Nov 29 11:30:03 prd-ubuntu1804-docker-8c-8g-16278 passwd[1018]: password for 'ubuntu' changed by 'root' Nov 29 11:30:03 prd-ubuntu1804-docker-8c-8g-16278 systemd-logind[1101]: Watching system buttons on /dev/input/event0 (Power Button) Nov 29 11:30:03 prd-ubuntu1804-docker-8c-8g-16278 systemd-logind[1101]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Nov 29 11:30:03 prd-ubuntu1804-docker-8c-8g-16278 systemd-logind[1101]: New seat seat0. Nov 29 11:30:03 prd-ubuntu1804-docker-8c-8g-16278 sshd[1149]: Server listening on 0.0.0.0 port 22. Nov 29 11:30:03 prd-ubuntu1804-docker-8c-8g-16278 sshd[1149]: Server listening on :: port 22. Nov 29 11:30:06 prd-ubuntu1804-docker-8c-8g-16278 sshd[1397]: Did not receive identification string from 10.30.104.4 port 33976 Nov 29 11:30:13 prd-ubuntu1804-docker-8c-8g-16278 sshd[1426]: Invalid user jenkins from 10.30.104.4 port 33978 Nov 29 11:30:13 prd-ubuntu1804-docker-8c-8g-16278 sshd[1426]: Received disconnect from 10.30.104.4 port 33978:11: Closed due to user request. [preauth] Nov 29 11:30:13 prd-ubuntu1804-docker-8c-8g-16278 sshd[1426]: Disconnected from invalid user jenkins 10.30.104.4 port 33978 [preauth] Nov 29 11:30:15 prd-ubuntu1804-docker-8c-8g-16278 sshd[1430]: Invalid user jenkins from 10.30.104.4 port 33980 Nov 29 11:30:16 prd-ubuntu1804-docker-8c-8g-16278 sshd[1430]: Received disconnect from 10.30.104.4 port 33980:11: Closed due to user request. [preauth] Nov 29 11:30:16 prd-ubuntu1804-docker-8c-8g-16278 sshd[1430]: Disconnected from invalid user jenkins 10.30.104.4 port 33980 [preauth] Nov 29 11:30:18 prd-ubuntu1804-docker-8c-8g-16278 sshd[1432]: Invalid user jenkins from 10.30.104.4 port 33984 Nov 29 11:30:18 prd-ubuntu1804-docker-8c-8g-16278 sshd[1432]: Received disconnect from 10.30.104.4 port 33984:11: Closed due to user request. [preauth] Nov 29 11:30:18 prd-ubuntu1804-docker-8c-8g-16278 sshd[1432]: Disconnected from invalid user jenkins 10.30.104.4 port 33984 [preauth] Nov 29 11:30:20 prd-ubuntu1804-docker-8c-8g-16278 sshd[1434]: Invalid user jenkins from 10.30.104.4 port 33986 Nov 29 11:30:20 prd-ubuntu1804-docker-8c-8g-16278 sshd[1434]: Received disconnect from 10.30.104.4 port 33986:11: Closed due to user request. [preauth] Nov 29 11:30:20 prd-ubuntu1804-docker-8c-8g-16278 sshd[1434]: Disconnected from invalid user jenkins 10.30.104.4 port 33986 [preauth] Nov 29 11:30:22 prd-ubuntu1804-docker-8c-8g-16278 sshd[1654]: Invalid user jenkins from 10.30.104.4 port 33988 Nov 29 11:30:22 prd-ubuntu1804-docker-8c-8g-16278 sshd[1654]: Received disconnect from 10.30.104.4 port 33988:11: Closed due to user request. [preauth] Nov 29 11:30:22 prd-ubuntu1804-docker-8c-8g-16278 sshd[1654]: Disconnected from invalid user jenkins 10.30.104.4 port 33988 [preauth] Nov 29 11:30:24 prd-ubuntu1804-docker-8c-8g-16278 sshd[1700]: Invalid user jenkins from 10.30.104.4 port 33996 Nov 29 11:30:24 prd-ubuntu1804-docker-8c-8g-16278 sshd[1700]: Received disconnect from 10.30.104.4 port 33996:11: Closed due to user request. [preauth] Nov 29 11:30:24 prd-ubuntu1804-docker-8c-8g-16278 sshd[1700]: Disconnected from invalid user jenkins 10.30.104.4 port 33996 [preauth] Nov 29 11:30:26 prd-ubuntu1804-docker-8c-8g-16278 useradd[1720]: new group: name=jenkins, GID=1001 Nov 29 11:30:26 prd-ubuntu1804-docker-8c-8g-16278 useradd[1720]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Nov 29 11:30:26 prd-ubuntu1804-docker-8c-8g-16278 usermod[1727]: add 'jenkins' to group 'docker' Nov 29 11:30:26 prd-ubuntu1804-docker-8c-8g-16278 usermod[1727]: add 'jenkins' to shadow group 'docker' Nov 29 11:30:26 prd-ubuntu1804-docker-8c-8g-16278 sshd[1738]: Accepted publickey for jenkins from 10.30.104.4 port 34002 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Nov 29 11:30:26 prd-ubuntu1804-docker-8c-8g-16278 sshd[1738]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Nov 29 11:30:26 prd-ubuntu1804-docker-8c-8g-16278 systemd-logind[1101]: New session 1 of user jenkins. Nov 29 11:30:26 prd-ubuntu1804-docker-8c-8g-16278 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Nov 29 11:31:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[2370]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 29 11:31:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[2370]: pam_unix(cron:session): session closed for user root Nov 29 11:32:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[3499]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 29 11:32:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[3499]: pam_unix(cron:session): session closed for user root Nov 29 11:33:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[3665]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 29 11:33:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[3665]: pam_unix(cron:session): session closed for user root Nov 29 11:34:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[4347]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 29 11:34:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[4347]: pam_unix(cron:session): session closed for user root Nov 29 11:35:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[4674]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 29 11:35:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[4674]: pam_unix(cron:session): session closed for user root Nov 29 11:36:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[4677]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 29 11:36:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[4677]: pam_unix(cron:session): session closed for user root Nov 29 11:37:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[4879]: pam_unix(cron:session): session opened for user root by (uid=0) Nov 29 11:37:01 prd-ubuntu1804-docker-8c-8g-16278 CRON[4879]: pam_unix(cron:session): session closed for user root Nov 29 11:37:19 prd-ubuntu1804-docker-8c-8g-16278 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/integration-xtesting-smoke-usecases-robot-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Nov 29 11:37:19 prd-ubuntu1804-docker-8c-8g-16278 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)