Oct 25 07:57:40 prd-ubuntu2004-docker-8c-8g-1084 passwd[754]: password for 'ubuntu' changed by 'root' Oct 25 07:57:40 prd-ubuntu2004-docker-8c-8g-1084 sshd[838]: Server listening on 0.0.0.0 port 22. Oct 25 07:57:40 prd-ubuntu2004-docker-8c-8g-1084 sshd[838]: Server listening on :: port 22. Oct 25 07:57:40 prd-ubuntu2004-docker-8c-8g-1084 systemd-logind[816]: New seat seat0. Oct 25 07:57:40 prd-ubuntu2004-docker-8c-8g-1084 systemd-logind[816]: Watching system buttons on /dev/input/event0 (Power Button) Oct 25 07:57:40 prd-ubuntu2004-docker-8c-8g-1084 systemd-logind[816]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Oct 25 07:57:43 prd-ubuntu2004-docker-8c-8g-1084 sshd[1693]: error: kex_exchange_identification: Connection closed by remote host Oct 25 07:57:49 prd-ubuntu2004-docker-8c-8g-1084 sshd[3468]: Invalid user jenkins from 10.30.168.15 port 51888 Oct 25 07:57:49 prd-ubuntu2004-docker-8c-8g-1084 sshd[3468]: Received disconnect from 10.30.168.15 port 51888:11: Closed due to user request. [preauth] Oct 25 07:57:49 prd-ubuntu2004-docker-8c-8g-1084 sshd[3468]: Disconnected from invalid user jenkins 10.30.168.15 port 51888 [preauth] Oct 25 07:57:52 prd-ubuntu2004-docker-8c-8g-1084 sshd[4404]: Invalid user jenkins from 10.30.168.15 port 51906 Oct 25 07:57:52 prd-ubuntu2004-docker-8c-8g-1084 sshd[4404]: Received disconnect from 10.30.168.15 port 51906:11: Closed due to user request. [preauth] Oct 25 07:57:52 prd-ubuntu2004-docker-8c-8g-1084 sshd[4404]: Disconnected from invalid user jenkins 10.30.168.15 port 51906 [preauth] Oct 25 07:57:55 prd-ubuntu2004-docker-8c-8g-1084 sshd[5184]: Invalid user jenkins from 10.30.168.15 port 51916 Oct 25 07:57:55 prd-ubuntu2004-docker-8c-8g-1084 sshd[5184]: Received disconnect from 10.30.168.15 port 51916:11: Closed due to user request. [preauth] Oct 25 07:57:55 prd-ubuntu2004-docker-8c-8g-1084 sshd[5184]: Disconnected from invalid user jenkins 10.30.168.15 port 51916 [preauth] Oct 25 07:57:58 prd-ubuntu2004-docker-8c-8g-1084 sshd[5960]: Invalid user jenkins from 10.30.168.15 port 51930 Oct 25 07:57:58 prd-ubuntu2004-docker-8c-8g-1084 sshd[5960]: Received disconnect from 10.30.168.15 port 51930:11: Closed due to user request. [preauth] Oct 25 07:57:58 prd-ubuntu2004-docker-8c-8g-1084 sshd[5960]: Disconnected from invalid user jenkins 10.30.168.15 port 51930 [preauth] Oct 25 07:58:02 prd-ubuntu2004-docker-8c-8g-1084 sshd[7054]: Invalid user jenkins from 10.30.168.15 port 51940 Oct 25 07:58:02 prd-ubuntu2004-docker-8c-8g-1084 sshd[7054]: Received disconnect from 10.30.168.15 port 51940:11: Closed due to user request. [preauth] Oct 25 07:58:02 prd-ubuntu2004-docker-8c-8g-1084 sshd[7054]: Disconnected from invalid user jenkins 10.30.168.15 port 51940 [preauth] Oct 25 07:58:02 prd-ubuntu2004-docker-8c-8g-1084 CRON[7313]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 25 07:58:02 prd-ubuntu2004-docker-8c-8g-1084 CRON[7313]: pam_unix(cron:session): session closed for user root Oct 25 07:58:04 prd-ubuntu2004-docker-8c-8g-1084 