Nov 16 10:31:29 prd-ubuntu1804-docker-4c-4g-10499 passwd[928]: password for 'ubuntu' changed by 'root' Nov 16 10:31:29 prd-ubuntu1804-docker-4c-4g-10499 systemd-logind[977]: Watching system buttons on /dev/input/event0 (Power Button) Nov 16 10:31:29 prd-ubuntu1804-docker-4c-4g-10499 systemd-logind[977]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Nov 16 10:31:29 prd-ubuntu1804-docker-4c-4g-10499 systemd-logind[977]: New seat seat0. Nov 16 10:31:29 prd-ubuntu1804-docker-4c-4g-10499 sshd[1103]: Server listening on 0.0.0.0 port 22. Nov 16 10:31:29 prd-ubuntu1804-docker-4c-4g-10499 sshd[1103]: Server listening on :: port 22. Nov 16 10:31:33 prd-ubuntu1804-docker-4c-4g-10499 sshd[1424]: Did not receive identification string from 10.32.4.5 port 54382 Nov 16 10:31:40 prd-ubuntu1804-docker-4c-4g-10499 sshd[1490]: Invalid user jenkins from 10.32.4.5 port 54386 Nov 16 10:31:40 prd-ubuntu1804-docker-4c-4g-10499 sshd[1490]: Received disconnect from 10.32.4.5 port 54386:11: Closed due to user request. [preauth] Nov 16 10:31:40 prd-ubuntu1804-docker-4c-4g-10499 sshd[1490]: Disconnected from invalid user jenkins 10.32.4.5 port 54386 [preauth] Nov 16 10:31:42 prd-ubuntu1804-docker-4c-4g-10499 sshd[1494]: Invalid user jenkins from 10.32.4.5 port 54388 Nov 16 10:31:42 prd-ubuntu1804-docker-4c-4g-10499 sshd[1494]: Received disconnect from 10.32.4.5 port 54388:11: Closed due to user request. [preauth] Nov 16 10:31:42 prd-ubuntu1804-docker-4c-4g-10499 sshd[1494]: Disconnected from invalid user jenkins 10.32.4.5 port 54388 [preauth] Nov 16 10:31:44 prd-ubuntu1804-docker-4c-4g-10499 sshd[1496]: Invalid user jenkins from 10.32.4.5 port 54396 Nov 16 10:31:44 prd-ubuntu1804-docker-4c-4g-10499 sshd[1496]: Received disconnect from 10.32.4.5 port 54396:11: Closed due to user request. [preauth] Nov 16 10:31:44 prd-ubuntu1804-docker-4c-4g-10499 sshd[1496]: Disconnected from invalid user jenkins 10.32.4.5 port 54396 [preauth] Nov 16 10:31:46 prd-ubuntu1804-docker-4c-4g-10499 sshd[1498]: Invalid user jenkins from 10.32.4.5 port 54398 Nov 16 10:31:46 prd-ubuntu1804-docker-4c-4g-10499 sshd[1498]: Received disconnect from 10.32.4.5 port 54398:11: Closed due to user request. [preauth] Nov 16 10:31:46 prd-ubuntu1804-docker-4c-4g-10499 sshd[1498]: Disconnected from invalid user jenkins 10.32.4.5 port 54398 [preauth] Nov 16 10:31:48 prd-ubuntu1804-docker-4c-4g-10499 sshd[1500]: Invalid user jenkins from 10.32.4.5 port 54402 Nov 16 10:31:48 prd-ubuntu1804-docker-4c-4g-10499 sshd[1500]: Received disconnect from 10.32.4.5 port 54402:11: Closed due to user request. [preauth] Nov 16 10:31:48 prd-ubuntu1804-docker-4c-4g-10499 sshd[1500]: Disconnected from invalid user jenkins 10.32.4.5 port 54402 [preauth] Nov 16 10:31:50 prd-ubuntu1804-docker-4c-4g-10499 sshd[1502]: Invalid user jenkins from 10.32.4.5 port 54404 Nov 16 10:31:50 prd-ubuntu1804-docker-4c-4g-10499 sshd[1502]: Received disconnect from 10.32.4.5 port 54404:11: Closed due to user request. [preauth] Nov 16 10:31:50 prd-ubuntu1804-docker-4c-4g-10499 sshd[1502]: Disconnected from invalid user jenkins 10.32.4.5 port 54404 [preauth] Nov 16 10:31:53 prd-ubuntu1804-docker-4c-4g-10499 sshd[1725]: Invalid user