Sep 25 11:31:49 prd-ubuntu1804-docker-4c-4g-4670 passwd[978]: password for 'ubuntu' changed by 'root' Sep 25 11:31:49 prd-ubuntu1804-docker-4c-4g-4670 systemd-logind[1138]: Watching system buttons on /dev/input/event0 (Power Button) Sep 25 11:31:49 prd-ubuntu1804-docker-4c-4g-4670 systemd-logind[1138]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Sep 25 11:31:49 prd-ubuntu1804-docker-4c-4g-4670 systemd-logind[1138]: New seat seat0. Sep 25 11:31:49 prd-ubuntu1804-docker-4c-4g-4670 sshd[1283]: Server listening on 0.0.0.0 port 22. Sep 25 11:31:49 prd-ubuntu1804-docker-4c-4g-4670 sshd[1283]: Server listening on :: port 22. Sep 25 11:31:53 prd-ubuntu1804-docker-4c-4g-4670 sshd[1519]: Did not receive identification string from 10.32.4.5 port 53830 Sep 25 11:31:57 prd-ubuntu1804-docker-4c-4g-4670 sshd[1555]: Invalid user jenkins from 10.32.4.5 port 53844 Sep 25 11:31:57 prd-ubuntu1804-docker-4c-4g-4670 sshd[1555]: Received disconnect from 10.32.4.5 port 53844:11: Closed due to user request. [preauth] Sep 25 11:31:57 prd-ubuntu1804-docker-4c-4g-4670 sshd[1555]: Disconnected from invalid user jenkins 10.32.4.5 port 53844 [preauth] Sep 25 11:31:59 prd-ubuntu1804-docker-4c-4g-4670 sshd[1562]: Invalid user jenkins from 10.32.4.5 port 53858 Sep 25 11:31:59 prd-ubuntu1804-docker-4c-4g-4670 sshd[1562]: Received disconnect from 10.32.4.5 port 53858:11: Closed due to user request. [preauth] Sep 25 11:31:59 prd-ubuntu1804-docker-4c-4g-4670 sshd[1562]: Disconnected from invalid user jenkins 10.32.4.5 port 53858 [preauth] Sep 25 11:32:01 prd-ubuntu1804-docker-4c-4g-4670 sshd[1564]: Invalid user jenkins from 10.32.4.5 port 53878 Sep 25 11:32:01 prd-ubuntu1804-docker-4c-4g-4670 sshd[1564]: Received disconnect from 10.32.4.5 port 53878:11: Closed due to user request. [preauth] Sep 25 11:32:01 prd-ubuntu1804-docker-4c-4g-4670 sshd[1564]: Disconnected from invalid user jenkins 10.32.4.5 port 53878 [preauth] Sep 25 11:32:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[1566]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 25 11:32:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[1566]: pam_unix(cron:session): session closed for user root Sep 25 11:32:03 prd-ubuntu1804-docker-4c-4g-4670 sshd[1576]: Invalid user jenkins from 10.32.4.5 port 53890 Sep 25 11:32:03 prd-ubuntu1804-docker-4c-4g-4670 sshd[1576]: Received disconnect from 10.32.4.5 port 53890:11: Closed due to user request. [preauth] Sep 25 11:32:03 prd-ubuntu1804-docker-4c-4g-4670 sshd[1576]: Disconnected from invalid user jenkins 10.32.4.5 port 53890 [preauth] Sep 25 11:32:06 prd-ubuntu1804-docker-4c-4g-4670 sshd[1578]: Invalid user jenkins from 10.32.4.5 port 53904 Sep 25 11:32:06 prd-ubuntu1804-docker-4c-4g-4670 sshd[1578]: Received disconnect from 10.32.4.5 port 53904:11: Closed due to user request. [preauth] Sep 25 11:32:06 prd-ubuntu1804-docker-4c-4g-4670 sshd[1578]: Disconnected from invalid user jenkins 10.32.4.5 port 53904 [preauth] Sep 25 11:32:08 prd-ubuntu1804-docker-4c-4g-4670 sshd[1580]: Invalid user jenkins from 10.32.4.5 port 53918 Sep 25 11:32:08 prd-ubuntu1804-docker-4c-4g-4670 sshd[1580]: Received disconnect from 10.32.4.5 port 53918:11: Closed due to user request. [preauth] Sep 25 11:32:08 prd-ubuntu1804-docker-4c-4g-4670 sshd[1580]: Disconnected from invalid user jenkins 10.32.4.5 port 53918 [preauth] Sep 25 11:32:10 prd-ubuntu1804-docker-4c-4g-4670 sshd[1601]: Invalid user jenkins from 10.32.4.5 port 53932 Sep 25 11:32:10 prd-ubuntu1804-docker-4c-4g-4670 sshd[1601]: Received disconnect from 10.32.4.5 port 53932:11: Closed due to user request. [preauth] Sep 25 11:32:10 prd-ubuntu1804-docker-4c-4g-4670 sshd[1601]: Disconnected from invalid user jenkins 10.32.4.5 port 53932 [preauth] Sep 25 11:32:12 prd-ubuntu1804-docker-4c-4g-4670 sshd[1788]: Invalid user jenkins from 10.32.4.5 port 53948 Sep 25 11:32:12 prd-ubuntu1804-docker-4c-4g-4670 sshd[1788]: Received disconnect from 10.32.4.5 port 53948:11: Closed due to user request. [preauth] Sep 25 11:32:12 prd-ubuntu1804-docker-4c-4g-4670 sshd[1788]: Disconnected from invalid user jenkins 10.32.4.5 port 