Apr 2 14:25:25 prd-ubuntu1804-docker-8c-8g-3308 passwd[1018]: password for 'ubuntu' changed by 'root' Apr 2 14:25:25 prd-ubuntu1804-docker-8c-8g-3308 systemd-logind[1071]: Watching system buttons on /dev/input/event0 (Power Button) Apr 2 14:25:25 prd-ubuntu1804-docker-8c-8g-3308 systemd-logind[1071]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Apr 2 14:25:25 prd-ubuntu1804-docker-8c-8g-3308 systemd-logind[1071]: New seat seat0. Apr 2 14:25:25 prd-ubuntu1804-docker-8c-8g-3308 sshd[1146]: Server listening on 0.0.0.0 port 22. Apr 2 14:25:25 prd-ubuntu1804-docker-8c-8g-3308 sshd[1146]: Server listening on :: port 22. Apr 2 14:25:28 prd-ubuntu1804-docker-8c-8g-3308 sshd[1485]: Did not receive identification string from 10.30.104.4 port 37106 Apr 2 14:25:28 prd-ubuntu1804-docker-8c-8g-3308 sshd[1491]: Invalid user jenkins from 10.30.104.4 port 37110 Apr 2 14:25:28 prd-ubuntu1804-docker-8c-8g-3308 sshd[1491]: Received disconnect from 10.30.104.4 port 37110:11: Closed due to user request. [preauth] Apr 2 14:25:28 prd-ubuntu1804-docker-8c-8g-3308 sshd[1491]: Disconnected from invalid user jenkins 10.30.104.4 port 37110 [preauth] Apr 2 14:25:30 prd-ubuntu1804-docker-8c-8g-3308 sshd[1508]: Invalid user jenkins from 10.30.104.4 port 37124 Apr 2 14:25:30 prd-ubuntu1804-docker-8c-8g-3308 sshd[1508]: Received disconnect from 10.30.104.4 port 37124:11: Closed due to user request. [preauth] Apr 2 14:25:30 prd-ubuntu1804-docker-8c-8g-3308 sshd[1508]: Disconnected from invalid user jenkins 10.30.104.4 port 37124 [preauth] Apr 2 14:25:32 prd-ubuntu1804-docker-8c-8g-3308 sshd[1517]: Invalid user jenkins from 10.30.104.4 port 37128 Apr 2 14:25:32 prd-ubuntu1804-docker-8c-8g-3308 sshd[1517]: Received disconnect from 10.30.104.4 port 37128:11: Closed due to user request. [preauth] Apr 2 14:25:32 prd-ubuntu1804-docker-8c-8g-3308 sshd[1517]: Disconnected from invalid user jenkins 10.30.104.4 port 37128 [preauth] Apr 2 14:25:34 prd-ubuntu1804-docker-8c-8g-3308 sshd[1519]: Invalid user jenkins from 10.30.104.4 port 37132 Apr 2 14:25:34 prd-ubuntu1804-docker-8c-8g-3308 sshd[1519]: Received disconnect from 10.30.104.4 port 37132:11: Closed due to user request. [preauth] Apr 2 14:25:34 prd-ubuntu1804-docker-8c-8g-3308 sshd[1519]: Disconnected from invalid user jenkins 10.30.104.4 port 37132 [preauth] Apr 2 14:25:36 prd-ubuntu1804-docker-8c-8g-3308 sshd[1521]: Invalid user jenkins from 10.30.104.4 port 37136 Apr 2 14:25:36 prd-ubuntu1804-docker-8c-8g-3308 sshd[1521]: Received disconnect from 10.30.104.4 port 37136:11: Closed due to user request. [preauth] Apr 2 14:25:36 prd-ubuntu1804-docker-8c-8g-3308 sshd[1521]: Disconnected from invalid user jenkins 10.30.104.4 port 37136 [preauth] Apr 2 14:25:38 prd-ubuntu1804-docker-8c-8g-3308 sshd[1523]: Invalid user jenkins from 10.30.104.4 port 37144 Apr 2 14:25:39 prd-ubuntu1804-docker-8c-8g-3308 sshd[1523]: Received disconnect from 10.30.104.4 port 37144:11: Closed due to user request. [preauth] Apr 2 14:25:39 prd-ubuntu1804-docker-8c-8g-3308 sshd[1523]: Disconnected from invalid user jenkins 10.30.104.4 port 37144 [preauth] Apr 2 14:25:41 prd-ubuntu1804-docker-8c-8g-3308 sshd[1525]: Invalid user jenkins from 10.30.104.4 port 37152 Apr 2 14:25:41 prd-ubuntu1804-docker-8c-8g-3308 sshd[1525]: Received disconnect from 10.30.104.4 port 37152:11: Closed due to user request. [preauth] Apr 2 14:25:41 prd-ubuntu1804-docker-8c-8g-3308 sshd[1525]: Disconnected from invalid user jenkins 10.30.104.4 port 37152 [preauth] Apr 2 14:25:43 prd-ubuntu1804-docker-8c-8g-3308 sshd[1602]: Invalid user jenkins from 10.30.104.4 port 37160 Apr 2 14:25:43 prd-ubuntu1804-docker-8c-8g-3308 sshd[1602]: Received disconnect from 10.30.104.4 port 37160:11: Closed due to user request. [preauth] Apr 2 14:25:43 prd-ubuntu1804-docker-8c-8g-3308 sshd[1602]: Disconnected from invalid user jenkins 10.30.104.4 port 37160 [preauth] Apr 2 14:25:45 prd-ubuntu1804-docker-8c-8g-3308 