Oct 1 11:01:00 prd-ubuntu2004-docker-4c-4g-33265 passwd[709]: password for 'ubuntu' changed by 'root' Oct 1 11:01:00 prd-ubuntu2004-docker-4c-4g-33265 sshd[812]: Server listening on 0.0.0.0 port 22. Oct 1 11:01:00 prd-ubuntu2004-docker-4c-4g-33265 sshd[812]: Server listening on :: port 22. Oct 1 11:01:00 prd-ubuntu2004-docker-4c-4g-33265 systemd-logind[766]: New seat seat0. Oct 1 11:01:00 prd-ubuntu2004-docker-4c-4g-33265 systemd-logind[766]: Watching system buttons on /dev/input/event0 (Power Button) Oct 1 11:01:00 prd-ubuntu2004-docker-4c-4g-33265 systemd-logind[766]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard) Oct 1 11:01:05 prd-ubuntu2004-docker-4c-4g-33265 sshd[2641]: error: kex_exchange_identification: Connection closed by remote host Oct 1 11:01:21 prd-ubuntu2004-docker-4c-4g-33265 sshd[6705]: Invalid user jenkins from 10.30.168.15 port 37190 Oct 1 11:01:21 prd-ubuntu2004-docker-4c-4g-33265 sshd[6705]: Received disconnect from 10.30.168.15 port 37190:11: Closed due to user request. [preauth] Oct 1 11:01:21 prd-ubuntu2004-docker-4c-4g-33265 sshd[6705]: Disconnected from invalid user jenkins 10.30.168.15 port 37190 [preauth] Oct 1 11:01:24 prd-ubuntu2004-docker-4c-4g-33265 sshd[8624]: Invalid user jenkins from 10.30.168.15 port 37242 Oct 1 11:01:24 prd-ubuntu2004-docker-4c-4g-33265 sshd[8624]: Received disconnect from 10.30.168.15 port 37242:11: Closed due to user request. [preauth] Oct 1 11:01:24 prd-ubuntu2004-docker-4c-4g-33265 sshd[8624]: Disconnected from invalid user jenkins 10.30.168.15 port 37242 [preauth] Oct 1 11:01:27 prd-ubuntu2004-docker-4c-4g-33265 sshd[9513]: Invalid user jenkins from 10.30.168.15 port 37254 Oct 1 11:01:27 prd-ubuntu2004-docker-4c-4g-33265 sshd[9513]: Received disconnect from 10.30.168.15 port 37254:11: Closed due to user request. [preauth] Oct 1 11:01:27 prd-ubuntu2004-docker-4c-4g-33265 sshd[9513]: Disconnected from invalid user jenkins 10.30.168.15 port 37254 [preauth] Oct 1 11:01:30 prd-ubuntu2004-docker-4c-4g-33265 sshd[10065]: Invalid user jenkins from 10.30.168.15 port 37260 Oct 1 11:01:30 prd-ubuntu2004-docker-4c-4g-33265 sshd[10065]: Received disconnect from 10.30.168.15 port 37260:11: Closed due to user request. [preauth] Oct 1 11:01:30 prd-ubuntu2004-docker-4c-4g-33265 sshd[10065]: Disconnected from invalid user jenkins 10.30.168.15 port 37260 [preauth] Oct 1 11:01:30 prd-ubuntu2004-docker-4c-4g-33265 useradd[10368]: new group: name=jenkins, GID=1001 Oct 1 11:01:30 prd-ubuntu2004-docker-4c-4g-33265 useradd[10368]: new user: name=jenkins, UID=1001, GID=1001, home=/home/jenkins, shell=/bin/bash, from=none Oct 1 11:01:30 prd-ubuntu2004-docker-4c-4g-33265 usermod[10410]: add 'jenkins' to group 'docker' Oct 1 11:01:30 prd-ubuntu2004-docker-4c-4g-33265 usermod[10410]: add 'jenkins' to shadow group 'docker' Oct 1 11:01:33 prd-ubuntu2004-docker-4c-4g-33265 sshd[11225]: Accepted publickey for jenkins from 10.30.168.15 port 37272 ssh2: RSA SHA256:BBsm4mRgG5V0fGum4Y1Rmy/vs16stdRVhwvexlLUhUs Oct 1 11:01:33 prd-ubuntu2004-docker-4c-4g-33265 sshd[11225]: pam_unix(sshd:session): session opened for user jenkins by (uid=0) Oct 1 11:01:33 prd-ubuntu2004-docker-4c-4g-33265 systemd-logind[766]: New session 1 of user jenkins. Oct 1 11:01:33 prd-ubuntu2004-docker-4c-4g-33265 systemd: pam_unix(systemd-user:session): session opened for user jenkins by (uid=0) Oct 1 11:02:02 prd-ubuntu2004-docker-4c-4g-33265 CRON[22150]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 1 11:02:02 prd-ubuntu2004-docker-4c-4g-33265 CRON[22150]: pam_unix(cron:session): session closed for user root Oct 1 11:03:01 prd-ubuntu2004-docker-4c-4g-33265 CRON[28816]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 1 11:03:01 prd-ubuntu2004-docker-4c-4g-33265 CRON[28816]: pam_unix(cron:session): session closed for user root Oct 1 11:03:09 prd-ubuntu2004-docker-4c-4g-33265 sudo: jenkins : TTY=unknown ; PWD=/w/workspace/docs-rtd-merge-calcium ; USER=root ; COMMAND=/usr/bin/cp /var/log/auth.log /tmp Oct 1 11:03:09 prd-ubuntu2004-docker-4c-4g-33265 sudo: pam_unix(sudo:session): session opened for user root by (uid=0)