Jan 1 19:00:25 prd-ubuntu2004-docker-2c-2g-6869 passwd[683]: password for 'ubuntu' changed by 'root' Jan 1 19:00:25 prd-ubuntu2004-docker-2c-2g-6869 systemd-logind[723]: New seat seat0. Jan 1 19:00:25 prd-ubuntu2004-docker-2c-2g-6869 systemd-logind[723]: Watching system buttons on /dev/input/event0 (Power Button) Jan 1 19:00:25 prd-ubuntu2004-docker-2c-2g-6869 systemd-logind[723]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Jan 1 19:00:25 prd-ubuntu2004-docker-2c-2g-6869 sshd[769]: Server listening on 0.0.0.0 port 22. Jan 1 19:00:25 prd-ubuntu2004-docker-2c-2g-6869 sshd[769]: Server listening on :: port 22. Jan 1 19:00:27 prd-ubuntu2004-docker-2c-2g-6869 sshd[1197]: error: kex_exchange_identification: Connection closed by remote host Jan 1 19:00:34 prd-ubuntu2004-docker-2c-2g-6869 sshd[3417]: Invalid user jenkins from 10.30.168.15 port 54422 Jan 1 19:00:34 prd-ubuntu2004-docker-2c-2g-6869 sshd[3417]: Received disconnect from 10.30.168.15 port 54422:11: Closed due to user request. [preauth] Jan 1 19:00:34 prd-ubuntu2004-docker-2c-2g-6869 sshd[3417]: Disconnected from invalid user jenkins 10.30.168.15 port 54422 [preauth] Jan 1 19:00:37 prd-ubuntu2004-docker-2c-2g-6869 sshd[4623]: Invalid user jenkins from 10.30.168.15 port 54424 Jan 1 19:00:37 prd-ubuntu2004-docker-2c-2g-6869 sshd[4623]: Received disconnect from 10.30.168.15 port 54424:11: Closed due to user request. [preauth] Jan 1 19:00:37 prd-ubuntu2004-docker-2c-2g-6869 sshd[4623]: Disconnected from invalid user jenkins 10.30.168.15 port 54424 [preauth] Jan 1 19:00:40 prd-ubuntu2004-docker-2c-2g-6869 sshd[5725]: Invalid user jenkins from 10.30.168.15 port 54426 Jan 1 19:00:40 prd-ubuntu2004-docker-2c-2g-6869 sshd[5725]: Received disconnect from 10.30.168.15 port 54426:11: Closed due to user request. [preauth] Jan 1 19:00:40 prd-ubuntu2004-docker-2c-2g-6869 sshd[5725]: Disconnected from invalid user jenkins 10.30.168.15 port 54426 [preauth] Jan 1 19:00:42 prd-ubuntu2004-docker-2c-2g-6869 sshd[6994]: Invalid user jenkins from 10.30.168.15 port 54428 Jan 1 19:00:42 prd-ubuntu2004-docker-2c-2g-6869 sshd[6994]: Received disconnect from 10.30.168.15 port 54428:11: Closed due to user request. [preauth] Jan 1 19:00:42 prd-ubuntu2004-docker-2c-2g-6869 sshd[6994]: Disconnected from invalid user jenkins 10.30.168.15 port 54428 [preauth] Jan 1 19:00:45 prd-ubuntu2004-docker-2c-2g-6869 sshd[8283]: Invalid user jenkins from 10.30.168.15 port 54432 Jan 1 19:00:45 prd-ubuntu2004-docker-2c-2g-6869 sshd[8283]: Received disconnect from 10.30.168.15 port 54432:11: Closed due to user request. [preauth] Jan 1 19:00:45 prd-ubuntu2004-docker-2c-2g-6869 sshd[8283]: Disconnected from invalid user jenkins 10.30.168.15 port 54432 [preauth] Jan 1 19:00:48 prd-ubuntu2004-docker-2c-2g-6869 sshd[9500]: Invalid user jenkins from 10.30.168.15 port 54434 Jan 1 19:00:48 prd-ubuntu2004-docker-2c-2g-6869 sshd[9500]: Received disconnect from 10.30.168.15 port 54434:11: Closed due to user request. [preauth] Jan 1 19:00:48 prd-ubuntu2004-docker-2c-2g-6869 