Feb 27 13:38:58 prd-ubuntu2004-helm-2c-1g-320 passwd[709]: password for 'ubuntu' changed by 'root' Feb 27 13:38:58 prd-ubuntu2004-helm-2c-1g-320 sshd[805]: Server listening on 0.0.0.0 port 22. Feb 27 13:38:58 prd-ubuntu2004-helm-2c-1g-320 sshd[805]: Server listening on :: port 22. Feb 27 13:38:58 prd-ubuntu2004-helm-2c-1g-320 systemd-logind[763]: New seat seat0. Feb 27 13:38:58 prd-ubuntu2004-helm-2c-1g-320 systemd-logind[763]: Watching system buttons on /dev/input/event0 (Power Button) Feb 27 13:38:58 prd-ubuntu2004-helm-2c-1g-320 systemd-logind[763]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Feb 27 13:39:00 prd-ubuntu2004-helm-2c-1g-320 sshd[1312]: error: kex_exchange_identification: Connection closed by remote host Feb 27 13:39:01 prd-ubuntu2004-helm-2c-1g-320 CRON[1815]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:39:01 prd-ubuntu2004-helm-2c-1g-320 CRON[1815]: pam_unix(cron:session): session closed for user root Feb 27 13:39:08 prd-ubuntu2004-helm-2c-1g-320 sshd[4160]: Invalid user jenkins from 10.30.104.4 port 48936 Feb 27 13:39:08 prd-ubuntu2004-helm-2c-1g-320 sshd[4160]: Received disconnect from 10.30.104.4 port 48936:11: Closed due to user request. [preauth] Feb 27 13:39:08 prd-ubuntu2004-helm-2c-1g-320 sshd[4160]: Disconnected from invalid user jenkins 10.30.104.4 port 48936 [preauth] Feb 27 13:39:11 prd-ubuntu2004-helm-2c-1g-320 sshd[4853]: Invalid user jenkins from 10.30.104.4 port 48942 Feb 27 13:39:11 prd-ubuntu2004-helm-2c-1g-320 sshd[4853]: Received disconnect from 10.30.104.4 port 48942:11: Closed due to user request. [preauth] Feb 27 13:39:11 prd-ubuntu2004-helm-2c-1g-320 sshd[4853]: Disconnected from invalid user jenkins 10.30.104.4 port 48942 [preauth] Feb 27 13:39:13 prd-ubuntu2004-helm-2c-1g-320 sshd[5538]: Invalid user jenkins from 10.30.104.4 port 48944 Feb 27 13:39:13 prd-ubuntu2004-helm-2c-1g-320 sshd[5538]: Received disconnect from 10.30.104.4 port 48944:11: Closed due to user request. [preauth] Feb 27 13:39:13 prd-ubuntu2004-helm-2c-1g-320 sshd[5538]: Disconnected from invalid user jenkins 10.30.104.4 port 48944 [preauth] Feb 27 13:39:15 prd-ubuntu2004-helm-2c-1g-320 sshd[6261]: Invalid user jenkins from 10.30.104.4 port 48946 Feb 27 13:39:15 prd-ubuntu2004-helm-2c-1g-320 sshd[6261]: Received disconnect from 10.30.104.4 port 48946:11: Closed due to user request. [preauth] Feb 27 13:39:15 prd-ubuntu2004-helm-2c-1g-320 sshd[6261]: Disconnected from invalid user jenkins 10.30.104.4 port 48946 [preauth] Feb 27 13:39:17 prd-ubuntu2004-helm-2c-1g-320 sshd[7169]: Invalid user jenkins from 10.30.104.4 port 48948 Feb 27 13:39:17 prd-ubuntu2004-helm-2c-1g-320 sshd[7169]: Received disconnect from 10.30.104.4 port 48948:11: Closed due to user request. [preauth] Feb 27 13:39:17 prd-ubuntu2004-helm-2c-1g-320 sshd[7169]: Disconnected from invalid user jenkins 10.30.104.4 port 48948 [preauth] Feb 27 13:39:19 prd-ubuntu2004-helm-2c-1g-320 sshd[8031]: Invalid user jenkins from 10.30.104.4 port 48950 Feb 27 13:39:19 prd-ubuntu2004-helm-2c-1g-320 sshd[8031]: Received disconnect from 10.30.104.4 port 48950:11: Closed due to user request. [preauth] Feb 27 13:39:19 prd-ubuntu2004-helm-2c-1g-320 sshd[8031]: Disconnected from invalid user jenkins 10.30.104.4 port 48950 [preauth] Feb 27 13:39:21 prd-ubuntu2004-helm-2c-1g-320 sshd[8478]: Invalid user jenkins from 10.30.104.4 port 48952 Feb 27 13:39:22 prd-ubuntu2004-helm-2c-1g-320 sshd[8478]: Received disconnect from 10.30.104.4 port 48952:11: Closed due to user request. [preauth] Feb 27 13:39:22 prd-ubuntu2004-helm-2c-1g-320 sshd[8478]: Disconnected from invalid user jenkins 10.30.104.4 port 48952 [preauth] Feb 27 13:39:24 prd-ubuntu2004-helm-2c-1g-320 sshd[9164]: Invalid user jenkins from 10.30.104.4 port 48954 Feb 27 13:39:24 prd-ubuntu2004-helm-2c-1g-320 useradd[9183]: new group: name=jenkins, GID=1001 Feb 27 13:39:24 prd-ubuntu2004-helm-2c-1g-320 useradd[9183]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Feb 27 13:39:24 prd-ubuntu2004-helm-2c-1g-320 sshd[9164]: Received disconnect from 10.30.104.4 port 48954:11: Closed due to user request. [preauth] Feb 27 13:39:24 prd-ubuntu2004-helm-2c-1g-320 sshd[9164]: Disconnected from invalid user jenkins 10.30.104.4 port 48954 [preauth] Feb 27 13:39:24 prd-ubuntu2004-helm-2c-1g-320 usermod[9219]: add 'jenkins' to group 'docker' Feb 27 13:39:24 prd-ubuntu2004-helm-2c-1g-320 usermod[9219]: add 'jenkins' to shadow group 'docker' Feb 27 13:39:26 prd-ubuntu2004-helm-2c-1g-320 sshd[10024]: Accepted publickey for jenkins from 10.30.104.4 port 48958 ssh2: RSA SHA256:V0799BjlU//1ruj1g81rY7MeNIJkwAJ0Kr3lNX3XaN4 Feb 27 13:39:26 prd-ubuntu2004-helm-2c-1g-320 sshd[10024]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Feb 27 13:39:26 prd-ubuntu2004-helm-2c-1g-320 systemd-logind[763]: New session 2 of user jenkins. Feb 27 13:39:26 prd-ubuntu2004-helm-2c-1g-320 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Feb 27 13:40:01 prd-ubuntu2004-helm-2c-1g-320 