May 7 07:44:00 prd-ubuntu1804-docker-8c-8g-11307 passwd[995]: password for 'ubuntu' changed by 'root' May 7 07:44:00 prd-ubuntu1804-docker-8c-8g-11307 systemd-logind[1080]: Watching system buttons on /dev/input/event0 (Power Button) May 7 07:44:00 prd-ubuntu1804-docker-8c-8g-11307 systemd-logind[1080]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) May 7 07:44:00 prd-ubuntu1804-docker-8c-8g-11307 systemd-logind[1080]: New seat seat0. May 7 07:44:00 prd-ubuntu1804-docker-8c-8g-11307 sshd[1149]: Server listening on 0.0.0.0 port 22. May 7 07:44:00 prd-ubuntu1804-docker-8c-8g-11307 sshd[1149]: Server listening on :: port 22. May 7 07:44:03 prd-ubuntu1804-docker-8c-8g-11307 sshd[1395]: Did not receive identification string from 10.30.104.4 port 34598 May 7 07:44:11 prd-ubuntu1804-docker-8c-8g-11307 sshd[1440]: Invalid user jenkins from 10.30.104.4 port 34608 May 7 07:44:11 prd-ubuntu1804-docker-8c-8g-11307 sshd[1440]: Received disconnect from 10.30.104.4 port 34608:11: Closed due to user request. [preauth] May 7 07:44:11 prd-ubuntu1804-docker-8c-8g-11307 sshd[1440]: Disconnected from invalid user jenkins 10.30.104.4 port 34608 [preauth] May 7 07:44:13 prd-ubuntu1804-docker-8c-8g-11307 sshd[1444]: Invalid user jenkins from 10.30.104.4 port 34612 May 7 07:44:13 prd-ubuntu1804-docker-8c-8g-11307 sshd[1444]: Received disconnect from 10.30.104.4 port 34612:11: Closed due to user request. [preauth] May 7 07:44:13 prd-ubuntu1804-docker-8c-8g-11307 sshd[1444]: Disconnected from invalid user jenkins 10.30.104.4 port 34612 [preauth] May 7 07:44:15 prd-ubuntu1804-docker-8c-8g-11307 sshd[1446]: Invalid user jenkins from 10.30.104.4 port 34614 May 7 07:44:15 prd-ubuntu1804-docker-8c-8g-11307 sshd[1446]: Received disconnect from 10.30.104.4 port 34614:11: Closed due to user request. [preauth] May 7 07:44:15 prd-ubuntu1804-docker-8c-8g-11307 sshd[1446]: Disconnected from invalid user jenkins 10.30.104.4 port 34614 [preauth] May 7 07:44:17 prd-ubuntu1804-docker-8c-8g-11307 sshd[1454]: Invalid user jenkins from 10.30.104.4 port 34616 May 7 07:44:17 prd-ubuntu1804-docker-8c-8g-11307 sshd[1454]: Received disconnect from 10.30.104.4 port 34616:11: Closed due to user request. [preauth] May 7 07:44:17 prd-ubuntu1804-docker-8c-8g-11307 sshd[1454]: Disconnected from invalid user jenkins 10.30.104.4 port 34616 [preauth] May 7 07:44:20 prd-ubuntu1804-docker-8c-8g-11307 sshd[1675]: Invalid user jenkins from 10.30.104.4 port 34618 May 7 07:44:20 prd-ubuntu1804-docker-8c-8g-11307 sshd[1675]: Received disconnect from 10.30.104.4 port 34618:11: Closed due to user request. [preauth] May 7 07:44:20 prd-ubuntu1804-docker-8c-8g-11307 sshd[1675]: Disconnected from invalid user jenkins 10.30.104.4 port 34618 [preauth] May 7 07:44:22 prd-ubuntu1804-docker-8c-8g-11307 sshd[1715]: Invalid user jenkins from 10.30.104.4 port 34620 May 7 07:44:22 prd-ubuntu1804-docker-8c-8g-11307 sshd[1715]: Received disconnect from 10.30.104.4 port 34620:11: Closed due to user request. [preauth] May 7 07:44:22 prd-ubuntu1804-docker-8c-8g-11307 