Dec 8 01:35:48 prd-ubuntu1804-docker-4c-4g-11221 passwd[946]: password for 'ubuntu' changed by 'root' Dec 8 01:35:48 prd-ubuntu1804-docker-4c-4g-11221 sshd[1115]: Server listening on 0.0.0.0 port 22. Dec 8 01:35:48 prd-ubuntu1804-docker-4c-4g-11221 sshd[1115]: Server listening on :: port 22. Dec 8 01:35:48 prd-ubuntu1804-docker-4c-4g-11221 systemd-logind[1080]: Watching system buttons on /dev/input/event0 (Power Button) Dec 8 01:35:48 prd-ubuntu1804-docker-4c-4g-11221 systemd-logind[1080]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Dec 8 01:35:48 prd-ubuntu1804-docker-4c-4g-11221 systemd-logind[1080]: New seat seat0. Dec 8 01:35:49 prd-ubuntu1804-docker-4c-4g-11221 sshd[1414]: Did not receive identification string from 10.32.4.5 port 37012 Dec 8 01:35:56 prd-ubuntu1804-docker-4c-4g-11221 sshd[1513]: Invalid user jenkins from 10.32.4.5 port 37016 Dec 8 01:35:56 prd-ubuntu1804-docker-4c-4g-11221 sshd[1513]: Received disconnect from 10.32.4.5 port 37016:11: Closed due to user request. [preauth] Dec 8 01:35:56 prd-ubuntu1804-docker-4c-4g-11221 sshd[1513]: Disconnected from invalid user jenkins 10.32.4.5 port 37016 [preauth] Dec 8 01:35:58 prd-ubuntu1804-docker-4c-4g-11221 sshd[1517]: Invalid user jenkins from 10.32.4.5 port 37018 Dec 8 01:35:58 prd-ubuntu1804-docker-4c-4g-11221 sshd[1517]: Received disconnect from 10.32.4.5 port 37018:11: Closed due to user request. [preauth] Dec 8 01:35:58 prd-ubuntu1804-docker-4c-4g-11221 sshd[1517]: Disconnected from invalid user jenkins 10.32.4.5 port 37018 [preauth] Dec 8 01:36:00 prd-ubuntu1804-docker-4c-4g-11221 sshd[1519]: Invalid user jenkins from 10.32.4.5 port 37026 Dec 8 01:36:00 prd-ubuntu1804-docker-4c-4g-11221 sshd[1519]: Received disconnect from 10.32.4.5 port 37026:11: Closed due to user request. [preauth] Dec 8 01:36:00 prd-ubuntu1804-docker-4c-4g-11221 sshd[1519]: Disconnected from invalid user jenkins 10.32.4.5 port 37026 [preauth] Dec 8 01:36:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[1521]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 8 01:36:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[1521]: pam_unix(cron:session): session closed for user root Dec 8 01:36:02 prd-ubuntu1804-docker-4c-4g-11221 sshd[1529]: Invalid user jenkins from 10.32.4.5 port 37028 Dec 8 01:36:02 prd-ubuntu1804-docker-4c-4g-11221 sshd[1529]: Received disconnect from 10.32.4.5 port 37028:11: Closed due to user request. [preauth] Dec 8 01:36:02 prd-ubuntu1804-docker-4c-4g-11221 sshd[1529]: Disconnected from invalid user jenkins 10.32.4.5 port 37028 [preauth] Dec 8 01:36:04 prd-ubuntu1804-docker-4c-4g-11221 sshd[1549]: Invalid user jenkins from 10.32.4.5 port 37030 Dec 8 01:36:04 prd-ubuntu1804-docker-4c-4g-11221 sshd[1549]: Received disconnect from 10.32.4.5 port 37030:11: Closed due to user request. [preauth] Dec 8 01:36:04 prd-ubuntu1804-docker-4c-4g-11221 sshd[1549]: Disconnected from invalid user jenkins 10.32.4.5 port 37030 [preauth] Dec 8 01:36:06 prd-ubuntu1804-docker-4c-4g-11221 sshd[1551]: Invalid user jenkins from 10.32.4.5 port 37032 Dec 8 01:36:06 prd-ubuntu1804-docker-4c-4g-11221 sshd[1551]: Received disconnect from 10.32.4.5 port 37032:11: Closed due to user request. [preauth] Dec 8 01:36:06 prd-ubuntu1804-docker-4c-4g-11221 sshd[1551]: Disconnected from invalid user jenkins 10.32.4.5 port 37032 [preauth] Dec 8 01:36:08 prd-ubuntu1804-docker-4c-4g-11221 sshd[1560]: Invalid user jenkins from 10.32.4.5 port 37036 Dec 8 01:36:08 prd-ubuntu1804-docker-4c-4g-11221 sshd[1560]: Received disconnect from 10.32.4.5 port 37036:11: Closed due to user request. [preauth] Dec 8 01:36:08 prd-ubuntu1804-docker-4c-4g-11221 sshd[1560]: Disconnected from invalid user jenkins 10.32.4.5 port 37036 [preauth] Dec 8 01:36:10 prd-ubuntu1804-docker-4c-4g-11221 sshd[1761]: Invalid user jenkins from 10.32.4.5 port 37038 Dec 8 01:36:11 prd-ubuntu1804-docker-4c-4g-11221 sshd[1761]: Received disconnect from 10.32.4.5 port 37038:11: Closed due to user request. [preauth] Dec 8 01:36:11 prd-ubuntu1804-docker-4c-4g-11221 sshd[1761]: Disconnected from invalid user jenkins 10.32.4.5 