Sep 24 20:21:47 prd-ubuntu1804-docker-4c-4g-4568 passwd[942]: password for 'ubuntu' changed by 'root' Sep 24 20:21:47 prd-ubuntu1804-docker-4c-4g-4568 systemd-logind[997]: Watching system buttons on /dev/input/event0 (Power Button) Sep 24 20:21:47 prd-ubuntu1804-docker-4c-4g-4568 systemd-logind[997]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Sep 24 20:21:47 prd-ubuntu1804-docker-4c-4g-4568 systemd-logind[997]: New seat seat0. Sep 24 20:21:47 prd-ubuntu1804-docker-4c-4g-4568 sshd[1275]: Server listening on 0.0.0.0 port 22. Sep 24 20:21:47 prd-ubuntu1804-docker-4c-4g-4568 sshd[1275]: Server listening on :: port 22. Sep 24 20:21:51 prd-ubuntu1804-docker-4c-4g-4568 sshd[1486]: Did not receive identification string from 10.32.4.5 port 37082 Sep 24 20:21:55 prd-ubuntu1804-docker-4c-4g-4568 sshd[1544]: Invalid user jenkins from 10.32.4.5 port 37086 Sep 24 20:21:55 prd-ubuntu1804-docker-4c-4g-4568 sshd[1544]: Received disconnect from 10.32.4.5 port 37086:11: Closed due to user request. [preauth] Sep 24 20:21:55 prd-ubuntu1804-docker-4c-4g-4568 sshd[1544]: Disconnected from invalid user jenkins 10.32.4.5 port 37086 [preauth] Sep 24 20:21:57 prd-ubuntu1804-docker-4c-4g-4568 sshd[1548]: Invalid user jenkins from 10.32.4.5 port 37088 Sep 24 20:21:58 prd-ubuntu1804-docker-4c-4g-4568 sshd[1548]: Received disconnect from 10.32.4.5 port 37088:11: Closed due to user request. [preauth] Sep 24 20:21:58 prd-ubuntu1804-docker-4c-4g-4568 sshd[1548]: Disconnected from invalid user jenkins 10.32.4.5 port 37088 [preauth] Sep 24 20:22:00 prd-ubuntu1804-docker-4c-4g-4568 sshd[1550]: Invalid user jenkins from 10.32.4.5 port 37096 Sep 24 20:22:00 prd-ubuntu1804-docker-4c-4g-4568 sshd[1550]: Received disconnect from 10.32.4.5 port 37096:11: Closed due to user request. [preauth] Sep 24 20:22:00 prd-ubuntu1804-docker-4c-4g-4568 sshd[1550]: Disconnected from invalid user jenkins 10.32.4.5 port 37096 [preauth] Sep 24 20:22:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[1553]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 24 20:22:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[1553]: pam_unix(cron:session): session closed for user root Sep 24 20:22:02 prd-ubuntu1804-docker-4c-4g-4568 sshd[1561]: Invalid user jenkins from 10.32.4.5 port 37098 Sep 24 20:22:02 prd-ubuntu1804-docker-4c-4g-4568 sshd[1561]: Received disconnect from 10.32.4.5 port 37098:11: Closed due to user request. [preauth] Sep 24 20:22:02 prd-ubuntu1804-docker-4c-4g-4568 sshd[1561]: Disconnected from invalid user jenkins 10.32.4.5 port 37098 [preauth] Sep 24 20:22:04 prd-ubuntu1804-docker-4c-4g-4568 sshd[1563]: Invalid user jenkins from 10.32.4.5 port 37100 Sep 24 20:22:04 prd-ubuntu1804-docker-4c-4g-4568 sshd[1563]: Received disconnect from 10.32.4.5 port 37100:11: Closed due to user request. [preauth] Sep 24 20:22:04 prd-ubuntu1804-docker-4c-4g-4568 sshd[1563]: Disconnected from invalid user jenkins 10.32.4.5 port 37100 [preauth] Sep 24 20:22:06 prd-ubuntu1804-docker-4c-4g-4568 sshd[1565]: Invalid user jenkins from 10.32.4.5 port 37102 Sep 24 20:22:06 prd-ubuntu1804-docker-4c-4g-4568 sshd[1565]: Received disconnect from 10.32.4.5 port 37102:11: Closed due to user request. [preauth] Sep 24 20:22:06 prd-ubuntu1804-docker-4c-4g-4568 sshd[1565]: Disconnected from invalid user jenkins 10.32.4.5 port 37102 [preauth] Sep 24 20:22:08 prd-ubuntu1804-docker-4c-4g-4568 sshd[1567]: Invalid user jenkins from 10.32.4.5 port 37108 Sep 24 20:22:08 prd-ubuntu1804-docker-4c-4g-4568 sshd[1567]: Received disconnect from 10.32.4.5 port 37108:11: Closed due to user request. [preauth] Sep 24 20:22:08 prd-ubuntu1804-docker-4c-4g-4568 sshd[1567]: Disconnected from invalid user jenkins 10.32.4.5 port 37108 [preauth] Sep 24 20:22:11 prd-ubuntu1804-docker-4c-4g-4568 sshd[1733]: Invalid user jenkins from 10.32.4.5 port 37110 Sep 24 20:22:11 prd-ubuntu1804-docker-4c-4g-4568 sshd[1733]: Received disconnect from 10.32.4.5 port 37110:11: Closed due to user request. [preauth] Sep 24 20:22:11 prd-ubuntu1804-docker-4c-4g-4568 sshd[1733]: Disconnected from invalid user jenkins 