Apr 5 11:21:53 prd-ubuntu1804-docker-8c-8g-20740 passwd[977]: password for 'ubuntu' changed by 'root' Apr 5 11:21:53 prd-ubuntu1804-docker-8c-8g-20740 systemd-logind[1006]: Watching system buttons on /dev/input/event0 (Power Button) Apr 5 11:21:53 prd-ubuntu1804-docker-8c-8g-20740 systemd-logind[1006]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Apr 5 11:21:53 prd-ubuntu1804-docker-8c-8g-20740 systemd-logind[1006]: New seat seat0. Apr 5 11:21:53 prd-ubuntu1804-docker-8c-8g-20740 sshd[1123]: Server listening on 0.0.0.0 port 22. Apr 5 11:21:53 prd-ubuntu1804-docker-8c-8g-20740 sshd[1123]: Server listening on :: port 22. Apr 5 11:21:55 prd-ubuntu1804-docker-8c-8g-20740 sshd[1390]: Did not receive identification string from 10.30.104.4 port 55884 Apr 5 11:22:01 prd-ubuntu1804-docker-8c-8g-20740 CRON[1414]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 5 11:22:01 prd-ubuntu1804-docker-8c-8g-20740 CRON[1414]: pam_unix(cron:session): session closed for user root Apr 5 11:22:03 prd-ubuntu1804-docker-8c-8g-20740 sshd[1423]: Invalid user jenkins from 10.30.104.4 port 55906 Apr 5 11:22:03 prd-ubuntu1804-docker-8c-8g-20740 sshd[1423]: Received disconnect from 10.30.104.4 port 55906:11: Closed due to user request. [preauth] Apr 5 11:22:03 prd-ubuntu1804-docker-8c-8g-20740 sshd[1423]: Disconnected from invalid user jenkins 10.30.104.4 port 55906 [preauth] Apr 5 11:22:05 prd-ubuntu1804-docker-8c-8g-20740 sshd[1427]: Invalid user jenkins from 10.30.104.4 port 55914 Apr 5 11:22:05 prd-ubuntu1804-docker-8c-8g-20740 sshd[1427]: Received disconnect from 10.30.104.4 port 55914:11: Closed due to user request. [preauth] Apr 5 11:22:05 prd-ubuntu1804-docker-8c-8g-20740 sshd[1427]: Disconnected from invalid user jenkins 10.30.104.4 port 55914 [preauth] Apr 5 11:22:07 prd-ubuntu1804-docker-8c-8g-20740 sshd[1429]: Invalid user jenkins from 10.30.104.4 port 55920 Apr 5 11:22:07 prd-ubuntu1804-docker-8c-8g-20740 sshd[1429]: Received disconnect from 10.30.104.4 port 55920:11: Closed due to user request. [preauth] Apr 5 11:22:07 prd-ubuntu1804-docker-8c-8g-20740 sshd[1429]: Disconnected from invalid user jenkins 10.30.104.4 port 55920 [preauth] Apr 5 11:22:09 prd-ubuntu1804-docker-8c-8g-20740 sshd[1451]: Invalid user jenkins from 10.30.104.4 port 55932 Apr 5 11:22:09 prd-ubuntu1804-docker-8c-8g-20740 sshd[1451]: Received disconnect from 10.30.104.4 port 55932:11: Closed due to user request. [preauth] Apr 5 11:22:09 prd-ubuntu1804-docker-8c-8g-20740 sshd[1451]: Disconnected from invalid user jenkins 10.30.104.4 port 55932 [preauth] Apr 5 11:22:12 prd-ubuntu1804-docker-8c-8g-20740 sshd[1661]: Invalid user jenkins from 10.30.104.4 port 55938 Apr 5 11:22:13 prd-ubuntu1804-docker-8c-8g-20740 sshd[1661]: Received disconnect from 10.30.104.4 port 55938:11: Closed due to user request. [preauth] Apr 5 11:22:13 prd-ubuntu1804-docker-8c-8g-20740 sshd[1661]: Disconnected from invalid user jenkins 10.30.104.4 port 55938 [preauth] Apr 5 11:22:15 prd-ubuntu1804-docker-8c-8g-20740 sshd[1679]: