Nov 9 12:40:24 prd-ubuntu1804-docker-8c-8g-11483 passwd[984]: password for 'ubuntu' changed by 'root' Nov 9 12:40:24 prd-ubuntu1804-docker-8c-8g-11483 systemd-logind[1044]: Watching system buttons on /dev/input/event0 (Power Button) Nov 9 12:40:24 prd-ubuntu1804-docker-8c-8g-11483 systemd-logind[1044]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Nov 9 12:40:24 prd-ubuntu1804-docker-8c-8g-11483 systemd-logind[1044]: New seat seat0. Nov 9 12:40:24 prd-ubuntu1804-docker-8c-8g-11483 sshd[1090]: Server listening on 0.0.0.0 port 22. Nov 9 12:40:24 prd-ubuntu1804-docker-8c-8g-11483 sshd[1090]: Server listening on :: port 22. Nov 9 12:40:27 prd-ubuntu1804-docker-8c-8g-11483 sshd[1383]: Did not receive identification string from 10.30.104.4 port 34740 Nov 9 12:40:33 prd-ubuntu1804-docker-8c-8g-11483 sshd[1406]: Invalid user jenkins from 10.30.104.4 port 34742 Nov 9 12:40:33 prd-ubuntu1804-docker-8c-8g-11483 sshd[1406]: Received disconnect from 10.30.104.4 port 34742:11: Closed due to user request. [preauth] Nov 9 12:40:33 prd-ubuntu1804-docker-8c-8g-11483 sshd[1406]: Disconnected from invalid user jenkins 10.30.104.4 port 34742 [preauth] Nov 9 12:40:35 prd-ubuntu1804-docker-8c-8g-11483 sshd[1410]: Invalid user jenkins from 10.30.104.4 port 34746 Nov 9 12:40:35 prd-ubuntu1804-docker-8c-8g-11483 sshd[1410]: Received disconnect from 10.30.104.4 port 34746:11: Closed due to user request. [preauth] Nov 9 12:40:35 prd-ubuntu1804-docker-8c-8g-11483 sshd[1410]: Disconnected from invalid user jenkins 10.30.104.4 port 34746 [preauth] Nov 9 12:40:37 prd-ubuntu1804-docker-8c-8g-11483 sshd[1412]: Invalid user jenkins from 10.30.104.4 port 34748 Nov 9 12:40:37 prd-ubuntu1804-docker-8c-8g-11483 sshd[1412]: Received disconnect from 10.30.104.4 port 34748:11: Closed due to user request. [preauth] Nov 9 12:40:37 prd-ubuntu1804-docker-8c-8g-11483 sshd[1412]: Disconnected from invalid user jenkins 10.30.104.4 port 34748 [preauth] Nov 9 12:40:39 prd-ubuntu1804-docker-8c-8g-11483 sshd[1414]: Invalid user jenkins from 10.30.104.4 port 34750 Nov 9 12:40:39 prd-ubuntu1804-docker-8c-8g-11483 sshd[1414]: Received disconnect from 10.30.104.4 port 34750:11: Closed due to user request. [preauth] Nov 9 12:40:39 prd-ubuntu1804-docker-8c-8g-11483 sshd[1414]: Disconnected from invalid user jenkins 10.30.104.4 port 34750 [preauth] Nov 9 12:40:42 prd-ubuntu1804-docker-8c-8g-11483 sshd[1513]: Invalid user jenkins from 10.30.104.4 port 34752 Nov 9 12:40:42 prd-ubuntu1804-docker-8c-8g-11483 sshd[1513]: Received disconnect from 10.30.104.4 port 34752:11: Closed due to user request. [preauth] Nov 9 12:40:42 prd-ubuntu1804-docker-8c-8g-11483 sshd[1513]: Disconnected from invalid user jenkins 10.30.104.4 port 34752 [preauth] Nov 9 12:40:44 prd-ubuntu1804-docker-8c-8g-11483 sshd[1668]: Invalid user jenkins from 10.30.104.4 port 34754 Nov 9 12:40:44 prd-ubuntu1804-docker-8c-8g-11483 sshd[1668]: Received disconnect from 10.30.104.4 port 34754:11: Closed due to user request. [preauth] Nov 9 12:40:44 