jenkins from 10.32.4.5 port 54408 Nov 16 10:31:53 prd-ubuntu1804-docker-4c-4g-10499 sshd[1725]: Received disconnect from 10.32.4.5 port 54408:11: Closed due to user request. [preauth] Nov 16 10:31:53 prd-ubuntu1804-docker-4c-4g-10499 sshd[1725]: Disconnected from invalid user jenkins 10.32.4.5 port 54408 [preauth] Nov 16 10:31:55 prd-ubuntu1804-docker-4c-4g-10499 sshd[1759]: Invalid user jenkins from 10.32.4.5 port 54410 Nov 16 10:31:56 prd-ubuntu1804-docker-4c-4g-10499 sshd[1759]: Received disconnect from 10.32.4.5 port 54410:11: Closed due to user request. [preauth] Nov 16 10:31:56 prd-ubuntu1804-docker-4c-4g-10499 sshd[1759]: Disconnected from invalid user jenkins 10.32.4.5 port 54410 [preauth] Nov 16 10:31:58 prd-ubuntu1804-docker-4c-4g-10499 sshd[1777]: Invalid user jenkins from 10.32.4.5 port 54412 Nov 16 10:31:58 prd-ubuntu1804-docker-4c-4g-10499 sshd[1777]: Received disconnect from 10.32.4.5 port 54412:11: Closed due to user request. [preauth] Nov 16 10:31:58 prd-ubuntu1804-docker-4c-4g-10499 sshd[1777]: Disconnected from invalid user jenkins 10.32.4.5 port 54412 [preauth] Nov 16 10:31:59 prd-ubuntu1804-docker-4c-4g-10499 useradd[1795]: new group: name=jenkins, GID=1001 Nov 16 10:31:59 prd-ubuntu1804-docker-4c-4g-10499 useradd[1795]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Nov 16 10:31:59 prd-ubuntu1804-docker-4c-4g-10499 usermod[1802]: add 'jenkins' to group 'docker' Nov 16 10:31:59 prd-ubuntu1804-docker-4c-4g-10499 usermod[1802]: add 'jenkins' to shadow group 'docker' Nov 16 10:32:00 prd-ubuntu1804-docker-4c-4g-10499 sshd[1836]: Accepted publickey for jenkins from 10.32.4.5 port 54414 ssh2: RSA SHA256:MwkAMVxCcf5mjE3h3rXSsWkdX5TtX0v/kuPsZexJ1qI Nov 16 10:32:00 prd-ubuntu1804-docker-4c-4g-10499 sshd[1836]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Nov 16 10:32:00 prd-ubuntu1804-docker-4c-4g-10499 systemd-logind[977]: New session 1 of user jenkins. Nov 16 10:32:00 prd-ubuntu1804-docker-4c-4g-10499 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Nov 16 10:32:02 prd-ubuntu1804-docker-4c-4g-10499 CRON[2049]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 16 10:32:02 prd-ubuntu1804-docker-4c-4g-10499 CRON[2049]: pam_unix(cron:session): session closed for user root Nov 16 10:33:01 prd-ubuntu1804-docker-4c-4g-10499 CRON[2594]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 16 10:33:01 prd-ubuntu1804-docker-4c-4g-10499 CRON[2594]: pam_unix(cron:session): session closed for user root Nov 16 10:34:01 prd-ubuntu1804-docker-4c-4g-10499 CRON[6600]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 16 10:34:01 prd-ubuntu1804-docker-4c-4g-10499 CRON[6600]: pam_unix(cron:session): session closed for user root Nov 16 10:35:01 prd-ubuntu1804-docker-4c-4g-10499 CRON[7979]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 16 10:35:01 prd-ubuntu1804-docker-4c-4g-10499 CRON[7979]: pam_unix(cron:session): session closed for user root Nov 16 10:35:14 prd-ubuntu1804-docker-4c-4g-10499 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/smo-ves-collector-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Nov 16 10:35:14 prd-ubuntu1804-docker-4c-4g-10499 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)