Dec 29 04:42:30 prd-ubuntu1804-docker-8c-8g-1982 passwd[1005]: password for 'ubuntu' changed by 'root' Dec 29 04:42:30 prd-ubuntu1804-docker-8c-8g-1982 systemd-logind[1117]: Watching system buttons on /dev/input/event0 (Power Button) Dec 29 04:42:30 prd-ubuntu1804-docker-8c-8g-1982 systemd-logind[1117]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Dec 29 04:42:30 prd-ubuntu1804-docker-8c-8g-1982 systemd-logind[1117]: New seat seat0. Dec 29 04:42:30 prd-ubuntu1804-docker-8c-8g-1982 sshd[1200]: Server listening on 0.0.0.0 port 22. Dec 29 04:42:30 prd-ubuntu1804-docker-8c-8g-1982 sshd[1200]: Server listening on :: port 22. Dec 29 04:42:33 prd-ubuntu1804-docker-8c-8g-1982 sshd[1464]: Did not receive identification string from 10.30.104.4 port 43302 Dec 29 04:42:40 prd-ubuntu1804-docker-8c-8g-1982 sshd[1509]: Invalid user jenkins from 10.30.104.4 port 43310 Dec 29 04:42:40 prd-ubuntu1804-docker-8c-8g-1982 sshd[1509]: Received disconnect from 10.30.104.4 port 43310:11: Closed due to user request. [preauth] Dec 29 04:42:40 prd-ubuntu1804-docker-8c-8g-1982 sshd[1509]: Disconnected from invalid user jenkins 10.30.104.4 port 43310 [preauth] Dec 29 04:42:42 prd-ubuntu1804-docker-8c-8g-1982 sshd[1513]: Invalid user jenkins from 10.30.104.4 port 43316 Dec 29 04:42:42 prd-ubuntu1804-docker-8c-8g-1982 sshd[1513]: Received disconnect from 10.30.104.4 port 43316:11: Closed due to user request. [preauth] Dec 29 04:42:42 prd-ubuntu1804-docker-8c-8g-1982 sshd[1513]: Disconnected from invalid user jenkins 10.30.104.4 port 43316 [preauth] Dec 29 04:42:44 prd-ubuntu1804-docker-8c-8g-1982 sshd[1515]: Invalid user jenkins from 10.30.104.4 port 43318 Dec 29 04:42:44 prd-ubuntu1804-docker-8c-8g-1982 sshd[1515]: Received disconnect from 10.30.104.4 port 43318:11: Closed due to user request. [preauth] Dec 29 04:42:44 prd-ubuntu1804-docker-8c-8g-1982 sshd[1515]: Disconnected from invalid user jenkins 10.30.104.4 port 43318 [preauth] Dec 29 04:42:46 prd-ubuntu1804-docker-8c-8g-1982 sshd[1517]: Invalid user jenkins from 10.30.104.4 port 43320 Dec 29 04:42:46 prd-ubuntu1804-docker-8c-8g-1982 sshd[1517]: Received disconnect from 10.30.104.4 port 43320:11: Closed due to user request. [preauth] Dec 29 04:42:46 prd-ubuntu1804-docker-8c-8g-1982 sshd[1517]: Disconnected from invalid user jenkins 10.30.104.4 port 43320 [preauth] Dec 29 04:42:48 prd-ubuntu1804-docker-8c-8g-1982 sshd[1674]: Invalid user jenkins from 10.30.104.4 port 43322 Dec 29 04:42:48 prd-ubuntu1804-docker-8c-8g-1982 sshd[1674]: Received disconnect from 10.30.104.4 port 43322:11: Closed due to user request. [preauth] Dec 29 04:42:48 prd-ubuntu1804-docker-8c-8g-1982 sshd[1674]: Disconnected from invalid user jenkins 10.30.104.4 port 43322 [preauth] Dec 29 04:42:50 prd-ubuntu1804-docker-8c-8g-1982 sshd[1786]: Invalid user jenkins from 10.30.104.4 port 43324 Dec 29 04:42:50 prd-ubuntu1804-docker-8c-8g-1982 sshd[1786]: Received disconnect from 10.30.104.4 port 43324:11: Closed due to user request. [preauth] Dec 29 04:42:50 prd-ubuntu1804-docker-8c-8g-1982 