Feb 8 14:24:23 prd-ubuntu1804-docker-8c-8g-3800 passwd[975]: password for 'ubuntu' changed by 'root' Feb 8 14:24:23 prd-ubuntu1804-docker-8c-8g-3800 systemd-logind[1008]: Watching system buttons on /dev/input/event0 (Power Button) Feb 8 14:24:23 prd-ubuntu1804-docker-8c-8g-3800 systemd-logind[1008]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Feb 8 14:24:23 prd-ubuntu1804-docker-8c-8g-3800 systemd-logind[1008]: New seat seat0. Feb 8 14:24:23 prd-ubuntu1804-docker-8c-8g-3800 sshd[1096]: Server listening on 0.0.0.0 port 22. Feb 8 14:24:23 prd-ubuntu1804-docker-8c-8g-3800 sshd[1096]: Server listening on :: port 22. Feb 8 14:24:25 prd-ubuntu1804-docker-8c-8g-3800 sshd[1409]: Did not receive identification string from 10.30.104.4 port 33348 Feb 8 14:24:34 prd-ubuntu1804-docker-8c-8g-3800 sshd[1440]: Invalid user jenkins from 10.30.104.4 port 33358 Feb 8 14:24:34 prd-ubuntu1804-docker-8c-8g-3800 sshd[1440]: Received disconnect from 10.30.104.4 port 33358:11: Closed due to user request. [preauth] Feb 8 14:24:34 prd-ubuntu1804-docker-8c-8g-3800 sshd[1440]: Disconnected from invalid user jenkins 10.30.104.4 port 33358 [preauth] Feb 8 14:24:36 prd-ubuntu1804-docker-8c-8g-3800 sshd[1444]: Invalid user jenkins from 10.30.104.4 port 33366 Feb 8 14:24:36 prd-ubuntu1804-docker-8c-8g-3800 sshd[1444]: Received disconnect from 10.30.104.4 port 33366:11: Closed due to user request. [preauth] Feb 8 14:24:36 prd-ubuntu1804-docker-8c-8g-3800 sshd[1444]: Disconnected from invalid user jenkins 10.30.104.4 port 33366 [preauth] Feb 8 14:24:38 prd-ubuntu1804-docker-8c-8g-3800 sshd[1446]: Invalid user jenkins from 10.30.104.4 port 33374 Feb 8 14:24:39 prd-ubuntu1804-docker-8c-8g-3800 sshd[1446]: Received disconnect from 10.30.104.4 port 33374:11: Closed due to user request. [preauth] Feb 8 14:24:39 prd-ubuntu1804-docker-8c-8g-3800 sshd[1446]: Disconnected from invalid user jenkins 10.30.104.4 port 33374 [preauth] Feb 8 14:24:41 prd-ubuntu1804-docker-8c-8g-3800 sshd[1462]: Invalid user jenkins from 10.30.104.4 port 33382 Feb 8 14:24:41 prd-ubuntu1804-docker-8c-8g-3800 sshd[1462]: Received disconnect from 10.30.104.4 port 33382:11: Closed due to user request. [preauth] Feb 8 14:24:41 prd-ubuntu1804-docker-8c-8g-3800 sshd[1462]: Disconnected from invalid user jenkins 10.30.104.4 port 33382 [preauth] Feb 8 14:24:43 prd-ubuntu1804-docker-8c-8g-3800 sshd[1675]: Invalid user jenkins from 10.30.104.4 port 33388 Feb 8 14:24:43 prd-ubuntu1804-docker-8c-8g-3800 sshd[1675]: Received disconnect from 10.30.104.4 port 33388:11: Closed due to user request. [preauth] Feb 8 14:24:43 prd-ubuntu1804-docker-8c-8g-3800 sshd[1675]: Disconnected from invalid user jenkins 10.30.104.4 port 33388 [preauth] Feb 8 14:24:45 prd-ubuntu1804-docker-8c-8g-3800 sshd[1715]: Invalid user jenkins from 10.30.104.4 port 33398 Feb 8 14:24:45 prd-ubuntu1804-docker-8c-8g-3800 sshd[1715]: Received disconnect from 10.30.104.4 port 33398:11: Closed due to user request. [preauth] Feb 8 14:24:45 prd-ubuntu1804-docker-8c-8g-3800 sshd[1715]: