Jan 26 11:44:11 prd-ubuntu1804-docker-8c-8g-3105 passwd[1003]: password for 'ubuntu' changed by 'root' Jan 26 11:44:11 prd-ubuntu1804-docker-8c-8g-3105 systemd-logind[1045]: Watching system buttons on /dev/input/event0 (Power Button) Jan 26 11:44:11 prd-ubuntu1804-docker-8c-8g-3105 systemd-logind[1045]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jan 26 11:44:11 prd-ubuntu1804-docker-8c-8g-3105 systemd-logind[1045]: New seat seat0. Jan 26 11:44:11 prd-ubuntu1804-docker-8c-8g-3105 sshd[1143]: Server listening on 0.0.0.0 port 22. Jan 26 11:44:11 prd-ubuntu1804-docker-8c-8g-3105 sshd[1143]: Server listening on :: port 22. Jan 26 11:44:14 prd-ubuntu1804-docker-8c-8g-3105 sshd[1456]: Did not receive identification string from 10.30.104.4 port 53284 Jan 26 11:44:22 prd-ubuntu1804-docker-8c-8g-3105 sshd[1483]: Invalid user jenkins from 10.30.104.4 port 53308 Jan 26 11:44:22 prd-ubuntu1804-docker-8c-8g-3105 sshd[1483]: Received disconnect from 10.30.104.4 port 53308:11: Closed due to user request. [preauth] Jan 26 11:44:22 prd-ubuntu1804-docker-8c-8g-3105 sshd[1483]: Disconnected from invalid user jenkins 10.30.104.4 port 53308 [preauth] Jan 26 11:44:24 prd-ubuntu1804-docker-8c-8g-3105 sshd[1487]: Invalid user jenkins from 10.30.104.4 port 53314 Jan 26 11:44:24 prd-ubuntu1804-docker-8c-8g-3105 sshd[1487]: Received disconnect from 10.30.104.4 port 53314:11: Closed due to user request. [preauth] Jan 26 11:44:24 prd-ubuntu1804-docker-8c-8g-3105 sshd[1487]: Disconnected from invalid user jenkins 10.30.104.4 port 53314 [preauth] Jan 26 11:44:26 prd-ubuntu1804-docker-8c-8g-3105 sshd[1489]: Invalid user jenkins from 10.30.104.4 port 53322 Jan 26 11:44:26 prd-ubuntu1804-docker-8c-8g-3105 sshd[1489]: Received disconnect from 10.30.104.4 port 53322:11: Closed due to user request. [preauth] Jan 26 11:44:26 prd-ubuntu1804-docker-8c-8g-3105 sshd[1489]: Disconnected from invalid user jenkins 10.30.104.4 port 53322 [preauth] Jan 26 11:44:28 prd-ubuntu1804-docker-8c-8g-3105 sshd[1572]: Invalid user jenkins from 10.30.104.4 port 53330 Jan 26 11:44:28 prd-ubuntu1804-docker-8c-8g-3105 sshd[1572]: Received disconnect from 10.30.104.4 port 53330:11: Closed due to user request. [preauth] Jan 26 11:44:28 prd-ubuntu1804-docker-8c-8g-3105 sshd[1572]: Disconnected from invalid user jenkins 10.30.104.4 port 53330 [preauth] Jan 26 11:44:31 prd-ubuntu1804-docker-8c-8g-3105 sshd[1737]: Invalid user jenkins from 10.30.104.4 port 53336 Jan 26 11:44:31 prd-ubuntu1804-docker-8c-8g-3105 sshd[1737]: Received disconnect from 10.30.104.4 port 53336:11: Closed due to user request. [preauth] Jan 26 11:44:31 prd-ubuntu1804-docker-8c-8g-3105 sshd[1737]: Disconnected from invalid user jenkins 10.30.104.4 port 53336 [preauth] Jan 26 11:44:33 prd-ubuntu1804-docker-8c-8g-3105 sshd[1759]: Invalid user jenkins from 10.30.104.4 port 53350 Jan 26 11:44:33 prd-ubuntu1804-docker-8c-8g-3105 sshd[1759]: Received disconnect from 10.30.104.4 port 53350:11: Closed due to user request. [preauth] Jan 26 11:44:33 