sshd[9500]: Disconnected from invalid user jenkins 10.30.168.15 port 54434 [preauth] Jan 1 19:00:51 prd-ubuntu2004-docker-2c-2g-6869 sshd[10689]: Invalid user jenkins from 10.30.168.15 port 54436 Jan 1 19:00:51 prd-ubuntu2004-docker-2c-2g-6869 sshd[10689]: Received disconnect from 10.30.168.15 port 54436:11: Closed due to user request. [preauth] Jan 1 19:00:51 prd-ubuntu2004-docker-2c-2g-6869 sshd[10689]: Disconnected from invalid user jenkins 10.30.168.15 port 54436 [preauth] Jan 1 19:00:54 prd-ubuntu2004-docker-2c-2g-6869 sshd[11714]: Invalid user jenkins from 10.30.168.15 port 54438 Jan 1 19:00:54 prd-ubuntu2004-docker-2c-2g-6869 sshd[11714]: Received disconnect from 10.30.168.15 port 54438:11: Closed due to user request. [preauth] Jan 1 19:00:54 prd-ubuntu2004-docker-2c-2g-6869 sshd[11714]: Disconnected from invalid user jenkins 10.30.168.15 port 54438 [preauth] Jan 1 19:00:55 prd-ubuntu2004-docker-2c-2g-6869 useradd[12031]: new group: name=jenkins, GID=1001 Jan 1 19:00:55 prd-ubuntu2004-docker-2c-2g-6869 useradd[12031]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Jan 1 19:00:55 prd-ubuntu2004-docker-2c-2g-6869 usermod[12063]: add 'jenkins' to group 'docker' Jan 1 19:00:55 prd-ubuntu2004-docker-2c-2g-6869 usermod[12063]: add 'jenkins' to shadow group 'docker' Jan 1 19:00:57 prd-ubuntu2004-docker-2c-2g-6869 sshd[12638]: Accepted publickey for jenkins from 10.30.168.15 port 54446 ssh2: RSA SHA256:BBsm4mRgG5V0fGum4Y1Rmy/vs16stdRVhwvexlLUhUs Jan 1 19:00:57 prd-ubuntu2004-docker-2c-2g-6869 sshd[12638]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Jan 1 19:00:57 prd-ubuntu2004-docker-2c-2g-6869 systemd-logind[723]: New session 1 of user jenkins. Jan 1 19:00:57 prd-ubuntu2004-docker-2c-2g-6869 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Jan 1 19:01:01 prd-ubuntu2004-docker-2c-2g-6869 CRON[14058]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 1 19:01:01 prd-ubuntu2004-docker-2c-2g-6869 CRON[14058]: pam_unix(cron:session): session closed for user root Jan 1 19:02:01 prd-ubuntu2004-docker-2c-2g-6869 CRON[28492]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 1 19:02:01 prd-ubuntu2004-docker-2c-2g-6869 CRON[28492]: pam_unix(cron:session): session closed for user root Jan 1 19:03:01 prd-ubuntu2004-docker-2c-2g-6869 CRON[28712]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 1 19:03:01 prd-ubuntu2004-docker-2c-2g-6869 CRON[28712]: pam_unix(cron:session): session closed for user root Jan 1 19:04:01 prd-ubuntu2004-docker-2c-2g-6869 CRON[29023]: pam_unix(cron:session): session opened for user root by (uid=0) Jan 1 19:04:01 prd-ubuntu2004-docker-2c-2g-6869 CRON[29023]: pam_unix(cron:session): session closed for user root Jan 1 19:04:58 prd-ubuntu2004-docker-2c-2g-6869 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/builder-packer-merge-centos-7-devstack-pre-pip-queens ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Jan 1 19:04:58 prd-ubuntu2004-docker-2c-2g-6869 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)