Jan 9 06:05:19 prd-ubuntu1804-docker-8c-8g-10652 passwd[991]: password for 'ubuntu' changed by 'root' Jan 9 06:05:19 prd-ubuntu1804-docker-8c-8g-10652 systemd-logind[1046]: Watching system buttons on /dev/input/event0 (Power Button) Jan 9 06:05:19 prd-ubuntu1804-docker-8c-8g-10652 systemd-logind[1046]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jan 9 06:05:19 prd-ubuntu1804-docker-8c-8g-10652 systemd-logind[1046]: New seat seat0. Jan 9 06:05:19 prd-ubuntu1804-docker-8c-8g-10652 sshd[1125]: Server listening on 0.0.0.0 port 22. Jan 9 06:05:19 prd-ubuntu1804-docker-8c-8g-10652 sshd[1125]: Server listening on :: port 22. Jan 9 06:05:22 prd-ubuntu1804-docker-8c-8g-10652 sshd[1464]: Did not receive identification string from 10.30.104.4 port 56996 Jan 9 06:05:31 prd-ubuntu1804-docker-8c-8g-10652 sshd[1492]: Invalid user jenkins from 10.30.104.4 port 56998 Jan 9 06:05:31 prd-ubuntu1804-docker-8c-8g-10652 sshd[1492]: Received disconnect from 10.30.104.4 port 56998:11: Closed due to user request. [preauth] Jan 9 06:05:31 prd-ubuntu1804-docker-8c-8g-10652 sshd[1492]: Disconnected from invalid user jenkins 10.30.104.4 port 56998 [preauth] Jan 9 06:05:33 prd-ubuntu1804-docker-8c-8g-10652 sshd[1496]: Invalid user jenkins from 10.30.104.4 port 57000 Jan 9 06:05:33 prd-ubuntu1804-docker-8c-8g-10652 sshd[1496]: Received disconnect from 10.30.104.4 port 57000:11: Closed due to user request. [preauth] Jan 9 06:05:33 prd-ubuntu1804-docker-8c-8g-10652 sshd[1496]: Disconnected from invalid user jenkins 10.30.104.4 port 57000 [preauth] Jan 9 06:05:35 prd-ubuntu1804-docker-8c-8g-10652 sshd[1498]: Invalid user jenkins from 10.30.104.4 port 57002 Jan 9 06:05:35 prd-ubuntu1804-docker-8c-8g-10652 sshd[1498]: Received disconnect from 10.30.104.4 port 57002:11: Closed due to user request. [preauth] Jan 9 06:05:35 prd-ubuntu1804-docker-8c-8g-10652 sshd[1498]: Disconnected from invalid user jenkins 10.30.104.4 port 57002 [preauth] Jan 9 06:05:38 prd-ubuntu1804-docker-8c-8g-10652 sshd[1682]: Invalid user jenkins from 10.30.104.4 port 57006 Jan 9 06:05:38 prd-ubuntu1804-docker-8c-8g-10652 sshd[1682]: Received disconnect from 10.30.104.4 port 57006:11: Closed due to user request. [preauth] Jan 9 06:05:38 prd-ubuntu1804-docker-8c-8g-10652 sshd[1682]: Disconnected from invalid user jenkins 10.30.104.4 port 57006 [preauth] Jan 9 06:05:40 prd-ubuntu1804-docker-8c-8g-10652 sshd[1762]: Invalid user jenkins from 10.30.104.4 port 57008 Jan 9 06:05:40 prd-ubuntu1804-docker-8c-8g-10652 sshd[1762]: Received disconnect from 10.30.104.4 port 57008:11: Closed due to user request. [preauth] Jan 9 06:05:40 prd-ubuntu1804-docker-8c-8g-10652 sshd[1762]: Disconnected from invalid user jenkins 10.30.104.4 port 57008 [preauth] Jan 9 06:05:42 prd-ubuntu1804-docker-8c-8g-10652 sshd[1766]: Invalid user jenkins from 10.30.104.4 port 57016 Jan 9 06:05:42 prd-ubuntu1804-docker-8c-8g-10652 sshd[1766]: Received disconnect from 10.30.104.4 port 57016:11: Closed due to user request. [preauth] Jan 9 