Jul 30 20:21:46 prd-ubuntu1804-docker-4c-4g-1713 passwd[956]: password for 'ubuntu' changed by 'root' Jul 30 20:21:46 prd-ubuntu1804-docker-4c-4g-1713 systemd-logind[1028]: Watching system buttons on /dev/input/event0 (Power Button) Jul 30 20:21:46 prd-ubuntu1804-docker-4c-4g-1713 systemd-logind[1028]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jul 30 20:21:46 prd-ubuntu1804-docker-4c-4g-1713 systemd-logind[1028]: New seat seat0. Jul 30 20:21:46 prd-ubuntu1804-docker-4c-4g-1713 sshd[1103]: Server listening on 0.0.0.0 port 22. Jul 30 20:21:46 prd-ubuntu1804-docker-4c-4g-1713 sshd[1103]: Server listening on :: port 22. Jul 30 20:21:50 prd-ubuntu1804-docker-4c-4g-1713 sshd[1423]: Did not receive identification string from 10.32.4.5 port 37412 Jul 30 20:21:53 prd-ubuntu1804-docker-4c-4g-1713 sshd[1470]: Invalid user jenkins from 10.32.4.5 port 37416 Jul 30 20:21:53 prd-ubuntu1804-docker-4c-4g-1713 sshd[1470]: Received disconnect from 10.32.4.5 port 37416:11: Closed due to user request. [preauth] Jul 30 20:21:53 prd-ubuntu1804-docker-4c-4g-1713 sshd[1470]: Disconnected from invalid user jenkins 10.32.4.5 port 37416 [preauth] Jul 30 20:21:55 prd-ubuntu1804-docker-4c-4g-1713 sshd[1480]: Invalid user jenkins from 10.32.4.5 port 37418 Jul 30 20:21:55 prd-ubuntu1804-docker-4c-4g-1713 sshd[1480]: Received disconnect from 10.32.4.5 port 37418:11: Closed due to user request. [preauth] Jul 30 20:21:55 prd-ubuntu1804-docker-4c-4g-1713 sshd[1480]: Disconnected from invalid user jenkins 10.32.4.5 port 37418 [preauth] Jul 30 20:21:57 prd-ubuntu1804-docker-4c-4g-1713 sshd[1482]: Invalid user jenkins from 10.32.4.5 port 37420 Jul 30 20:21:58 prd-ubuntu1804-docker-4c-4g-1713 sshd[1482]: Received disconnect from 10.32.4.5 port 37420:11: Closed due to user request. [preauth] Jul 30 20:21:58 prd-ubuntu1804-docker-4c-4g-1713 sshd[1482]: Disconnected from invalid user jenkins 10.32.4.5 port 37420 [preauth] Jul 30 20:22:00 prd-ubuntu1804-docker-4c-4g-1713 sshd[1484]: Invalid user jenkins from 10.32.4.5 port 37428 Jul 30 20:22:00 prd-ubuntu1804-docker-4c-4g-1713 sshd[1484]: Received disconnect from 10.32.4.5 port 37428:11: Closed due to user request. [preauth] Jul 30 20:22:00 prd-ubuntu1804-docker-4c-4g-1713 sshd[1484]: Disconnected from invalid user jenkins 10.32.4.5 port 37428 [preauth] Jul 30 20:22:02 prd-ubuntu1804-docker-4c-4g-1713 CRON[1487]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 30 20:22:02 prd-ubuntu1804-docker-4c-4g-1713 CRON[1487]: pam_unix(cron:session): session closed for user root Jul 30 20:22:02 prd-ubuntu1804-docker-4c-4g-1713 sshd[1495]: Invalid user jenkins from 10.32.4.5 port 37430 Jul 30 20:22:02 prd-ubuntu1804-docker-4c-4g-1713 sshd[1495]: Received disconnect from 10.32.4.5 port 37430:11: Closed due to user request. [preauth] Jul 30 20:22:02 prd-ubuntu1804-docker-4c-4g-1713 sshd[1495]: Disconnected from invalid user jenkins 10.32.4.5 port 37430 [preauth] Jul 30 20:22:04 prd-ubuntu1804-docker-4c-4g-1713 sshd[1497]: Invalid user jenkins from 10.32.4.5 port 37432 Jul 30 20:22:04 prd-ubuntu1804-docker-4c-4g-1713 sshd[1497]: Received disconnect from 10.32.4.5 port 37432:11: Closed due to user request. [preauth] Jul 30 20:22:04 prd-ubuntu1804-docker-4c-4g-1713 sshd[1497]: Disconnected from invalid user jenkins 10.32.4.5 port 37432 [preauth] Jul 30 20:22:06 prd-ubuntu1804-docker-4c-4g-1713 sshd[1499]: Invalid user jenkins from 10.32.4.5 port 37434 Jul 30 20:22:06 prd-ubuntu1804-docker-4c-4g-1713 sshd[1499]: Received disconnect from 10.32.4.5 port 37434:11: Closed due to user request. [preauth] Jul 30 20:22:06 prd-ubuntu1804-docker-4c-4g-1713 sshd[1499]: Disconnected from invalid user jenkins 10.32.4.5 port 37434 [preauth] Jul 30 20:22:08 prd-ubuntu1804-docker-4c-4g-1713 sshd[1538]: Invalid user jenkins from 10.32.4.5 port 37438 Jul 30 20:22:08 prd-ubuntu1804-docker-4c-4g-1713 sshd[1538]: Received disconnect from 10.32.4.5 port 37438:11: Closed due to user request. [preauth] Jul 30 20:22:08 prd-ubuntu1804-docker-4c-4g-1713 sshd[1538]: Disconnected from invalid user jenkins 10.32.4.5 port 37438 [preauth] Jul 