sshd[1715]: Disconnected from invalid user jenkins 10.30.104.4 port 34620 [preauth] May 7 07:44:24 prd-ubuntu1804-docker-8c-8g-11307 sshd[1717]: Invalid user jenkins from 10.30.104.4 port 34622 May 7 07:44:24 prd-ubuntu1804-docker-8c-8g-11307 sshd[1717]: Received disconnect from 10.30.104.4 port 34622:11: Closed due to user request. [preauth] May 7 07:44:24 prd-ubuntu1804-docker-8c-8g-11307 sshd[1717]: Disconnected from invalid user jenkins 10.30.104.4 port 34622 [preauth] May 7 07:44:27 prd-ubuntu1804-docker-8c-8g-11307 sshd[1727]: Invalid user jenkins from 10.30.104.4 port 34624 May 7 07:44:27 prd-ubuntu1804-docker-8c-8g-11307 sshd[1727]: Received disconnect from 10.30.104.4 port 34624:11: Closed due to user request. [preauth] May 7 07:44:27 prd-ubuntu1804-docker-8c-8g-11307 sshd[1727]: Disconnected from invalid user jenkins 10.30.104.4 port 34624 [preauth] May 7 07:44:28 prd-ubuntu1804-docker-8c-8g-11307 useradd[1747]: new group: name=jenkins, GID=1001 May 7 07:44:28 prd-ubuntu1804-docker-8c-8g-11307 useradd[1747]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash May 7 07:44:28 prd-ubuntu1804-docker-8c-8g-11307 usermod[1754]: add 'jenkins' to group 'docker' May 7 07:44:28 prd-ubuntu1804-docker-8c-8g-11307 usermod[1754]: add 'jenkins' to shadow group 'docker' May 7 07:44:29 prd-ubuntu1804-docker-8c-8g-11307 sshd[1822]: Accepted publickey for jenkins from 10.30.104.4 port 34628 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 May 7 07:44:29 prd-ubuntu1804-docker-8c-8g-11307 sshd[1822]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) May 7 07:44:29 prd-ubuntu1804-docker-8c-8g-11307 systemd-logind[1080]: New session 1 of user jenkins. May 7 07:44:29 prd-ubuntu1804-docker-8c-8g-11307 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) May 7 07:45:02 prd-ubuntu1804-docker-8c-8g-11307 CRON[2407]: pam_unix(cron:session): session opened for user root by (uid=0) May 7 07:45:02 prd-ubuntu1804-docker-8c-8g-11307 CRON[2407]: pam_unix(cron:session): session closed for user root May 7 07:46:01 prd-ubuntu1804-docker-8c-8g-11307 CRON[3100]: pam_unix(cron:session): session opened for user root by (uid=0) May 7 07:46:01 prd-ubuntu1804-docker-8c-8g-11307 CRON[3100]: pam_unix(cron:session): session closed for user root May 7 07:47:01 prd-ubuntu1804-docker-8c-8g-11307 CRON[3502]: pam_unix(cron:session): session opened for user root by (uid=0) May 7 07:47:01 prd-ubuntu1804-docker-8c-8g-11307 CRON[3502]: pam_unix(cron:session): session closed for user root May 7 07:48:01 prd-ubuntu1804-docker-8c-8g-11307 CRON[3873]: pam_unix(cron:session): session opened for user root by (uid=0) May 7 07:48:01 prd-ubuntu1804-docker-8c-8g-11307 CRON[3873]: pam_unix(cron:session): session closed for user root May 7 07:48:02 prd-ubuntu1804-docker-8c-8g-11307 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/integration-xtesting-smoke-usecases-pythonsdk-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp May 7 07:48:02 prd-ubuntu1804-docker-8c-8g-11307 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)