sshd[1760]: Invalid user jenkins from 10.30.104.4 port 37170 Apr 2 14:25:46 prd-ubuntu1804-docker-8c-8g-3308 sshd[1760]: Received disconnect from 10.30.104.4 port 37170:11: Closed due to user request. [preauth] Apr 2 14:25:46 prd-ubuntu1804-docker-8c-8g-3308 sshd[1760]: Disconnected from invalid user jenkins 10.30.104.4 port 37170 [preauth] Apr 2 14:25:48 prd-ubuntu1804-docker-8c-8g-3308 sshd[1800]: Invalid user jenkins from 10.30.104.4 port 37178 Apr 2 14:25:48 prd-ubuntu1804-docker-8c-8g-3308 sshd[1800]: Received disconnect from 10.30.104.4 port 37178:11: Closed due to user request. [preauth] Apr 2 14:25:48 prd-ubuntu1804-docker-8c-8g-3308 sshd[1800]: Disconnected from invalid user jenkins 10.30.104.4 port 37178 [preauth] Apr 2 14:25:50 prd-ubuntu1804-docker-8c-8g-3308 sshd[1810]: Invalid user jenkins from 10.30.104.4 port 37210 Apr 2 14:25:50 prd-ubuntu1804-docker-8c-8g-3308 sshd[1810]: Received disconnect from 10.30.104.4 port 37210:11: Closed due to user request. [preauth] Apr 2 14:25:50 prd-ubuntu1804-docker-8c-8g-3308 sshd[1810]: Disconnected from invalid user jenkins 10.30.104.4 port 37210 [preauth] Apr 2 14:25:51 prd-ubuntu1804-docker-8c-8g-3308 useradd[1817]: new group: name=jenkins, GID=1001 Apr 2 14:25:51 prd-ubuntu1804-docker-8c-8g-3308 useradd[1817]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Apr 2 14:25:52 prd-ubuntu1804-docker-8c-8g-3308 sshd[1818]: Received disconnect from 10.30.104.4 port 37230:11: Closed due to user request. [preauth] Apr 2 14:25:52 prd-ubuntu1804-docker-8c-8g-3308 sshd[1818]: Disconnected from authenticating user jenkins 10.30.104.4 port 37230 [preauth] Apr 2 14:25:52 prd-ubuntu1804-docker-8c-8g-3308 usermod[1826]: add 'jenkins' to group 'docker' Apr 2 14:25:52 prd-ubuntu1804-docker-8c-8g-3308 usermod[1826]: add 'jenkins' to shadow group 'docker' Apr 2 14:25:54 prd-ubuntu1804-docker-8c-8g-3308 sshd[1887]: Accepted publickey for jenkins from 10.30.104.4 port 37250 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Apr 2 14:25:54 prd-ubuntu1804-docker-8c-8g-3308 sshd[1887]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Apr 2 14:25:54 prd-ubuntu1804-docker-8c-8g-3308 systemd-logind[1071]: New session 1 of user jenkins. Apr 2 14:25:54 prd-ubuntu1804-docker-8c-8g-3308 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Apr 2 14:26:01 prd-ubuntu1804-docker-8c-8g-3308 CRON[2118]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 2 14:26:01 prd-ubuntu1804-docker-8c-8g-3308 CRON[2118]: pam_unix(cron:session): session closed for user root Apr 2 14:27:01 prd-ubuntu1804-docker-8c-8g-3308 CRON[2962]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 2 14:27:01 prd-ubuntu1804-docker-8c-8g-3308 CRON[2962]: pam_unix(cron:session): session closed for user root Apr 2 14:28:01 prd-ubuntu1804-docker-8c-8g-3308 CRON[5989]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 2 14:28:01 prd-ubuntu1804-docker-8c-8g-3308 CRON[5989]: pam_unix(cron:session): session closed for user root Apr 2 14:29:01 prd-ubuntu1804-docker-8c-8g-3308 CRON[9524]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 2 14:29:01 prd-ubuntu1804-docker-8c-8g-3308 CRON[9524]: pam_unix(cron:session): session closed for user root Apr 2 14:30:01 prd-ubuntu1804-docker-8c-8g-3308 CRON[10007]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 2 14:30:01 prd-ubuntu1804-docker-8c-8g-3308 CRON[10007]: pam_unix(cron:session): session closed for user root Apr 2 14:31:01 prd-ubuntu1804-docker-8c-8g-3308 CRON[10560]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 2 14:31:01 prd-ubuntu1804-docker-8c-8g-3308 CRON[10560]: pam_unix(cron:session): session closed for user root Apr 2 14:31:06 prd-ubuntu1804-docker-8c-8g-3308 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/integration-xtesting-security-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Apr 2 14:31:06 prd-ubuntu1804-docker-8c-8g-3308 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)