May 20 20:21:45 prd-ubuntu1804-docker-4c-4g-1369 passwd[946]: password for 'ubuntu' changed by 'root' May 20 20:21:45 prd-ubuntu1804-docker-4c-4g-1369 systemd-logind[977]: Watching system buttons on /dev/input/event0 (Power Button) May 20 20:21:45 prd-ubuntu1804-docker-4c-4g-1369 systemd-logind[977]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) May 20 20:21:45 prd-ubuntu1804-docker-4c-4g-1369 systemd-logind[977]: New seat seat0. May 20 20:21:46 prd-ubuntu1804-docker-4c-4g-1369 sshd[1261]: Server listening on 0.0.0.0 port 22. May 20 20:21:46 prd-ubuntu1804-docker-4c-4g-1369 sshd[1261]: Server listening on :: port 22. May 20 20:21:47 prd-ubuntu1804-docker-4c-4g-1369 sshd[1310]: Did not receive identification string from 10.32.4.5 port 43782 May 20 20:21:53 prd-ubuntu1804-docker-4c-4g-1369 sshd[1528]: Invalid user jenkins from 10.32.4.5 port 43784 May 20 20:21:53 prd-ubuntu1804-docker-4c-4g-1369 sshd[1528]: Received disconnect from 10.32.4.5 port 43784:11: Closed due to user request. [preauth] May 20 20:21:53 prd-ubuntu1804-docker-4c-4g-1369 sshd[1528]: Disconnected from invalid user jenkins 10.32.4.5 port 43784 [preauth] May 20 20:21:55 prd-ubuntu1804-docker-4c-4g-1369 sshd[1547]: Invalid user jenkins from 10.32.4.5 port 43786 May 20 20:21:55 prd-ubuntu1804-docker-4c-4g-1369 sshd[1547]: Received disconnect from 10.32.4.5 port 43786:11: Closed due to user request. [preauth] May 20 20:21:55 prd-ubuntu1804-docker-4c-4g-1369 sshd[1547]: Disconnected from invalid user jenkins 10.32.4.5 port 43786 [preauth] May 20 20:21:57 prd-ubuntu1804-docker-4c-4g-1369 sshd[1549]: Invalid user jenkins from 10.32.4.5 port 43788 May 20 20:21:57 prd-ubuntu1804-docker-4c-4g-1369 sshd[1549]: Received disconnect from 10.32.4.5 port 43788:11: Closed due to user request. [preauth] May 20 20:21:57 prd-ubuntu1804-docker-4c-4g-1369 sshd[1549]: Disconnected from invalid user jenkins 10.32.4.5 port 43788 [preauth] May 20 20:21:59 prd-ubuntu1804-docker-4c-4g-1369 sshd[1551]: Invalid user jenkins from 10.32.4.5 port 43790 May 20 20:21:59 prd-ubuntu1804-docker-4c-4g-1369 sshd[1551]: Received disconnect from 10.32.4.5 port 43790:11: Closed due to user request. [preauth] May 20 20:21:59 prd-ubuntu1804-docker-4c-4g-1369 sshd[1551]: Disconnected from invalid user jenkins 10.32.4.5 port 43790 [preauth] May 20 20:22:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[1553]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 20:22:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[1553]: pam_unix(cron:session): session closed for user root May 20 20:22:01 prd-ubuntu1804-docker-4c-4g-1369 sshd[1562]: Invalid user jenkins from 10.32.4.5 port 43794 May 20 20:22:01 prd-ubuntu1804-docker-4c-4g-1369 sshd[1562]: Received disconnect from 10.32.4.5 port 43794:11: Closed due to user request. [preauth] May 20 20:22:01 prd-ubuntu1804-docker-4c-4g-1369 sshd[1562]: Disconnected from invalid user jenkins 10.32.4.5 port 43794 [preauth] May 20 20:22:03 prd-ubuntu1804-docker-4c-4g-1369 sshd[1564]: Invalid user jenkins from 10.32.4.5 port 43796 May 20 20:22:03 prd-ubuntu1804-docker-4c-4g-1369 sshd[1564]: Received disconnect from 10.32.4.5 port 43796:11: Closed due to user request. [preauth] May 20 20:22:03 prd-ubuntu1804-docker-4c-4g-1369 sshd[1564]: Disconnected from invalid user jenkins 10.32.4.5 port 43796 [preauth] May 20 20:22:05 prd-ubuntu1804-docker-4c-4g-1369 sshd[1566]: Invalid user jenkins from 10.32.4.5 port 43798 May 20 20:22:05 prd-ubuntu1804-docker-4c-4g-1369 sshd[1566]: Received disconnect from 10.32.4.5 port 43798:11: Closed due to user request. [preauth] May 20 20:22:05 prd-ubuntu1804-docker-4c-4g-1369 sshd[1566]: Disconnected from invalid user jenkins 10.32.4.5 port 43798 [preauth] May 20 20:22:08 prd-ubuntu1804-docker-4c-4g-1369 sshd[1586]: Invalid user jenkins from 10.32.4.5 port 43800 May 20 20:22:08 prd-ubuntu1804-docker-4c-4g-1369 sshd[1586]: Received disconnect from 10.32.4.5 port 43800:11: Closed due to user request. [preauth] May 20 20:22:08 prd-ubuntu1804-docker-4c-4g-1369 sshd[1586]: Disconnected from invalid user jenkins 10.32.4.5 port 