CRON[22449]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:40:01 prd-ubuntu2004-helm-2c-1g-320 CRON[22449]: pam_unix(cron:session): session closed for user root Feb 27 13:41:01 prd-ubuntu2004-helm-2c-1g-320 CRON[28900]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:41:01 prd-ubuntu2004-helm-2c-1g-320 CRON[28900]: pam_unix(cron:session): session closed for user root Feb 27 13:42:01 prd-ubuntu2004-helm-2c-1g-320 CRON[29706]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:42:01 prd-ubuntu2004-helm-2c-1g-320 CRON[29706]: pam_unix(cron:session): session closed for user root Feb 27 13:43:01 prd-ubuntu2004-helm-2c-1g-320 CRON[30862]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:43:01 prd-ubuntu2004-helm-2c-1g-320 CRON[30862]: pam_unix(cron:session): session closed for user root Feb 27 13:44:01 prd-ubuntu2004-helm-2c-1g-320 CRON[31731]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:44:01 prd-ubuntu2004-helm-2c-1g-320 CRON[31731]: pam_unix(cron:session): session closed for user root Feb 27 13:45:01 prd-ubuntu2004-helm-2c-1g-320 CRON[32643]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:45:01 prd-ubuntu2004-helm-2c-1g-320 CRON[32643]: pam_unix(cron:session): session closed for user root Feb 27 13:46:01 prd-ubuntu2004-helm-2c-1g-320 CRON[33922]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:46:01 prd-ubuntu2004-helm-2c-1g-320 CRON[33922]: pam_unix(cron:session): session closed for user root Feb 27 13:47:01 prd-ubuntu2004-helm-2c-1g-320 CRON[34395]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:47:01 prd-ubuntu2004-helm-2c-1g-320 CRON[34395]: pam_unix(cron:session): session closed for user root Feb 27 13:48:01 prd-ubuntu2004-helm-2c-1g-320 CRON[34399]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:48:01 prd-ubuntu2004-helm-2c-1g-320 CRON[34399]: pam_unix(cron:session): session closed for user root Feb 27 13:49:01 prd-ubuntu2004-helm-2c-1g-320 CRON[34404]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:49:01 prd-ubuntu2004-helm-2c-1g-320 CRON[34404]: pam_unix(cron:session): session closed for user root Feb 27 13:50:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35256]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:50:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35256]: pam_unix(cron:session): session closed for user root Feb 27 13:51:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35771]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:51:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35771]: pam_unix(cron:session): session closed for user root Feb 27 13:52:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35807]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:52:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35807]: pam_unix(cron:session): session closed for user root Feb 27 13:53:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35810]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:53:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35810]: pam_unix(cron:session): session closed for user root Feb 27 13:54:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35836]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:54:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35836]: pam_unix(cron:session): session closed for user root Feb 27 13:55:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35840]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:55:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35840]: pam_unix(cron:session): session closed for user root Feb 27 13:56:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35845]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:56:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35845]: pam_unix(cron:session): session closed for user root Feb 27 13:57:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35848]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:57:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35848]: pam_unix(cron:session): session closed for user root Feb 27 13:58:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35852]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:58:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35852]: pam_unix(cron:session): session closed for user root Feb 27 13:59:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35856]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 13:59:01 prd-ubuntu2004-helm-2c-1g-320 CRON[35856]: pam_unix(cron:session): session closed for user root Feb 27 14:00:01 prd-ubuntu2004-helm-2c-1g-320 CRON[36864]: pam_unix(cron:session): session opened for user root by (uid=0) Feb 27 14:00:01 prd-ubuntu2004-helm-2c-1g-320 CRON[36864]: pam_unix(cron:session): session closed for user root Feb 27 14:00:18 prd-ubuntu2004-helm-2c-1g-320 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/oom-master-merge-helm ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Feb 27 14:00:18 prd-ubuntu2004-helm-2c-1g-320 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)