port 37038 [preauth] Dec 8 01:36:13 prd-ubuntu1804-docker-4c-4g-11221 sshd[1814]: Invalid user jenkins from 10.32.4.5 port 37042 Dec 8 01:36:13 prd-ubuntu1804-docker-4c-4g-11221 sshd[1814]: Received disconnect from 10.32.4.5 port 37042:11: Closed due to user request. [preauth] Dec 8 01:36:13 prd-ubuntu1804-docker-4c-4g-11221 sshd[1814]: Disconnected from invalid user jenkins 10.32.4.5 port 37042 [preauth] Dec 8 01:36:15 prd-ubuntu1804-docker-4c-4g-11221 sshd[1833]: Invalid user jenkins from 10.32.4.5 port 37044 Dec 8 01:36:15 prd-ubuntu1804-docker-4c-4g-11221 sshd[1833]: Received disconnect from 10.32.4.5 port 37044:11: Closed due to user request. [preauth] Dec 8 01:36:15 prd-ubuntu1804-docker-4c-4g-11221 sshd[1833]: Disconnected from invalid user jenkins 10.32.4.5 port 37044 [preauth] Dec 8 01:36:17 prd-ubuntu1804-docker-4c-4g-11221 sshd[1837]: Invalid user jenkins from 10.32.4.5 port 37046 Dec 8 01:36:17 prd-ubuntu1804-docker-4c-4g-11221 sshd[1837]: Received disconnect from 10.32.4.5 port 37046:11: Closed due to user request. [preauth] Dec 8 01:36:17 prd-ubuntu1804-docker-4c-4g-11221 sshd[1837]: Disconnected from invalid user jenkins 10.32.4.5 port 37046 [preauth] Dec 8 01:36:18 prd-ubuntu1804-docker-4c-4g-11221 useradd[1864]: new group: name=jenkins, GID=1001 Dec 8 01:36:18 prd-ubuntu1804-docker-4c-4g-11221 useradd[1864]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Dec 8 01:36:18 prd-ubuntu1804-docker-4c-4g-11221 usermod[1871]: add 'jenkins' to group 'docker' Dec 8 01:36:18 prd-ubuntu1804-docker-4c-4g-11221 usermod[1871]: add 'jenkins' to shadow group 'docker' Dec 8 01:36:19 prd-ubuntu1804-docker-4c-4g-11221 sshd[1905]: Accepted publickey for jenkins from 10.32.4.5 port 37050 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Dec 8 01:36:19 prd-ubuntu1804-docker-4c-4g-11221 sshd[1905]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Dec 8 01:36:19 prd-ubuntu1804-docker-4c-4g-11221 systemd-logind[1080]: New session 2 of user jenkins. Dec 8 01:36:19 prd-ubuntu1804-docker-4c-4g-11221 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Dec 8 01:37:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[2427]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 8 01:37:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[2427]: pam_unix(cron:session): session closed for user root Dec 8 01:38:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[2462]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 8 01:38:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[2462]: pam_unix(cron:session): session closed for user root Dec 8 01:39:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[2878]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 8 01:39:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[2878]: pam_unix(cron:session): session closed for user root Dec 8 01:40:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[9620]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 8 01:40:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[9620]: pam_unix(cron:session): session closed for user root Dec 8 01:41:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[13869]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 8 01:41:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[13869]: pam_unix(cron:session): session closed for user root Dec 8 01:42:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[15883]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 8 01:42:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[15883]: pam_unix(cron:session): session closed for user root Dec 8 01:43:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[16454]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 8 01:43:01 prd-ubuntu1804-docker-4c-4g-11221 CRON[16454]: pam_unix(cron:session): session closed for user root Dec 8 01:43:18 prd-ubuntu1804-docker-4c-4g-11221 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-plt-alarm-go-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Dec 8 01:43:18 prd-ubuntu1804-docker-4c-4g-11221 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)