43800 [preauth] May 20 20:22:10 prd-ubuntu1804-docker-4c-4g-1369 sshd[1781]: Invalid user jenkins from 10.32.4.5 port 43802 May 20 20:22:10 prd-ubuntu1804-docker-4c-4g-1369 sshd[1781]: Received disconnect from 10.32.4.5 port 43802:11: Closed due to user request. [preauth] May 20 20:22:10 prd-ubuntu1804-docker-4c-4g-1369 sshd[1781]: Disconnected from invalid user jenkins 10.32.4.5 port 43802 [preauth] May 20 20:22:12 prd-ubuntu1804-docker-4c-4g-1369 sshd[1827]: Invalid user jenkins from 10.32.4.5 port 43804 May 20 20:22:12 prd-ubuntu1804-docker-4c-4g-1369 sshd[1827]: Received disconnect from 10.32.4.5 port 43804:11: Closed due to user request. [preauth] May 20 20:22:12 prd-ubuntu1804-docker-4c-4g-1369 sshd[1827]: Disconnected from invalid user jenkins 10.32.4.5 port 43804 [preauth] May 20 20:22:14 prd-ubuntu1804-docker-4c-4g-1369 sshd[1846]: Invalid user jenkins from 10.32.4.5 port 43806 May 20 20:22:14 prd-ubuntu1804-docker-4c-4g-1369 sshd[1846]: Received disconnect from 10.32.4.5 port 43806:11: Closed due to user request. [preauth] May 20 20:22:14 prd-ubuntu1804-docker-4c-4g-1369 sshd[1846]: Disconnected from invalid user jenkins 10.32.4.5 port 43806 [preauth] May 20 20:22:16 prd-ubuntu1804-docker-4c-4g-1369 useradd[1853]: new group: name=jenkins, GID=1001 May 20 20:22:16 prd-ubuntu1804-docker-4c-4g-1369 useradd[1853]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash May 20 20:22:16 prd-ubuntu1804-docker-4c-4g-1369 usermod[1860]: add 'jenkins' to group 'docker' May 20 20:22:16 prd-ubuntu1804-docker-4c-4g-1369 usermod[1860]: add 'jenkins' to shadow group 'docker' May 20 20:22:17 prd-ubuntu1804-docker-4c-4g-1369 sshd[1894]: Accepted publickey for jenkins from 10.32.4.5 port 43810 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI May 20 20:22:17 prd-ubuntu1804-docker-4c-4g-1369 sshd[1894]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) May 20 20:22:17 prd-ubuntu1804-docker-4c-4g-1369 systemd-logind[977]: New session 2 of user jenkins. May 20 20:22:17 prd-ubuntu1804-docker-4c-4g-1369 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) May 20 20:23:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[2436]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 20:23:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[2436]: pam_unix(cron:session): session closed for user root May 20 20:24:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[2745]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 20:24:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[2745]: pam_unix(cron:session): session closed for user root May 20 20:25:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[8154]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 20:25:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[8154]: pam_unix(cron:session): session closed for user root May 20 20:26:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[15346]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 20:26:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[15346]: pam_unix(cron:session): session closed for user root May 20 20:27:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[19176]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 20:27:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[19176]: pam_unix(cron:session): session closed for user root May 20 20:28:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[21640]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 20:28:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[21640]: pam_unix(cron:session): session closed for user root May 20 20:29:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[25836]: pam_unix(cron:session): session opened for user root by (uid=0) May 20 20:29:01 prd-ubuntu1804-docker-4c-4g-1369 CRON[25836]: pam_unix(cron:session): session closed for user root May 20 20:29:30 prd-ubuntu1804-docker-4c-4g-1369 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-plt-ricdms-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp May 20 20:29:30 prd-ubuntu1804-docker-4c-4g-1369 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)