Disconnected from invalid user jenkins 10.30.104.4 port 33398 [preauth] Feb 8 14:24:47 prd-ubuntu1804-docker-8c-8g-3800 sshd[1717]: Invalid user jenkins from 10.30.104.4 port 33400 Feb 8 14:24:47 prd-ubuntu1804-docker-8c-8g-3800 sshd[1717]: Received disconnect from 10.30.104.4 port 33400:11: Closed due to user request. [preauth] Feb 8 14:24:47 prd-ubuntu1804-docker-8c-8g-3800 sshd[1717]: Disconnected from invalid user jenkins 10.30.104.4 port 33400 [preauth] Feb 8 14:24:49 prd-ubuntu1804-docker-8c-8g-3800 sshd[1725]: Invalid user jenkins from 10.30.104.4 port 33402 Feb 8 14:24:49 prd-ubuntu1804-docker-8c-8g-3800 sshd[1725]: Received disconnect from 10.30.104.4 port 33402:11: Closed due to user request. [preauth] Feb 8 14:24:49 prd-ubuntu1804-docker-8c-8g-3800 sshd[1725]: Disconnected from invalid user jenkins 10.30.104.4 port 33402 [preauth] Feb 8 14:24:51 prd-ubuntu1804-docker-8c-8g-3800 useradd[1745]: new group: name=jenkins, GID=1001 Feb 8 14:24:51 prd-ubuntu1804-docker-8c-8g-3800 useradd[1745]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Feb 8 14:24:51 prd-ubuntu1804-docker-8c-8g-3800 usermod[1754]: add 'jenkins' to group 'docker' Feb 8 14:24:51 prd-ubuntu1804-docker-8c-8g-3800 usermod[1754]: add 'jenkins' to shadow group 'docker' Feb 8 14:24:51 prd-ubuntu1804-docker-8c-8g-3800 sshd[1746]: Received disconnect from 10.30.104.4 port 33408:11: Closed due to user request. [preauth] Feb 8 14:24:51 prd-ubuntu1804-docker-8c-8g-3800 sshd[1746]: Disconnected from authenticating user jenkins 10.30.104.4 port 33408 [preauth] Feb 8 14:24:53 prd-ubuntu1804-docker-8c-8g-3800 sshd[1821]: Accepted publickey for jenkins from 10.30.104.4 port 33412 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Feb 8 14:24:53 prd-ubuntu1804-docker-8c-8g-3800 sshd[1821]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Feb 8 14:24:53 prd-ubuntu1804-docker-8c-8g-3800 systemd-logind[1008]: New session 1 of user jenkins. Feb 8 14:24:53 prd-ubuntu1804-docker-8c-8g-3800 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Feb 8 14:25:01 prd-ubuntu1804-docker-8c-8g-3800 CRON[2104]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 8 14:25:01 prd-ubuntu1804-docker-8c-8g-3800 CRON[2104]: pam_unix(cron:session): session closed for user root Feb 8 14:26:01 prd-ubuntu1804-docker-8c-8g-3800 CRON[2641]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 8 14:26:01 prd-ubuntu1804-docker-8c-8g-3800 CRON[2641]: pam_unix(cron:session): session closed for user root Feb 8 14:27:01 prd-ubuntu1804-docker-8c-8g-3800 CRON[3274]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 8 14:27:01 prd-ubuntu1804-docker-8c-8g-3800 CRON[3274]: pam_unix(cron:session): session closed for user root Feb 8 14:27:40 prd-ubuntu1804-docker-8c-8g-3800 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/integration-xtesting-smoke-usecases-pythonsdk-docker-merge-kohn ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Feb 8 14:27:40 prd-ubuntu1804-docker-8c-8g-3800 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)