06:05:42 prd-ubuntu1804-docker-8c-8g-10652 sshd[1766]: Disconnected from invalid user jenkins 10.30.104.4 port 57016 [preauth] Jan 9 06:05:44 prd-ubuntu1804-docker-8c-8g-10652 sshd[1768]: Invalid user jenkins from 10.30.104.4 port 57018 Jan 9 06:05:45 prd-ubuntu1804-docker-8c-8g-10652 sshd[1768]: Received disconnect from 10.30.104.4 port 57018:11: Closed due to user request. [preauth] Jan 9 06:05:45 prd-ubuntu1804-docker-8c-8g-10652 sshd[1768]: Disconnected from invalid user jenkins 10.30.104.4 port 57018 [preauth] Jan 9 06:05:47 prd-ubuntu1804-docker-8c-8g-10652 sshd[1776]: Invalid user jenkins from 10.30.104.4 port 57020 Jan 9 06:05:47 prd-ubuntu1804-docker-8c-8g-10652 sshd[1776]: Received disconnect from 10.30.104.4 port 57020:11: Closed due to user request. [preauth] Jan 9 06:05:47 prd-ubuntu1804-docker-8c-8g-10652 sshd[1776]: Disconnected from invalid user jenkins 10.30.104.4 port 57020 [preauth] Jan 9 06:05:48 prd-ubuntu1804-docker-8c-8g-10652 useradd[1796]: new group: name=jenkins, GID=1001 Jan 9 06:05:48 prd-ubuntu1804-docker-8c-8g-10652 useradd[1796]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Jan 9 06:05:48 prd-ubuntu1804-docker-8c-8g-10652 usermod[1803]: add 'jenkins' to group 'docker' Jan 9 06:05:48 prd-ubuntu1804-docker-8c-8g-10652 usermod[1803]: add 'jenkins' to shadow group 'docker' Jan 9 06:05:49 prd-ubuntu1804-docker-8c-8g-10652 sshd[1864]: Accepted publickey for jenkins from 10.30.104.4 port 57022 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Jan 9 06:05:49 prd-ubuntu1804-docker-8c-8g-10652 sshd[1864]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jan 9 06:05:49 prd-ubuntu1804-docker-8c-8g-10652 systemd-logind[1046]: New session 1 of user jenkins. Jan 9 06:05:49 prd-ubuntu1804-docker-8c-8g-10652 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jan 9 06:06:02 prd-ubuntu1804-docker-8c-8g-10652 CRON[2399]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 9 06:06:02 prd-ubuntu1804-docker-8c-8g-10652 CRON[2399]: pam_unix(cron:session): session closed for user root Jan 9 06:07:01 prd-ubuntu1804-docker-8c-8g-10652 CRON[2672]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 9 06:07:01 prd-ubuntu1804-docker-8c-8g-10652 CRON[2672]: pam_unix(cron:session): session closed for user root Jan 9 06:08:01 prd-ubuntu1804-docker-8c-8g-10652 CRON[3812]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 9 06:08:01 prd-ubuntu1804-docker-8c-8g-10652 CRON[3812]: pam_unix(cron:session): session closed for user root Jan 9 06:09:01 prd-ubuntu1804-docker-8c-8g-10652 CRON[4187]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 9 06:09:01 prd-ubuntu1804-docker-8c-8g-10652 CRON[4187]: pam_unix(cron:session): session closed for user root Jan 9 06:09:11 prd-ubuntu1804-docker-8c-8g-10652 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/integration-xtesting-infra-healthcheck-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Jan 9 06:09:11 prd-ubuntu1804-docker-8c-8g-10652 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)