sshd[1786]: Disconnected from invalid user jenkins 10.30.104.4 port 43324 [preauth] Dec 29 04:42:52 prd-ubuntu1804-docker-8c-8g-1982 sshd[1790]: Invalid user jenkins from 10.30.104.4 port 43326 Dec 29 04:42:53 prd-ubuntu1804-docker-8c-8g-1982 sshd[1790]: Received disconnect from 10.30.104.4 port 43326:11: Closed due to user request. [preauth] Dec 29 04:42:53 prd-ubuntu1804-docker-8c-8g-1982 sshd[1790]: Disconnected from invalid user jenkins 10.30.104.4 port 43326 [preauth] Dec 29 04:42:55 prd-ubuntu1804-docker-8c-8g-1982 sshd[1792]: Invalid user jenkins from 10.30.104.4 port 43328 Dec 29 04:42:55 prd-ubuntu1804-docker-8c-8g-1982 sshd[1792]: Received disconnect from 10.30.104.4 port 43328:11: Closed due to user request. [preauth] Dec 29 04:42:55 prd-ubuntu1804-docker-8c-8g-1982 sshd[1792]: Disconnected from invalid user jenkins 10.30.104.4 port 43328 [preauth] Dec 29 04:42:56 prd-ubuntu1804-docker-8c-8g-1982 useradd[1818]: new group: name=jenkins, GID=1001 Dec 29 04:42:56 prd-ubuntu1804-docker-8c-8g-1982 useradd[1818]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash Dec 29 04:42:56 prd-ubuntu1804-docker-8c-8g-1982 usermod[1825]: add 'jenkins' to group 'docker' Dec 29 04:42:56 prd-ubuntu1804-docker-8c-8g-1982 usermod[1825]: add 'jenkins' to shadow group 'docker' Dec 29 04:42:57 prd-ubuntu1804-docker-8c-8g-1982 sshd[1886]: Accepted publickey for jenkins from 10.30.104.4 port 43332 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Dec 29 04:42:57 prd-ubuntu1804-docker-8c-8g-1982 sshd[1886]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Dec 29 04:42:57 prd-ubuntu1804-docker-8c-8g-1982 systemd-logind[1117]: New session 1 of user jenkins. Dec 29 04:42:57 prd-ubuntu1804-docker-8c-8g-1982 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Dec 29 04:43:01 prd-ubuntu1804-docker-8c-8g-1982 CRON[2113]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 29 04:43:01 prd-ubuntu1804-docker-8c-8g-1982 CRON[2113]: pam_unix(cron:session): session closed for user root Dec 29 04:44:01 prd-ubuntu1804-docker-8c-8g-1982 CRON[2468]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 29 04:44:01 prd-ubuntu1804-docker-8c-8g-1982 CRON[2468]: pam_unix(cron:session): session closed for user root Dec 29 04:45:01 prd-ubuntu1804-docker-8c-8g-1982 CRON[4428]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 29 04:45:01 prd-ubuntu1804-docker-8c-8g-1982 CRON[4428]: pam_unix(cron:session): session closed for user root Dec 29 04:46:01 prd-ubuntu1804-docker-8c-8g-1982 CRON[5192]: pam_unix(cron:session): session opened for user root by (uid=0) Dec 29 04:46:01 prd-ubuntu1804-docker-8c-8g-1982 CRON[5192]: pam_unix(cron:session): session closed for user root Dec 29 04:46:02 prd-ubuntu1804-docker-8c-8g-1982 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/integration-xtesting-smoke-usecases-robot-py3-docker-merge-master ; USER=root ; COMMAND=/bin/cp /var/log/auth.log /tmp Dec 29 04:46:02 prd-ubuntu1804-docker-8c-8g-1982 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)