sshd[8036]: Invalid user jenkins from 10.30.168.15 port 51946 Oct 25 07:58:04 prd-ubuntu2004-docker-8c-8g-1084 sshd[8036]: Received disconnect from 10.30.168.15 port 51946:11: Closed due to user request. [preauth] Oct 25 07:58:04 prd-ubuntu2004-docker-8c-8g-1084 sshd[8036]: Disconnected from invalid user jenkins 10.30.168.15 port 51946 [preauth] Oct 25 07:58:07 prd-ubuntu2004-docker-8c-8g-1084 sshd[8438]: Invalid user jenkins from 10.30.168.15 port 51958 Oct 25 07:58:07 prd-ubuntu2004-docker-8c-8g-1084 sshd[8438]: Received disconnect from 10.30.168.15 port 51958:11: Closed due to user request. [preauth] Oct 25 07:58:07 prd-ubuntu2004-docker-8c-8g-1084 sshd[8438]: Disconnected from invalid user jenkins 10.30.168.15 port 51958 [preauth] Oct 25 07:58:10 prd-ubuntu2004-docker-8c-8g-1084 sshd[8858]: Invalid user jenkins from 10.30.168.15 port 51968 Oct 25 07:58:10 prd-ubuntu2004-docker-8c-8g-1084 sshd[8858]: Received disconnect from 10.30.168.15 port 51968:11: Closed due to user request. [preauth] Oct 25 07:58:10 prd-ubuntu2004-docker-8c-8g-1084 sshd[8858]: Disconnected from invalid user jenkins 10.30.168.15 port 51968 [preauth] Oct 25 07:58:12 prd-ubuntu2004-docker-8c-8g-1084 useradd[9177]: new group: name=jenkins, GID=1001 Oct 25 07:58:12 prd-ubuntu2004-docker-8c-8g-1084 useradd[9177]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Oct 25 07:58:12 prd-ubuntu2004-docker-8c-8g-1084 usermod[9242]: add 'jenkins' to group 'docker' Oct 25 07:58:12 prd-ubuntu2004-docker-8c-8g-1084 usermod[9242]: add 'jenkins' to shadow group 'docker' Oct 25 07:58:13 prd-ubuntu2004-docker-8c-8g-1084 sshd[9658]: Accepted publickey for jenkins from 10.30.168.15 port 51978 ssh2: RSA SHA256:BBsm4mRgG5V0fGum4Y1Rmy/vs16stdRVhwvexlLUhUs Oct 25 07:58:13 prd-ubuntu2004-docker-8c-8g-1084 sshd[9658]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Oct 25 07:58:13 prd-ubuntu2004-docker-8c-8g-1084 systemd-logind[816]: New session 2 of user jenkins. Oct 25 07:58:13 prd-ubuntu2004-docker-8c-8g-1084 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Oct 25 07:59:01 prd-ubuntu2004-docker-8c-8g-1084 CRON[23802]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 25 07:59:01 prd-ubuntu2004-docker-8c-8g-1084 CRON[23802]: pam_unix(cron:session): session closed for user root Oct 25 08:00:01 prd-ubuntu2004-docker-8c-8g-1084 CRON[29035]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 25 08:00:01 prd-ubuntu2004-docker-8c-8g-1084 CRON[29035]: pam_unix(cron:session): session closed for user root Oct 25 08:01:01 prd-ubuntu2004-docker-8c-8g-1084 CRON[30213]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 25 08:01:01 prd-ubuntu2004-docker-8c-8g-1084 CRON[30213]: pam_unix(cron:session): session closed for user root Oct 25 08:01:06 prd-ubuntu2004-docker-8c-8g-1084 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/bgpcep-tox-verify-master ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Oct 25 08:01:06 prd-ubuntu2004-docker-8c-8g-1084 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)