53948 [preauth] Sep 25 11:32:14 prd-ubuntu1804-docker-4c-4g-4670 sshd[1841]: Invalid user jenkins from 10.32.4.5 port 53964 Sep 25 11:32:14 prd-ubuntu1804-docker-4c-4g-4670 sshd[1841]: Received disconnect from 10.32.4.5 port 53964:11: Closed due to user request. [preauth] Sep 25 11:32:14 prd-ubuntu1804-docker-4c-4g-4670 sshd[1841]: Disconnected from invalid user jenkins 10.32.4.5 port 53964 [preauth] Sep 25 11:32:16 prd-ubuntu1804-docker-4c-4g-4670 sshd[1860]: Invalid user jenkins from 10.32.4.5 port 53976 Sep 25 11:32:16 prd-ubuntu1804-docker-4c-4g-4670 sshd[1860]: Received disconnect from 10.32.4.5 port 53976:11: Closed due to user request. [preauth] Sep 25 11:32:16 prd-ubuntu1804-docker-4c-4g-4670 sshd[1860]: Disconnected from invalid user jenkins 10.32.4.5 port 53976 [preauth] Sep 25 11:32:18 prd-ubuntu1804-docker-4c-4g-4670 sshd[1864]: Invalid user jenkins from 10.32.4.5 port 53982 Sep 25 11:32:18 prd-ubuntu1804-docker-4c-4g-4670 sshd[1864]: Received disconnect from 10.32.4.5 port 53982:11: Closed due to user request. [preauth] Sep 25 11:32:18 prd-ubuntu1804-docker-4c-4g-4670 sshd[1864]: Disconnected from invalid user jenkins 10.32.4.5 port 53982 [preauth] Sep 25 11:32:20 prd-ubuntu1804-docker-4c-4g-4670 useradd[1892]: new group: name=jenkins, GID=1001 Sep 25 11:32:20 prd-ubuntu1804-docker-4c-4g-4670 useradd[1892]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Sep 25 11:32:20 prd-ubuntu1804-docker-4c-4g-4670 usermod[1899]: add 'jenkins' to group 'docker' Sep 25 11:32:20 prd-ubuntu1804-docker-4c-4g-4670 usermod[1899]: add 'jenkins' to shadow group 'docker' Sep 25 11:32:20 prd-ubuntu1804-docker-4c-4g-4670 sshd[1925]: Accepted publickey for jenkins from 10.32.4.5 port 53986 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Sep 25 11:32:20 prd-ubuntu1804-docker-4c-4g-4670 sshd[1925]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Sep 25 11:32:20 prd-ubuntu1804-docker-4c-4g-4670 systemd-logind[1138]: New session 2 of user jenkins. Sep 25 11:32:20 prd-ubuntu1804-docker-4c-4g-4670 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Sep 25 11:33:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[2466]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 25 11:33:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[2466]: pam_unix(cron:session): session closed for user root Sep 25 11:34:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[2514]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 25 11:34:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[2514]: pam_unix(cron:session): session closed for user root Sep 25 11:35:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[2805]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 25 11:35:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[2805]: pam_unix(cron:session): session closed for user root Sep 25 11:36:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[2927]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 25 11:36:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[2927]: pam_unix(cron:session): session closed for user root Sep 25 11:37:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[8199]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 25 11:37:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[8199]: pam_unix(cron:session): session closed for user root Sep 25 11:38:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[15246]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 25 11:38:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[15246]: pam_unix(cron:session): session closed for user root Sep 25 11:39:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[18284]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 25 11:39:01 prd-ubuntu1804-docker-4c-4g-4670 CRON[18284]: pam_unix(cron:session): session closed for user root Sep 25 11:39:43 prd-ubuntu1804-docker-4c-4g-4670 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-plt-appmgr-docker-verify-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Sep 25 11:39:43 prd-ubuntu1804-docker-4c-4g-4670 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)