Aug 9 01:40:49 prd-ubuntu1804-docker-4c-4g-496 passwd[921]: password for 'ubuntu' changed by 'root' Aug 9 01:40:49 prd-ubuntu1804-docker-4c-4g-496 systemd-logind[993]: Watching system buttons on /dev/input/event0 (Power Button) Aug 9 01:40:49 prd-ubuntu1804-docker-4c-4g-496 systemd-logind[993]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Aug 9 01:40:49 prd-ubuntu1804-docker-4c-4g-496 systemd-logind[993]: New seat seat0. Aug 9 01:40:49 prd-ubuntu1804-docker-4c-4g-496 sshd[1217]: Server listening on 0.0.0.0 port 22. Aug 9 01:40:49 prd-ubuntu1804-docker-4c-4g-496 sshd[1217]: Server listening on :: port 22. Aug 9 01:40:50 prd-ubuntu1804-docker-4c-4g-496 sshd[1257]: Did not receive identification string from 10.32.4.5 port 47634 Aug 9 01:40:56 prd-ubuntu1804-docker-4c-4g-496 sshd[1483]: Invalid user jenkins from 10.32.4.5 port 47638 Aug 9 01:40:56 prd-ubuntu1804-docker-4c-4g-496 sshd[1483]: Received disconnect from 10.32.4.5 port 47638:11: Closed due to user request. [preauth] Aug 9 01:40:56 prd-ubuntu1804-docker-4c-4g-496 sshd[1483]: Disconnected from invalid user jenkins 10.32.4.5 port 47638 [preauth] Aug 9 01:40:58 prd-ubuntu1804-docker-4c-4g-496 sshd[1501]: Invalid user jenkins from 10.32.4.5 port 47640 Aug 9 01:40:58 prd-ubuntu1804-docker-4c-4g-496 sshd[1501]: Received disconnect from 10.32.4.5 port 47640:11: Closed due to user request. [preauth] Aug 9 01:40:58 prd-ubuntu1804-docker-4c-4g-496 sshd[1501]: Disconnected from invalid user jenkins 10.32.4.5 port 47640 [preauth] Aug 9 01:41:00 prd-ubuntu1804-docker-4c-4g-496 sshd[1503]: Invalid user jenkins from 10.32.4.5 port 47648 Aug 9 01:41:00 prd-ubuntu1804-docker-4c-4g-496 sshd[1503]: Received disconnect from 10.32.4.5 port 47648:11: Closed due to user request. [preauth] Aug 9 01:41:00 prd-ubuntu1804-docker-4c-4g-496 sshd[1503]: Disconnected from invalid user jenkins 10.32.4.5 port 47648 [preauth] Aug 9 01:41:01 prd-ubuntu1804-docker-4c-4g-496 CRON[1506]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 9 01:41:01 prd-ubuntu1804-docker-4c-4g-496 CRON[1506]: pam_unix(cron:session): session closed for user root Aug 9 01:41:02 prd-ubuntu1804-docker-4c-4g-496 sshd[1513]: Invalid user jenkins from 10.32.4.5 port 47650 Aug 9 01:41:02 prd-ubuntu1804-docker-4c-4g-496 sshd[1513]: Received disconnect from 10.32.4.5 port 47650:11: Closed due to user request. [preauth] Aug 9 01:41:02 prd-ubuntu1804-docker-4c-4g-496 sshd[1513]: Disconnected from invalid user jenkins 10.32.4.5 port 47650 [preauth] Aug 9 01:41:04 prd-ubuntu1804-docker-4c-4g-496 sshd[1515]: Invalid user jenkins from 10.32.4.5 port 47652 Aug 9 01:41:04 prd-ubuntu1804-docker-4c-4g-496 sshd[1515]: Received disconnect from 10.32.4.5 port 47652:11: Closed due to user request. [preauth] Aug 9 01:41:04 prd-ubuntu1804-docker-4c-4g-496 sshd[1515]: Disconnected from invalid user jenkins 10.32.4.5 port 47652 [preauth] Aug 9 01:41:07 prd-ubuntu1804-docker-4c-4g-496 sshd[1517]: Invalid user jenkins from 10.32.4.5 port 47654 Aug 9 01:41:07 prd-ubuntu1804-docker-4c-4g-496 sshd[1517]: Received disconnect from 10.32.4.5 port 47654:11: Closed due to user request. [preauth] Aug 9 01:41:07 prd-ubuntu1804-docker-4c-4g-496 sshd[1517]: Disconnected from invalid user jenkins 10.32.4.5 port 47654 [preauth] Aug 9 01:41:09 prd-ubuntu1804-docker-4c-4g-496 sshd[1519]: Invalid user jenkins from 10.32.4.5 port 47658 Aug 9 01:41:09 prd-ubuntu1804-docker-4c-4g-496 sshd[1519]: Received disconnect from 10.32.4.5 port 47658:11: Closed due to user request. [preauth] Aug 9 01:41:09 prd-ubuntu1804-docker-4c-4g-496 sshd[1519]: Disconnected from invalid user jenkins 10.32.4.5 port 47658 [preauth] Aug 9 01:41:11 prd-ubuntu1804-docker-4c-4g-496 sshd[1536]: Invalid user jenkins from 10.32.4.5 port 47660 Aug 9 01:41:11 prd-ubuntu1804-docker-4c-4g-496 sshd[1536]: Received disconnect from 10.32.4.5 port 47660:11: Closed due to user request. [preauth] Aug 9 01:41:11 prd-ubuntu1804-docker-4c-4g-496 sshd[1536]: Disconnected from invalid user jenkins 10.32.4.5 port 47660 [preauth] Aug 