prd-ubuntu1804-docker-8c-8g-3105 sshd[1759]: Disconnected from invalid user jenkins 10.30.104.4 port 53350 [preauth] Jan 26 11:44:35 prd-ubuntu1804-docker-8c-8g-3105 sshd[1761]: Invalid user jenkins from 10.30.104.4 port 53358 Jan 26 11:44:35 prd-ubuntu1804-docker-8c-8g-3105 sshd[1761]: Received disconnect from 10.30.104.4 port 53358:11: Closed due to user request. [preauth] Jan 26 11:44:35 prd-ubuntu1804-docker-8c-8g-3105 sshd[1761]: Disconnected from invalid user jenkins 10.30.104.4 port 53358 [preauth] Jan 26 11:44:37 prd-ubuntu1804-docker-8c-8g-3105 sshd[1772]: Invalid user jenkins from 10.30.104.4 port 53364 Jan 26 11:44:37 prd-ubuntu1804-docker-8c-8g-3105 sshd[1772]: Received disconnect from 10.30.104.4 port 53364:11: Closed due to user request. [preauth] Jan 26 11:44:37 prd-ubuntu1804-docker-8c-8g-3105 sshd[1772]: Disconnected from invalid user jenkins 10.30.104.4 port 53364 [preauth] Jan 26 11:44:38 prd-ubuntu1804-docker-8c-8g-3105 useradd[1792]: new group: name=jenkins, GID=1001 Jan 26 11:44:38 prd-ubuntu1804-docker-8c-8g-3105 useradd[1792]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Jan 26 11:44:38 prd-ubuntu1804-docker-8c-8g-3105 usermod[1799]: add 'jenkins' to group 'docker' Jan 26 11:44:38 prd-ubuntu1804-docker-8c-8g-3105 usermod[1799]: add 'jenkins' to shadow group 'docker' Jan 26 11:44:39 prd-ubuntu1804-docker-8c-8g-3105 sshd[1866]: Accepted publickey for jenkins from 10.30.104.4 port 53370 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Jan 26 11:44:39 prd-ubuntu1804-docker-8c-8g-3105 sshd[1866]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jan 26 11:44:39 prd-ubuntu1804-docker-8c-8g-3105 systemd-logind[1045]: New session 1 of user jenkins. Jan 26 11:44:39 prd-ubuntu1804-docker-8c-8g-3105 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jan 26 11:45:01 prd-ubuntu1804-docker-8c-8g-3105 CRON[2414]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 26 11:45:01 prd-ubuntu1804-docker-8c-8g-3105 CRON[2414]: pam_unix(cron:session): session closed for user root Jan 26 11:46:01 prd-ubuntu1804-docker-8c-8g-3105 CRON[3541]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 26 11:46:01 prd-ubuntu1804-docker-8c-8g-3105 CRON[3541]: pam_unix(cron:session): session closed for user root Jan 26 11:47:01 prd-ubuntu1804-docker-8c-8g-3105 CRON[3728]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 26 11:47:01 prd-ubuntu1804-docker-8c-8g-3105 CRON[3728]: pam_unix(cron:session): session closed for user root Jan 26 11:48:01 prd-ubuntu1804-docker-8c-8g-3105 CRON[4413]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 26 11:48:01 prd-ubuntu1804-docker-8c-8g-3105 CRON[4413]: pam_unix(cron:session): session closed for user root Jan 26 11:48:30 prd-ubuntu1804-docker-8c-8g-3105 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/integration-xtesting-smoke-usecases-robot-docker-verify-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Jan 26 11:48:30 prd-ubuntu1804-docker-8c-8g-3105 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)