Invalid user jenkins from 10.30.104.4 port 55948 Apr 5 11:22:15 prd-ubuntu1804-docker-8c-8g-20740 sshd[1679]: Received disconnect from 10.30.104.4 port 55948:11: Closed due to user request. [preauth] Apr 5 11:22:15 prd-ubuntu1804-docker-8c-8g-20740 sshd[1679]: Disconnected from invalid user jenkins 10.30.104.4 port 55948 [preauth] Apr 5 11:22:17 prd-ubuntu1804-docker-8c-8g-20740 sshd[1722]: Invalid user jenkins from 10.30.104.4 port 55954 Apr 5 11:22:17 prd-ubuntu1804-docker-8c-8g-20740 sshd[1722]: Received disconnect from 10.30.104.4 port 55954:11: Closed due to user request. [preauth] Apr 5 11:22:17 prd-ubuntu1804-docker-8c-8g-20740 sshd[1722]: Disconnected from invalid user jenkins 10.30.104.4 port 55954 [preauth] Apr 5 11:22:19 prd-ubuntu1804-docker-8c-8g-20740 sshd[1732]: Invalid user jenkins from 10.30.104.4 port 55956 Apr 5 11:22:19 prd-ubuntu1804-docker-8c-8g-20740 sshd[1732]: Received disconnect from 10.30.104.4 port 55956:11: Closed due to user request. [preauth] Apr 5 11:22:19 prd-ubuntu1804-docker-8c-8g-20740 sshd[1732]: Disconnected from invalid user jenkins 10.30.104.4 port 55956 [preauth] Apr 5 11:22:19 prd-ubuntu1804-docker-8c-8g-20740 useradd[1751]: new group: name=jenkins, GID=1001 Apr 5 11:22:19 prd-ubuntu1804-docker-8c-8g-20740 useradd[1751]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Apr 5 11:22:19 prd-ubuntu1804-docker-8c-8g-20740 usermod[1758]: add 'jenkins' to group 'docker' Apr 5 11:22:19 prd-ubuntu1804-docker-8c-8g-20740 usermod[1758]: add 'jenkins' to shadow group 'docker' Apr 5 11:22:21 prd-ubuntu1804-docker-8c-8g-20740 sshd[1819]: Accepted publickey for jenkins from 10.30.104.4 port 55960 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Apr 5 11:22:21 prd-ubuntu1804-docker-8c-8g-20740 sshd[1819]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Apr 5 11:22:21 prd-ubuntu1804-docker-8c-8g-20740 systemd-logind[1006]: New session 2 of user jenkins. Apr 5 11:22:21 prd-ubuntu1804-docker-8c-8g-20740 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Apr 5 11:23:02 prd-ubuntu1804-docker-8c-8g-20740 CRON[2475]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 5 11:23:02 prd-ubuntu1804-docker-8c-8g-20740 CRON[2475]: pam_unix(cron:session): session closed for user root Apr 5 11:24:01 prd-ubuntu1804-docker-8c-8g-20740 CRON[3308]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 5 11:24:01 prd-ubuntu1804-docker-8c-8g-20740 CRON[3308]: pam_unix(cron:session): session closed for user root Apr 5 11:25:01 prd-ubuntu1804-docker-8c-8g-20740 CRON[4032]: pam_unix(cron:session): session opened for user root by (uid=0) Apr 5 11:25:01 prd-ubuntu1804-docker-8c-8g-20740 CRON[4032]: pam_unix(cron:session): session closed for user root Apr 5 11:25:21 prd-ubuntu1804-docker-8c-8g-20740 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/integration-xtesting-smoke-usecases-pythonsdk-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Apr 5 11:25:21 prd-ubuntu1804-docker-8c-8g-20740 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)