Oct 29 20:21:47 prd-ubuntu1804-docker-4c-4g-7686 passwd[957]: password for 'ubuntu' changed by 'root' Oct 29 20:21:47 prd-ubuntu1804-docker-4c-4g-7686 systemd-logind[1013]: Watching system buttons on /dev/input/event0 (Power Button) Oct 29 20:21:47 prd-ubuntu1804-docker-4c-4g-7686 systemd-logind[1013]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Oct 29 20:21:47 prd-ubuntu1804-docker-4c-4g-7686 systemd-logind[1013]: New seat seat0. Oct 29 20:21:48 prd-ubuntu1804-docker-4c-4g-7686 sshd[1137]: Server listening on 0.0.0.0 port 22. Oct 29 20:21:48 prd-ubuntu1804-docker-4c-4g-7686 sshd[1137]: Server listening on :: port 22. Oct 29 20:21:50 prd-ubuntu1804-docker-4c-4g-7686 sshd[1475]: Did not receive identification string from 10.32.4.5 port 55712 Oct 29 20:21:55 prd-ubuntu1804-docker-4c-4g-7686 sshd[1538]: Invalid user jenkins from 10.32.4.5 port 55716 Oct 29 20:21:56 prd-ubuntu1804-docker-4c-4g-7686 sshd[1538]: Received disconnect from 10.32.4.5 port 55716:11: Closed due to user request. [preauth] Oct 29 20:21:56 prd-ubuntu1804-docker-4c-4g-7686 sshd[1538]: Disconnected from invalid user jenkins 10.32.4.5 port 55716 [preauth] Oct 29 20:21:58 prd-ubuntu1804-docker-4c-4g-7686 sshd[1542]: Invalid user jenkins from 10.32.4.5 port 55718 Oct 29 20:21:58 prd-ubuntu1804-docker-4c-4g-7686 sshd[1542]: Received disconnect from 10.32.4.5 port 55718:11: Closed due to user request. [preauth] Oct 29 20:21:58 prd-ubuntu1804-docker-4c-4g-7686 sshd[1542]: Disconnected from invalid user jenkins 10.32.4.5 port 55718 [preauth] Oct 29 20:22:00 prd-ubuntu1804-docker-4c-4g-7686 sshd[1544]: Invalid user jenkins from 10.32.4.5 port 55726 Oct 29 20:22:00 prd-ubuntu1804-docker-4c-4g-7686 sshd[1544]: Received disconnect from 10.32.4.5 port 55726:11: Closed due to user request. [preauth] Oct 29 20:22:00 prd-ubuntu1804-docker-4c-4g-7686 sshd[1544]: Disconnected from invalid user jenkins 10.32.4.5 port 55726 [preauth] Oct 29 20:22:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[1547]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 29 20:22:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[1547]: pam_unix(cron:session): session closed for user root Oct 29 20:22:02 prd-ubuntu1804-docker-4c-4g-7686 sshd[1554]: Invalid user jenkins from 10.32.4.5 port 55728 Oct 29 20:22:02 prd-ubuntu1804-docker-4c-4g-7686 sshd[1554]: Received disconnect from 10.32.4.5 port 55728:11: Closed due to user request. [preauth] Oct 29 20:22:02 prd-ubuntu1804-docker-4c-4g-7686 sshd[1554]: Disconnected from invalid user jenkins 10.32.4.5 port 55728 [preauth] Oct 29 20:22:04 prd-ubuntu1804-docker-4c-4g-7686 sshd[1556]: Invalid user jenkins from 10.32.4.5 port 55730 Oct 29 20:22:04 prd-ubuntu1804-docker-4c-4g-7686 sshd[1556]: Received disconnect from 10.32.4.5 port 55730:11: Closed due to user request. [preauth] Oct 29 20:22:04 prd-ubuntu1804-docker-4c-4g-7686 sshd[1556]: Disconnected from invalid user jenkins 10.32.4.5 port 55730 [preauth] Oct 29 20:22:06 prd-ubuntu1804-docker-4c-4g-7686 sshd[1558]: Invalid user jenkins from 10.32.4.5 port 55732 Oct 29 20:22:06 prd-ubuntu1804-docker-4c-4g-7686 sshd[1558]: Received disconnect from 10.32.4.5 port 55732:11: Closed due to user request. [preauth] Oct 29 20:22:06 prd-ubuntu1804-docker-4c-4g-7686 sshd[1558]: Disconnected from invalid user jenkins 10.32.4.5 port 55732 [preauth] Oct 29 20:22:08 prd-ubuntu1804-docker-4c-4g-7686 sshd[1560]: Invalid user jenkins from 10.32.4.5 port 55736 Oct 29 20:22:08 prd-ubuntu1804-docker-4c-4g-7686 sshd[1560]: Received disconnect from 10.32.4.5 port 55736:11: Closed due to user request. [preauth] Oct 29 20:22:08 prd-ubuntu1804-docker-4c-4g-7686 sshd[1560]: Disconnected from invalid user jenkins 10.32.4.5 port 55736 [preauth] Oct 29 20:22:11 prd-ubuntu1804-docker-4c-4g-7686 sshd[1663]: Invalid user jenkins from 10.32.4.5 port 55738 Oct 29 20:22:11 prd-ubuntu1804-docker-4c-4g-7686 sshd[1663]: Received disconnect from 10.32.4.5 port 55738:11: Closed due to user request. [preauth] Oct 29 20:22:11 prd-ubuntu1804-docker-4c-4g-7686 sshd[1663]: Disconnected from invalid user jenkins 