30 20:22:10 prd-ubuntu1804-docker-4c-4g-1713 sshd[1735]: Invalid user jenkins from 10.32.4.5 port 37440 Jul 30 20:22:10 prd-ubuntu1804-docker-4c-4g-1713 sshd[1735]: Received disconnect from 10.32.4.5 port 37440:11: Closed due to user request. [preauth] Jul 30 20:22:10 prd-ubuntu1804-docker-4c-4g-1713 sshd[1735]: Disconnected from invalid user jenkins 10.32.4.5 port 37440 [preauth] Jul 30 20:22:12 prd-ubuntu1804-docker-4c-4g-1713 sshd[1775]: Invalid user jenkins from 10.32.4.5 port 37442 Jul 30 20:22:12 prd-ubuntu1804-docker-4c-4g-1713 sshd[1775]: Received disconnect from 10.32.4.5 port 37442:11: Closed due to user request. [preauth] Jul 30 20:22:12 prd-ubuntu1804-docker-4c-4g-1713 sshd[1775]: Disconnected from invalid user jenkins 10.32.4.5 port 37442 [preauth] Jul 30 20:22:15 prd-ubuntu1804-docker-4c-4g-1713 sshd[1779]: Invalid user jenkins from 10.32.4.5 port 37444 Jul 30 20:22:15 prd-ubuntu1804-docker-4c-4g-1713 sshd[1779]: Received disconnect from 10.32.4.5 port 37444:11: Closed due to user request. [preauth] Jul 30 20:22:15 prd-ubuntu1804-docker-4c-4g-1713 sshd[1779]: Disconnected from invalid user jenkins 10.32.4.5 port 37444 [preauth] Jul 30 20:22:16 prd-ubuntu1804-docker-4c-4g-1713 useradd[1795]: new group: name=jenkins, GID=1001 Jul 30 20:22:16 prd-ubuntu1804-docker-4c-4g-1713 useradd[1795]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Jul 30 20:22:16 prd-ubuntu1804-docker-4c-4g-1713 usermod[1802]: add 'jenkins' to group 'docker' Jul 30 20:22:16 prd-ubuntu1804-docker-4c-4g-1713 usermod[1802]: add 'jenkins' to shadow group 'docker' Jul 30 20:22:17 prd-ubuntu1804-docker-4c-4g-1713 sshd[1843]: Accepted publickey for jenkins from 10.32.4.5 port 37446 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Jul 30 20:22:17 prd-ubuntu1804-docker-4c-4g-1713 sshd[1843]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jul 30 20:22:17 prd-ubuntu1804-docker-4c-4g-1713 systemd-logind[1028]: New session 2 of user jenkins. Jul 30 20:22:17 prd-ubuntu1804-docker-4c-4g-1713 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jul 30 20:23:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[2383]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 30 20:23:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[2383]: pam_unix(cron:session): session closed for user root Jul 30 20:24:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[2419]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 30 20:24:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[2419]: pam_unix(cron:session): session closed for user root Jul 30 20:25:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[8130]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 30 20:25:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[8130]: pam_unix(cron:session): session closed for user root Jul 30 20:26:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[14668]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 30 20:26:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[14668]: pam_unix(cron:session): session closed for user root Jul 30 20:27:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[18474]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 30 20:27:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[18474]: pam_unix(cron:session): session closed for user root Jul 30 20:28:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[21018]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 30 20:28:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[21018]: pam_unix(cron:session): session closed for user root Jul 30 20:29:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[25692]: pam_unix(cron:session): session opened for user root by (uid=0) Jul 30 20:29:01 prd-ubuntu1804-docker-4c-4g-1713 CRON[25692]: pam_unix(cron:session): session closed for user root Jul 30 20:29:52 prd-ubuntu1804-docker-4c-4g-1713 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-plt-ricdms-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Jul 30 20:29:52 prd-ubuntu1804-docker-4c-4g-1713 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)