9 01:41:13 prd-ubuntu1804-docker-4c-4g-496 sshd[1743]: Invalid user jenkins from 10.32.4.5 port 47662 Aug 9 01:41:13 prd-ubuntu1804-docker-4c-4g-496 sshd[1743]: Received disconnect from 10.32.4.5 port 47662:11: Closed due to user request. [preauth] Aug 9 01:41:13 prd-ubuntu1804-docker-4c-4g-496 sshd[1743]: Disconnected from invalid user jenkins 10.32.4.5 port 47662 [preauth] Aug 9 01:41:15 prd-ubuntu1804-docker-4c-4g-496 sshd[1781]: Invalid user jenkins from 10.32.4.5 port 47664 Aug 9 01:41:15 prd-ubuntu1804-docker-4c-4g-496 sshd[1781]: Received disconnect from 10.32.4.5 port 47664:11: Closed due to user request. [preauth] Aug 9 01:41:15 prd-ubuntu1804-docker-4c-4g-496 sshd[1781]: Disconnected from invalid user jenkins 10.32.4.5 port 47664 [preauth] Aug 9 01:41:17 prd-ubuntu1804-docker-4c-4g-496 sshd[1799]: Invalid user jenkins from 10.32.4.5 port 47666 Aug 9 01:41:17 prd-ubuntu1804-docker-4c-4g-496 sshd[1799]: Received disconnect from 10.32.4.5 port 47666:11: Closed due to user request. [preauth] Aug 9 01:41:17 prd-ubuntu1804-docker-4c-4g-496 sshd[1799]: Disconnected from invalid user jenkins 10.32.4.5 port 47666 [preauth] Aug 9 01:41:20 prd-ubuntu1804-docker-4c-4g-496 sshd[1809]: Invalid user jenkins from 10.32.4.5 port 47668 Aug 9 01:41:20 prd-ubuntu1804-docker-4c-4g-496 sshd[1809]: Received disconnect from 10.32.4.5 port 47668:11: Closed due to user request. [preauth] Aug 9 01:41:20 prd-ubuntu1804-docker-4c-4g-496 sshd[1809]: Disconnected from invalid user jenkins 10.32.4.5 port 47668 [preauth] Aug 9 01:41:20 prd-ubuntu1804-docker-4c-4g-496 useradd[1832]: new group: name=jenkins, GID=1001 Aug 9 01:41:20 prd-ubuntu1804-docker-4c-4g-496 useradd[1832]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Aug 9 01:41:20 prd-ubuntu1804-docker-4c-4g-496 usermod[1839]: add 'jenkins' to group 'docker' Aug 9 01:41:20 prd-ubuntu1804-docker-4c-4g-496 usermod[1839]: add 'jenkins' to shadow group 'docker' Aug 9 01:41:22 prd-ubuntu1804-docker-4c-4g-496 sshd[1885]: Accepted publickey for jenkins from 10.32.4.5 port 47670 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Aug 9 01:41:22 prd-ubuntu1804-docker-4c-4g-496 sshd[1885]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Aug 9 01:41:22 prd-ubuntu1804-docker-4c-4g-496 systemd-logind[993]: New session 2 of user jenkins. Aug 9 01:41:22 prd-ubuntu1804-docker-4c-4g-496 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Aug 9 01:42:01 prd-ubuntu1804-docker-4c-4g-496 CRON[2383]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 9 01:42:01 prd-ubuntu1804-docker-4c-4g-496 CRON[2383]: pam_unix(cron:session): session closed for user root Aug 9 01:43:01 prd-ubuntu1804-docker-4c-4g-496 CRON[2441]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 9 01:43:01 prd-ubuntu1804-docker-4c-4g-496 CRON[2441]: pam_unix(cron:session): session closed for user root Aug 9 01:44:01 prd-ubuntu1804-docker-4c-4g-496 CRON[6118]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 9 01:44:01 prd-ubuntu1804-docker-4c-4g-496 CRON[6118]: pam_unix(cron:session): session closed for user root Aug 9 01:45:02 prd-ubuntu1804-docker-4c-4g-496 CRON[12795]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 9 01:45:02 prd-ubuntu1804-docker-4c-4g-496 CRON[12795]: pam_unix(cron:session): session closed for user root Aug 9 01:46:01 prd-ubuntu1804-docker-4c-4g-496 CRON[14891]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 9 01:46:01 prd-ubuntu1804-docker-4c-4g-496 CRON[14891]: pam_unix(cron:session): session closed for user root Aug 9 01:47:01 prd-ubuntu1804-docker-4c-4g-496 CRON[15979]: pam_unix(cron:session): session opened for user root by (uid=0) Aug 9 01:47:01 prd-ubuntu1804-docker-4c-4g-496 CRON[15979]: pam_unix(cron:session): session closed for user root Aug 9 01:47:29 prd-ubuntu1804-docker-4c-4g-496 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-plt-e2mgr-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Aug 9 01:47:29 prd-ubuntu1804-docker-4c-4g-496 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)