10.32.4.5 port 55738 [preauth] Oct 29 20:22:13 prd-ubuntu1804-docker-4c-4g-7686 sshd[1804]: Invalid user jenkins from 10.32.4.5 port 55740 Oct 29 20:22:13 prd-ubuntu1804-docker-4c-4g-7686 sshd[1804]: Received disconnect from 10.32.4.5 port 55740:11: Closed due to user request. [preauth] Oct 29 20:22:13 prd-ubuntu1804-docker-4c-4g-7686 sshd[1804]: Disconnected from invalid user jenkins 10.32.4.5 port 55740 [preauth] Oct 29 20:22:16 prd-ubuntu1804-docker-4c-4g-7686 sshd[1844]: Invalid user jenkins from 10.32.4.5 port 55742 Oct 29 20:22:16 prd-ubuntu1804-docker-4c-4g-7686 sshd[1844]: Received disconnect from 10.32.4.5 port 55742:11: Closed due to user request. [preauth] Oct 29 20:22:16 prd-ubuntu1804-docker-4c-4g-7686 sshd[1844]: Disconnected from invalid user jenkins 10.32.4.5 port 55742 [preauth] Oct 29 20:22:18 prd-ubuntu1804-docker-4c-4g-7686 sshd[1872]: Invalid user jenkins from 10.32.4.5 port 55744 Oct 29 20:22:18 prd-ubuntu1804-docker-4c-4g-7686 sshd[1872]: Received disconnect from 10.32.4.5 port 55744:11: Closed due to user request. [preauth] Oct 29 20:22:18 prd-ubuntu1804-docker-4c-4g-7686 sshd[1872]: Disconnected from invalid user jenkins 10.32.4.5 port 55744 [preauth] Oct 29 20:22:20 prd-ubuntu1804-docker-4c-4g-7686 useradd[1899]: new group: name=jenkins, GID=1001 Oct 29 20:22:20 prd-ubuntu1804-docker-4c-4g-7686 useradd[1899]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Oct 29 20:22:20 prd-ubuntu1804-docker-4c-4g-7686 usermod[1906]: add 'jenkins' to group 'docker' Oct 29 20:22:20 prd-ubuntu1804-docker-4c-4g-7686 usermod[1906]: add 'jenkins' to shadow group 'docker' Oct 29 20:22:20 prd-ubuntu1804-docker-4c-4g-7686 sshd[1907]: Accepted publickey for jenkins from 10.32.4.5 port 55746 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Oct 29 20:22:20 prd-ubuntu1804-docker-4c-4g-7686 sshd[1907]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Oct 29 20:22:20 prd-ubuntu1804-docker-4c-4g-7686 systemd-logind[1013]: New session 2 of user jenkins. Oct 29 20:22:20 prd-ubuntu1804-docker-4c-4g-7686 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Oct 29 20:23:02 prd-ubuntu1804-docker-4c-4g-7686 CRON[2473]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 29 20:23:02 prd-ubuntu1804-docker-4c-4g-7686 CRON[2473]: pam_unix(cron:session): session closed for user root Oct 29 20:24:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[2513]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 29 20:24:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[2513]: pam_unix(cron:session): session closed for user root Oct 29 20:25:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[8197]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 29 20:25:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[8197]: pam_unix(cron:session): session closed for user root Oct 29 20:26:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[14535]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 29 20:26:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[14535]: pam_unix(cron:session): session closed for user root Oct 29 20:27:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[18283]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 29 20:27:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[18283]: pam_unix(cron:session): session closed for user root Oct 29 20:28:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[21075]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 29 20:28:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[21075]: pam_unix(cron:session): session closed for user root Oct 29 20:29:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[25951]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 29 20:29:01 prd-ubuntu1804-docker-4c-4g-7686 CRON[25951]: pam_unix(cron:session): session closed for user root Oct 29 20:29:39 prd-ubuntu1804-docker-4c-4g-7686 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-plt-ricdms-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Oct 29 20:29:39 prd-ubuntu1804-docker-4c-4g-7686 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)