10.32.4.5 port 37110 [preauth] Sep 24 20:22:13 prd-ubuntu1804-docker-4c-4g-4568 sshd[1807]: Invalid user jenkins from 10.32.4.5 port 37112 Sep 24 20:22:13 prd-ubuntu1804-docker-4c-4g-4568 sshd[1807]: Received disconnect from 10.32.4.5 port 37112:11: Closed due to user request. [preauth] Sep 24 20:22:13 prd-ubuntu1804-docker-4c-4g-4568 sshd[1807]: Disconnected from invalid user jenkins 10.32.4.5 port 37112 [preauth] Sep 24 20:22:15 prd-ubuntu1804-docker-4c-4g-4568 sshd[1841]: Invalid user jenkins from 10.32.4.5 port 37114 Sep 24 20:22:15 prd-ubuntu1804-docker-4c-4g-4568 sshd[1841]: Received disconnect from 10.32.4.5 port 37114:11: Closed due to user request. [preauth] Sep 24 20:22:15 prd-ubuntu1804-docker-4c-4g-4568 sshd[1841]: Disconnected from invalid user jenkins 10.32.4.5 port 37114 [preauth] Sep 24 20:22:17 prd-ubuntu1804-docker-4c-4g-4568 sshd[1845]: Invalid user jenkins from 10.32.4.5 port 37116 Sep 24 20:22:17 prd-ubuntu1804-docker-4c-4g-4568 sshd[1845]: Received disconnect from 10.32.4.5 port 37116:11: Closed due to user request. [preauth] Sep 24 20:22:17 prd-ubuntu1804-docker-4c-4g-4568 sshd[1845]: Disconnected from invalid user jenkins 10.32.4.5 port 37116 [preauth] Sep 24 20:22:19 prd-ubuntu1804-docker-4c-4g-4568 useradd[1861]: new group: name=jenkins, GID=1001 Sep 24 20:22:19 prd-ubuntu1804-docker-4c-4g-4568 useradd[1861]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Sep 24 20:22:19 prd-ubuntu1804-docker-4c-4g-4568 usermod[1868]: add 'jenkins' to group 'docker' Sep 24 20:22:19 prd-ubuntu1804-docker-4c-4g-4568 usermod[1868]: add 'jenkins' to shadow group 'docker' Sep 24 20:22:20 prd-ubuntu1804-docker-4c-4g-4568 sshd[1913]: Accepted publickey for jenkins from 10.32.4.5 port 37118 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Sep 24 20:22:20 prd-ubuntu1804-docker-4c-4g-4568 sshd[1913]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Sep 24 20:22:20 prd-ubuntu1804-docker-4c-4g-4568 systemd-logind[997]: New session 2 of user jenkins. Sep 24 20:22:20 prd-ubuntu1804-docker-4c-4g-4568 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Sep 24 20:23:02 prd-ubuntu1804-docker-4c-4g-4568 CRON[2429]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 24 20:23:02 prd-ubuntu1804-docker-4c-4g-4568 CRON[2429]: pam_unix(cron:session): session closed for user root Sep 24 20:24:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[2481]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 24 20:24:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[2481]: pam_unix(cron:session): session closed for user root Sep 24 20:25:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[8171]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 24 20:25:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[8171]: pam_unix(cron:session): session closed for user root Sep 24 20:26:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[14685]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 24 20:26:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[14685]: pam_unix(cron:session): session closed for user root Sep 24 20:27:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[18886]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 24 20:27:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[18886]: pam_unix(cron:session): session closed for user root Sep 24 20:28:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[21726]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 24 20:28:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[21726]: pam_unix(cron:session): session closed for user root Sep 24 20:29:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[25900]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 24 20:29:01 prd-ubuntu1804-docker-4c-4g-4568 CRON[25900]: pam_unix(cron:session): session closed for user root Sep 24 20:29:35 prd-ubuntu1804-docker-4c-4g-4568 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-plt-ricdms-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Sep 24 20:29:35 prd-ubuntu1804-docker-4c-4g-4568 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)