Jan 1 22:25:42 prd-ubuntu1804-docker-4c-4g-703 passwd[940]: password for 'ubuntu' changed by 'root' Jan 1 22:25:42 prd-ubuntu1804-docker-4c-4g-703 systemd-logind[1045]: Watching system buttons on /dev/input/event0 (Power Button) Jan 1 22:25:42 prd-ubuntu1804-docker-4c-4g-703 systemd-logind[1045]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jan 1 22:25:42 prd-ubuntu1804-docker-4c-4g-703 systemd-logind[1045]: New seat seat0. Jan 1 22:25:43 prd-ubuntu1804-docker-4c-4g-703 sshd[1240]: Server listening on 0.0.0.0 port 22. Jan 1 22:25:43 prd-ubuntu1804-docker-4c-4g-703 sshd[1240]: Server listening on :: port 22. Jan 1 22:25:46 prd-ubuntu1804-docker-4c-4g-703 sshd[1462]: Did not receive identification string from 10.32.4.5 port 57298 Jan 1 22:25:47 prd-ubuntu1804-docker-4c-4g-703 sshd[1478]: Invalid user jenkins from 10.32.4.5 port 57300 Jan 1 22:25:47 prd-ubuntu1804-docker-4c-4g-703 sshd[1478]: Received disconnect from 10.32.4.5 port 57300:11: Closed due to user request. [preauth] Jan 1 22:25:47 prd-ubuntu1804-docker-4c-4g-703 sshd[1478]: Disconnected from invalid user jenkins 10.32.4.5 port 57300 [preauth] Jan 1 22:25:49 prd-ubuntu1804-docker-4c-4g-703 sshd[1502]: Invalid user jenkins from 10.32.4.5 port 57302 Jan 1 22:25:49 prd-ubuntu1804-docker-4c-4g-703 sshd[1502]: Received disconnect from 10.32.4.5 port 57302:11: Closed due to user request. [preauth] Jan 1 22:25:49 prd-ubuntu1804-docker-4c-4g-703 sshd[1502]: Disconnected from invalid user jenkins 10.32.4.5 port 57302 [preauth] Jan 1 22:25:51 prd-ubuntu1804-docker-4c-4g-703 sshd[1521]: Invalid user jenkins from 10.32.4.5 port 57310 Jan 1 22:25:51 prd-ubuntu1804-docker-4c-4g-703 sshd[1521]: Received disconnect from 10.32.4.5 port 57310:11: Closed due to user request. [preauth] Jan 1 22:25:51 prd-ubuntu1804-docker-4c-4g-703 sshd[1521]: Disconnected from invalid user jenkins 10.32.4.5 port 57310 [preauth] Jan 1 22:25:53 prd-ubuntu1804-docker-4c-4g-703 sshd[1523]: Invalid user jenkins from 10.32.4.5 port 57312 Jan 1 22:25:53 prd-ubuntu1804-docker-4c-4g-703 sshd[1523]: Received disconnect from 10.32.4.5 port 57312:11: Closed due to user request. [preauth] Jan 1 22:25:53 prd-ubuntu1804-docker-4c-4g-703 sshd[1523]: Disconnected from invalid user jenkins 10.32.4.5 port 57312 [preauth] Jan 1 22:25:55 prd-ubuntu1804-docker-4c-4g-703 sshd[1525]: Invalid user jenkins from 10.32.4.5 port 57314 Jan 1 22:25:56 prd-ubuntu1804-docker-4c-4g-703 sshd[1525]: Received disconnect from 10.32.4.5 port 57314:11: Closed due to user request. [preauth] Jan 1 22:25:56 prd-ubuntu1804-docker-4c-4g-703 sshd[1525]: Disconnected from invalid user jenkins 10.32.4.5 port 57314 [preauth] Jan 1 22:25:58 prd-ubuntu1804-docker-4c-4g-703 sshd[1527]: Invalid user jenkins from 10.32.4.5 port 57316 Jan 1 22:25:58 prd-ubuntu1804-docker-4c-4g-703 sshd[1527]: Received disconnect from 10.32.4.5 port 57316:11: Closed due to user request. [preauth] Jan 1 22:25:58 prd-ubuntu1804-docker-4c-4g-703 sshd[1527]: Disconnected from invalid user jenkins 10.32.4.5 port 57316 [preauth] Jan 1 22:26:00 prd-ubuntu1804-docker-4c-4g-703 sshd[1529]: Invalid user jenkins from 10.32.4.5 port 57320 Jan 1 22:26:00 prd-ubuntu1804-docker-4c-4g-703 sshd[1529]: Received disconnect from 10.32.4.5 port 57320:11: Closed due to user request. [preauth] Jan 1 22:26:00 prd-ubuntu1804-docker-4c-4g-703 sshd[1529]: Disconnected from invalid user jenkins 10.32.4.5 port 57320 [preauth] Jan 1 22:26:01 prd-ubuntu1804-docker-4c-4g-703 CRON[1532]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 1 22:26:01 prd-ubuntu1804-docker-4c-4g-703 CRON[1532]: pam_unix(cron:session): session closed for user root Jan 1 22:26:02 prd-ubuntu1804-docker-4c-4g-703 sshd[1540]: Invalid user jenkins from 10.32.4.5 port 57322 Jan 1 22:26:02 prd-ubuntu1804-docker-4c-4g-703 sshd[1540]: Received disconnect from 10.32.4.5 port 57322:11: Closed due to user request. [preauth] Jan 1 22:26:02 prd-ubuntu1804-docker-4c-4g-703 sshd[1540]: Disconnected from invalid user jenkins 10.32.4.5 port 57322 [preauth] Jan 1 22:26:04 prd-ubuntu1804-docker-4c-4g-703 sshd[1553]: Invalid user jenkins from 10.32.4.5 port 57324 Jan 1 22:26:04 prd-ubuntu1804-docker-4c-4g-703 sshd[1553]: Received disconnect from 10.32.4.5 port 57324:11: Closed due to user request. [preauth] Jan 1 22:26:04 prd-ubuntu1804-docker-4c-4g-703 sshd[1553]: Disconnected from invalid user jenkins 10.32.4.5 port 57324 [preauth] Jan 1 22:26:07 prd-ubuntu1804-docker-4c-4g-703 sshd[1774]: Invalid user jenkins from 10.32.4.5 port 57326 Jan 1 22:26:07 prd-ubuntu1804-docker-4c-4g-703 sshd[1774]: Received disconnect from 10.32.4.5 port 57326:11: Closed due to user request. [preauth] Jan 1 22:26:07 prd-ubuntu1804-docker-4c-4g-703 sshd[1774]: Disconnected from invalid user jenkins 10.32.4.5 port 57326 [preauth] Jan 1 22:26:09 prd-ubuntu1804-docker-4c-4g-703 sshd[1824]: Invalid user jenkins from 10.32.4.5 port 57328 Jan 1 22:26:09 prd-ubuntu1804-docker-4c-4g-703 sshd[1824]: Received disconnect from 10.32.4.5 port 57328:11: Closed due to user request. [preauth] Jan 1 22:26:09 prd-ubuntu1804-docker-4c-4g-703 sshd[1824]: Disconnected from invalid user jenkins 10.32.4.5 port 57328 [preauth] Jan 1 22:26:11 prd-ubuntu1804-docker-4c-4g-703 sshd[1828]: Invalid user jenkins from 10.32.4.5 port 57330 Jan 1 22:26:11 prd-ubuntu1804-docker-4c-4g-703 sshd[1828]: Received disconnect from 10.32.4.5 port 57330:11: Closed due to user request. [preauth] Jan 1 22:26:11 prd-ubuntu1804-docker-4c-4g-703 sshd[1828]: Disconnected from invalid user jenkins 10.32.4.5 port 57330 [preauth] Jan 1 22:26:12 prd-ubuntu1804-docker-4c-4g-703 useradd[1844]: new group: name=jenkins, GID=1001 Jan 1 22:26:12 prd-ubuntu1804-docker-4c-4g-703 useradd[1844]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Jan 1 22:26:12 prd-ubuntu1804-docker-4c-4g-703 usermod[1851]: add 'jenkins' to group 'docker' Jan 1 22:26:12 prd-ubuntu1804-docker-4c-4g-703 usermod[1851]: add 'jenkins' to shadow group 'docker' Jan 1 22:26:14 prd-ubuntu1804-docker-4c-4g-703 sshd[1885]: Accepted publickey for jenkins from 10.32.4.5 port 57332 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Jan 1 22:26:14 prd-ubuntu1804-docker-4c-4g-703 sshd[1885]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jan 1 22:26:14 prd-ubuntu1804-docker-4c-4g-703 systemd-logind[1045]: New session 2 of user jenkins. Jan 1 22:26:14 prd-ubuntu1804-docker-4c-4g-703 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jan 1 22:27:02 prd-ubuntu1804-docker-4c-4g-703 CRON[2445]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 1 22:27:02 prd-ubuntu1804-docker-4c-4g-703 CRON[2445]: pam_unix(cron:session): session closed for user root Jan 1 22:28:01 prd-ubuntu1804-docker-4c-4g-703 CRON[2964]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 1 22:28:01 prd-ubuntu1804-docker-4c-4g-703 CRON[2964]: pam_unix(cron:session): session closed for user root Jan 1 22:29:01 prd-ubuntu1804-docker-4c-4g-703 CRON[3514]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 1 22:29:01 prd-ubuntu1804-docker-4c-4g-703 CRON[3514]: pam_unix(cron:session): session closed for user root Jan 1 22:30:01 prd-ubuntu1804-docker-4c-4g-703 CRON[3519]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 1 22:30:01 prd-ubuntu1804-docker-4c-4g-703 CRON[3519]: pam_unix(cron:session): session closed for user root Jan 1 22:31:01 prd-ubuntu1804-docker-4c-4g-703 CRON[7652]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 1 22:31:01 prd-ubuntu1804-docker-4c-4g-703 CRON[7652]: pam_unix(cron:session): session closed for user root Jan 1 22:32:01 prd-ubuntu1804-docker-4c-4g-703 CRON[8546]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 1 22:32:01 prd-ubuntu1804-docker-4c-4g-703 CRON[8546]: pam_unix(cron:session): session closed for user root Jan 1 22:32:04 prd-ubuntu1804-docker-4c-4g-703 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/sim-e2-interface-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Jan 1 22:32:04 prd-ubuntu1804-docker-4c-4g-703 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)