prd-ubuntu1804-docker-8c-8g-11483 sshd[1668]: Disconnected from invalid user jenkins 10.30.104.4 port 34754 [preauth] Nov 9 12:40:46 prd-ubuntu1804-docker-8c-8g-11483 sshd[1676]: Invalid user jenkins from 10.30.104.4 port 34756 Nov 9 12:40:46 prd-ubuntu1804-docker-8c-8g-11483 sshd[1676]: Received disconnect from 10.30.104.4 port 34756:11: Closed due to user request. [preauth] Nov 9 12:40:46 prd-ubuntu1804-docker-8c-8g-11483 sshd[1676]: Disconnected from invalid user jenkins 10.30.104.4 port 34756 [preauth] Nov 9 12:40:48 prd-ubuntu1804-docker-8c-8g-11483 sshd[1678]: Invalid user jenkins from 10.30.104.4 port 34758 Nov 9 12:40:48 prd-ubuntu1804-docker-8c-8g-11483 sshd[1678]: Received disconnect from 10.30.104.4 port 34758:11: Closed due to user request. [preauth] Nov 9 12:40:48 prd-ubuntu1804-docker-8c-8g-11483 sshd[1678]: Disconnected from invalid user jenkins 10.30.104.4 port 34758 [preauth] Nov 9 12:40:50 prd-ubuntu1804-docker-8c-8g-11483 useradd[1704]: new group: name=jenkins, GID=1001 Nov 9 12:40:50 prd-ubuntu1804-docker-8c-8g-11483 useradd[1704]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Nov 9 12:40:50 prd-ubuntu1804-docker-8c-8g-11483 usermod[1711]: add 'jenkins' to group 'docker' Nov 9 12:40:50 prd-ubuntu1804-docker-8c-8g-11483 usermod[1711]: add 'jenkins' to shadow group 'docker' Nov 9 12:40:50 prd-ubuntu1804-docker-8c-8g-11483 sshd[1768]: Accepted publickey for jenkins from 10.30.104.4 port 34764 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Nov 9 12:40:50 prd-ubuntu1804-docker-8c-8g-11483 sshd[1768]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Nov 9 12:40:50 prd-ubuntu1804-docker-8c-8g-11483 systemd-logind[1044]: New session 1 of user jenkins. Nov 9 12:40:50 prd-ubuntu1804-docker-8c-8g-11483 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Nov 9 12:41:01 prd-ubuntu1804-docker-8c-8g-11483 CRON[2110]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 9 12:41:01 prd-ubuntu1804-docker-8c-8g-11483 CRON[2110]: pam_unix(cron:session): session closed for user root Nov 9 12:42:01 prd-ubuntu1804-docker-8c-8g-11483 CRON[2584]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 9 12:42:01 prd-ubuntu1804-docker-8c-8g-11483 CRON[2584]: pam_unix(cron:session): session closed for user root Nov 9 12:43:01 prd-ubuntu1804-docker-8c-8g-11483 CRON[2794]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 9 12:43:01 prd-ubuntu1804-docker-8c-8g-11483 CRON[2794]: pam_unix(cron:session): session closed for user root Nov 9 12:44:01 prd-ubuntu1804-docker-8c-8g-11483 CRON[3118]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 9 12:44:01 prd-ubuntu1804-docker-8c-8g-11483 CRON[3118]: pam_unix(cron:session): session closed for user root Nov 9 12:44:12 prd-ubuntu1804-docker-8c-8g-11483 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/dcaegen2-services-ml-prediction-ms-tox-sonar ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Nov 9 12:44:12 prd-ubuntu1804-docker-8c-8g-11483 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)