Feb 11 19:22:42 prd-ubuntu1804-docker-4c-4g-5965 passwd[935]: password for 'ubuntu' changed by 'root' Feb 11 19:22:42 prd-ubuntu1804-docker-4c-4g-5965 systemd-logind[1017]: Watching system buttons on /dev/input/event0 (Power Button) Feb 11 19:22:42 prd-ubuntu1804-docker-4c-4g-5965 systemd-logind[1017]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Feb 11 19:22:42 prd-ubuntu1804-docker-4c-4g-5965 systemd-logind[1017]: New seat seat0. Feb 11 19:22:43 prd-ubuntu1804-docker-4c-4g-5965 sshd[1274]: Server listening on 0.0.0.0 port 22. Feb 11 19:22:43 prd-ubuntu1804-docker-4c-4g-5965 sshd[1274]: Server listening on :: port 22. Feb 11 19:22:49 prd-ubuntu1804-docker-4c-4g-5965 sshd[1521]: Did not receive identification string from 10.32.4.5 port 56128 Feb 11 19:22:52 prd-ubuntu1804-docker-4c-4g-5965 sshd[1541]: Invalid user jenkins from 10.32.4.5 port 56140 Feb 11 19:22:52 prd-ubuntu1804-docker-4c-4g-5965 sshd[1541]: Received disconnect from 10.32.4.5 port 56140:11: Closed due to user request. [preauth] Feb 11 19:22:52 prd-ubuntu1804-docker-4c-4g-5965 sshd[1541]: Disconnected from invalid user jenkins 10.32.4.5 port 56140 [preauth] Feb 11 19:22:54 prd-ubuntu1804-docker-4c-4g-5965 sshd[1545]: Invalid user jenkins from 10.32.4.5 port 56150 Feb 11 19:22:54 prd-ubuntu1804-docker-4c-4g-5965 sshd[1545]: Received disconnect from 10.32.4.5 port 56150:11: Closed due to user request. [preauth] Feb 11 19:22:54 prd-ubuntu1804-docker-4c-4g-5965 sshd[1545]: Disconnected from invalid user jenkins 10.32.4.5 port 56150 [preauth] Feb 11 19:22:56 prd-ubuntu1804-docker-4c-4g-5965 sshd[1547]: Invalid user jenkins from 10.32.4.5 port 56154 Feb 11 19:22:56 prd-ubuntu1804-docker-4c-4g-5965 sshd[1547]: Received disconnect from 10.32.4.5 port 56154:11: Closed due to user request. [preauth] Feb 11 19:22:56 prd-ubuntu1804-docker-4c-4g-5965 sshd[1547]: Disconnected from invalid user jenkins 10.32.4.5 port 56154 [preauth] Feb 11 19:22:58 prd-ubuntu1804-docker-4c-4g-5965 sshd[1549]: Invalid user jenkins from 10.32.4.5 port 56158 Feb 11 19:22:58 prd-ubuntu1804-docker-4c-4g-5965 sshd[1549]: Received disconnect from 10.32.4.5 port 56158:11: Closed due to user request. [preauth] Feb 11 19:22:58 prd-ubuntu1804-docker-4c-4g-5965 sshd[1549]: Disconnected from invalid user jenkins 10.32.4.5 port 56158 [preauth] Feb 11 19:23:00 prd-ubuntu1804-docker-4c-4g-5965 sshd[1551]: Invalid user jenkins from 10.32.4.5 port 56162 Feb 11 19:23:00 prd-ubuntu1804-docker-4c-4g-5965 sshd[1551]: Received disconnect from 10.32.4.5 port 56162:11: Closed due to user request. [preauth] Feb 11 19:23:00 prd-ubuntu1804-docker-4c-4g-5965 sshd[1551]: Disconnected from invalid user jenkins 10.32.4.5 port 56162 [preauth] Feb 11 19:23:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[1553]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 11 19:23:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[1553]: pam_unix(cron:session): session closed for user root Feb 11 19:23:02 prd-ubuntu1804-docker-4c-4g-5965 sshd[1563]: Invalid user jenkins from 10.32.4.5 port 56174 Feb 11 19:23:02 prd-ubuntu1804-docker-4c-4g-5965 sshd[1563]: Received disconnect from 10.32.4.5 port 56174:11: Closed due to user request. [preauth] Feb 11 19:23:02 prd-ubuntu1804-docker-4c-4g-5965 sshd[1563]: Disconnected from invalid user jenkins 10.32.4.5 port 56174 [preauth] Feb 11 19:23:04 prd-ubuntu1804-docker-4c-4g-5965 sshd[1583]: Invalid user jenkins from 10.32.4.5 port 56178 Feb 11 19:23:04 prd-ubuntu1804-docker-4c-4g-5965 sshd[1583]: Received disconnect from 10.32.4.5 port 56178:11: Closed due to user request. [preauth] Feb 11 19:23:04 prd-ubuntu1804-docker-4c-4g-5965 sshd[1583]: Disconnected from invalid user jenkins 10.32.4.5 port 56178 [preauth] Feb 11 19:23:07 prd-ubuntu1804-docker-4c-4g-5965 sshd[1795]: Invalid user jenkins from 10.32.4.5 port 56182 Feb 11 19:23:07 prd-ubuntu1804-docker-4c-4g-5965 sshd[1795]: Received disconnect from 10.32.4.5 port 56182:11: Closed due to user request. [preauth] Feb 11 19:23:07 prd-ubuntu1804-docker-4c-4g-5965 sshd[1795]: Disconnected from invalid user jenkins 10.32.4.5 port 56182 [preauth] Feb 11 19:23:09 prd-ubuntu1804-docker-4c-4g-5965 sshd[1831]: Invalid user jenkins from 10.32.4.5 port 56186 Feb 11 19:23:09 prd-ubuntu1804-docker-4c-4g-5965 sshd[1831]: Received disconnect from 10.32.4.5 port 56186:11: Closed due to user request. [preauth] Feb 11 19:23:09 prd-ubuntu1804-docker-4c-4g-5965 sshd[1831]: Disconnected from invalid user jenkins 10.32.4.5 port 56186 [preauth] Feb 11 19:23:11 prd-ubuntu1804-docker-4c-4g-5965 sshd[1850]: Invalid user jenkins from 10.32.4.5 port 56190 Feb 11 19:23:11 prd-ubuntu1804-docker-4c-4g-5965 sshd[1850]: Received disconnect from 10.32.4.5 port 56190:11: Closed due to user request. [preauth] Feb 11 19:23:11 prd-ubuntu1804-docker-4c-4g-5965 sshd[1850]: Disconnected from invalid user jenkins 10.32.4.5 port 56190 [preauth] Feb 11 19:23:13 prd-ubuntu1804-docker-4c-4g-5965 sshd[1854]: Invalid user jenkins from 10.32.4.5 port 56196 Feb 11 19:23:13 prd-ubuntu1804-docker-4c-4g-5965 sshd[1854]: Received disconnect from 10.32.4.5 port 56196:11: Closed due to user request. [preauth] Feb 11 19:23:13 prd-ubuntu1804-docker-4c-4g-5965 sshd[1854]: Disconnected from invalid user jenkins 10.32.4.5 port 56196 [preauth] Feb 11 19:23:15 prd-ubuntu1804-docker-4c-4g-5965 useradd[1884]: new group: name=jenkins, GID=1001 Feb 11 19:23:15 prd-ubuntu1804-docker-4c-4g-5965 useradd[1884]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Feb 11 19:23:15 prd-ubuntu1804-docker-4c-4g-5965 usermod[1891]: add 'jenkins' to group 'docker' Feb 11 19:23:15 prd-ubuntu1804-docker-4c-4g-5965 usermod[1891]: add 'jenkins' to shadow group 'docker' Feb 11 19:23:16 prd-ubuntu1804-docker-4c-4g-5965 sshd[1946]: Accepted publickey for jenkins from 10.32.4.5 port 56202 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Feb 11 19:23:16 prd-ubuntu1804-docker-4c-4g-5965 sshd[1946]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Feb 11 19:23:16 prd-ubuntu1804-docker-4c-4g-5965 systemd-logind[1017]: New session 2 of user jenkins. Feb 11 19:23:16 prd-ubuntu1804-docker-4c-4g-5965 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Feb 11 19:24:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[2484]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 11 19:24:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[2484]: pam_unix(cron:session): session closed for user root Feb 11 19:25:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[2531]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 11 19:25:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[2531]: pam_unix(cron:session): session closed for user root Feb 11 19:26:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[6114]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 11 19:26:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[6114]: pam_unix(cron:session): session closed for user root Feb 11 19:27:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[7018]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 11 19:27:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[7018]: pam_unix(cron:session): session closed for user root Feb 11 19:28:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[10679]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 11 19:28:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[10679]: pam_unix(cron:session): session closed for user root Feb 11 19:29:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[14320]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 11 19:29:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[14320]: pam_unix(cron:session): session closed for user root Feb 11 19:30:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[15562]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 11 19:30:01 prd-ubuntu1804-docker-4c-4g-5965 CRON[15562]: pam_unix(cron:session): session closed for user root Feb 11 19:30:11 prd-ubuntu1804-docker-4c-4g-5965 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/ric-plt-submgr-docker-verify-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Feb 11 19:30:11 prd-ubuntu1804-docker-4c-4g-5965 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)