-docker-4c-4g-10663 sshd[1761]: Invalid user jenkins from 10.32.4.5 port 39290 Dec 1 01:36:13 prd-ubuntu1804-docker-4c-4g-10663 sshd[1761]: Received disconnect from 10.32.4.5 port 39290:11: Closed due to user request. [preauth] Dec 1 01:36:13 prd-ubuntu1804-docker-4c-4g-10663 sshd[1761]: Disconnected from invalid user jenkins 10.32.4.5 port 39290 [preauth] Dec 1 01:36:15 prd-ubuntu1804-docker-4c-4g-10663 sshd[1795]: Invalid user jenkins from 10.32.4.5 port 39292 Dec 1 01:36:15 prd-ubuntu1804-docker-4c-4g-10663 sshd[1795]: Received disconnect from 10.32.4.5 port 39292:11: Closed due to user request. [preauth] Dec 1 01:36:15 prd-ubuntu1804-docker-4c-4g-10663 sshd[1795]: Disconnected from invalid user jenkins 10.32.4.5 port 39292 [preauth] Dec 1 01:36:17 prd-ubuntu1804-docker-4c-4g-10663 sshd[1799]: Invalid user jenkins from 10.32.4.5 port 39296 Dec 1 01:36:17 prd-ubuntu1804-docker-4c-4g-10663 sshd[1799]: Received disconnect from 10.32.4.5 port 39296:11: Closed due to user request. [preauth] Dec 1 01:36:17 prd-ubuntu1804-docker-4c-4g-10663 sshd[1799]: Disconnected from invalid user jenkins 10.32.4.5 port 39296 [preauth] Dec 1 01:36:18 prd-ubuntu1804-docker-4c-4g-10663 useradd[1815]: new group: name=jenkins, GID=1001 Dec 1 01:36:18 prd-ubuntu1804-docker-4c-4g-10663 useradd[1815]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Dec 1 01:36:18 prd-ubuntu1804-docker-4c-4g-10663 usermod[1822]: add 'jenkins' to group 'docker' Dec 1 01:36:18 prd-ubuntu1804-docker-4c-4g-10663 usermod[1822]: add 'jenkins' to shadow group 'docker' Dec 1 01:36:19 prd-ubuntu1804-docker-4c-4g-10663 sshd[1865]: Accepted publickey for jenkins from 10.32.4.5 port 39298 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Dec 1 01:36:19 prd-ubuntu1804-docker-4c-4g-10663 sshd[1865]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Dec 1 01:36:19 prd-ubuntu1804-docker-4c-4g-10663 systemd-logind[1056]: New session 2 of user jenkins. Dec 1 01:36:19 prd-ubuntu1804-docker-4c-4g-10663 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Dec 1 01:37:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[2391]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 1 01:37:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[2391]: pam_unix(cron:session): session closed for user root Dec 1 01:38:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[2429]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 1 01:38:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[2429]: pam_unix(cron:session): session closed for user root Dec 1 01:39:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[2847]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 1 01:39:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[2847]: pam_unix(cron:session): session closed for user root Dec 1 01:40:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[10231]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 1 01:40:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[10231]: pam_unix(cron:session): session closed for user root Dec 1 01:41:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[14600]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 1 01:41:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[14600]: pam_unix(cron:session): session closed for user root Dec 1 01:42:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[15822]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 1 01:42:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[15822]: pam_unix(cron:session): session closed for user root Dec 1 01:43:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[16387]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 1 01:43:01 prd-ubuntu1804-docker-4c-4g-10663 CRON[16387]: pam_unix(cron:session): session closed for user root Dec 1 01:43:06 prd-ubuntu1804-docker-4c-4g-10663 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-plt-alarm-go-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Dec 1 01:43:06 prd-ubuntu1804-docker-4c-4g-10663 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)