emd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 12.363227] systemd[1]: modprobe@dm_mod.service: Deactivated successfully. [ 12.368430] audit: type=1131 audit(1747442155.397:90): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@configfs comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 12.372270] systemd[1]: Finished modprobe@dm_mod.service. [ 12.381343] systemd[1]: modprobe@drm.service: Deactivated successfully. [ 12.382800] loop: module loaded [ 12.384737] systemd[1]: Finished modprobe@drm.service. [ 12.385745] audit: type=1130 audit(1747442155.415:91): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@dm_mod comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 12.394383] systemd[1]: modprobe@efi_pstore.service: Deactivated successfully. [ 12.397555] audit: type=1131 audit(1747442155.415:92): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@dm_mod comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 12.404660] systemd[1]: Finished modprobe@efi_pstore.service. [ 12.411891] audit: type=1130 audit(1747442155.428:93): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@drm comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 12.418376] systemd[1]: Finished systemd-modules-load.service. [ 12.422829] systemd[1]: Finished systemd-network-generator.service. [ 12.426852] systemd[1]: Started systemd-journald.service. [ 12.430085] audit: type=1131 audit(1747442155.428:94): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=modprobe@drm comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 12.438191] fuse: init (API version 7.34) [ 12.439205] audit: type=1305 audit(1747442155.442:95): op=set audit_enabled=1 old=1 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 res=1 [ 12.490731] systemd-journald[1448]: Received client request to flush runtime journal. [ 13.403850] input: Power Button as /devices/LNXSYSTM:00/LNXPWRBN:00/input/input2 [ 13.408738] ACPI: button: Power Button [PWRF] [ 13.409860] input: Sleep Button as /devices/LNXSYSTM:00/LNXSLPBN:00/input/input3 [ 13.414030] ACPI: button: Sleep Button [SLPF] [ 13.450375] input: ImPS/2 Generic Wheel Mouse as /devices/platform/i8042/serio1/input/input4 [ 13.455511] piix4_smbus 0000:00:01.3: SMBus base address uninitialized - upgrade BIOS or use force_addr=0xaddr [ 13.502626] mousedev: PS/2 mouse device common for all mice [ 13.514824] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready [ 13.871269] loop0: detected capacity change from 0 to 221472 [ 13.999525] squashfs: version 4.0 (2009/01/31) Phillip Lougher [ 14.019229] loop1: detected capacity change from 0 to 221472 [ 15.339277] EXT4-fs (nvme0n1p9): resizing filesystem from 553472 to 1489915 blocks [ 15.477275] EXT4-fs (nvme0n1p9): resized filesystem to 1489915 2025/05/17 00:35:59Z: Amazon SSM Agent v2.3.1319.0 is running 2025/05/17 00:35:59Z: OsProductName: Flatcar Container Linux by Kinvolk 2025/05/17 00:35:59Z: OsVersion: 3510.3.7 This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:36:03 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 26.462923] kauditd_printk_skb: 178 callbacks suppressed [ 26.462926] audit: type=1305 audit(1747442169.898:157): auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 op=remove_rule key=(null) list=5 res=1 [ 26.465953] audit: type=1300 audit(1747442169.898:157): arch=c000003e syscall=44 success=yes exit=1056 a0=3 a1=7fff9ea1ae50 a2=420 a3=0 items=0 ppid=1 pid=2114 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="auditctl" exe="/usr/sbin/auditctl" subj=system_u:system_r:kernel_t:s0 key=(null) [ 26.470634] audit: type=1327 audit(1747442169.898:157): proctitle=2F7362696E2F617564697463746C002D44 [ 26.477607] audit: type=1131 audit(1747442169.900:158): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=audit-rules comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 26.499523] audit: type=1130 audit(1747442169.934:159): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=audit-rules comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 26.503494] audit: type=1106 audit(1747442169.935:160): pid=2110 uid=500 auid=500 ses=6 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_unix,pam_permit,pam_systemd acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' [ 26.507872] audit: type=1104 audit(1747442169.935:161): pid=2110 uid=500 auid=500 ses=6 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' [ 26.526869] audit: type=1106 audit(1747442169.962:162): pid=2106 uid=0 auid=500 ses=6 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 26.534205] audit: type=1104 audit(1747442169.962:163): pid=2106 uid=0 auid=500 ses=6 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 26.538118] audit: type=1131 audit(1747442169.962:164): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@5-172.31.26.143:22-139.178.68.195:52024 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 27.157729] Initializing XFRM netlink socket This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:36:11 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 41.102268] kauditd_printk_skb: 88 callbacks suppressed [ 41.102272] audit: type=1130 audit(1747442184.535:203): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 41.109516] audit: type=1131 audit(1747442184.535:204): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 41.987092] audit: type=1130 audit(1747442185.422:205): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 42.064585] audit: type=1131 audit(1747442185.499:206): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed' [ 44.941149] audit: type=1130 audit(1747442188.376:207): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 44.944526] audit: type=1131 audit(1747442188.376:208): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 45.408396] audit: type=1130 audit(1747442188.843:209): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed' [ 45.648513] audit: type=1130 audit(1747442189.082:210): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 46.079372] audit: type=1131 audit(1747442189.514:211): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-hostnamed comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 46.199167] audit: type=1400 audit(1747442189.634:212): avc: denied { mac_admin } for pid=2423 comm="kubelet" capability=33 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=capability2 permissive=0 [ 46.204396] audit: type=1401 audit(1747442189.634:212): op=setxattr invalid_context="system_u:object_r:container_file_t:s0" [ 46.209097] audit: type=1300 audit(1747442189.634:212): arch=c000003e syscall=188 success=no exit=-22 a0=c0009c1fb0 a1=c0009cde48 a2=c0009c1f80 a3=25 items=0 ppid=1 pid=2423 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="kubelet" exe="/usr/bin/kubelet" subj=system_u:system_r:kernel_t:s0 key=(null) [ 46.217313] audit: type=1327 audit(1747442189.634:212): proctitle=2F7573722F62696E2F6B7562656C6574002D2D626F6F7473747261702D6B756265636F6E6669673D2F6574632F6B756265726E657465732F626F6F7473747261702D6B7562656C65742E636F6E66002D2D6B756265636F6E6669673D2F6574632F6B756265726E657465732F6B7562656C65742E636F6E66002D2D636F6E6669 [ 46.224721] audit: type=1400 audit(1747442189.634:213): avc: denied { mac_admin } for pid=2423 comm="kubelet" capability=33 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=capability2 permissive=0 [ 46.230325] audit: type=1401 audit(1747442189.634:213): op=setxattr invalid_context="system_u:object_r:container_file_t:s0" [ 46.233655] audit: type=1300 audit(1747442189.634:213): arch=c000003e syscall=188 success=no exit=-22 a0=c0009dd760 a1=c0009cde60 a2=c000b02060 a3=25 items=0 ppid=1 pid=2423 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="kubelet" exe="/usr/bin/kubelet" subj=system_u:system_r:kernel_t:s0 key=(null) [ 46.241163] audit: type=1327 audit(1747442189.634:213): proctitle=2F7573722F62696E2F6B7562656C6574002D2D626F6F7473747261702D6B756265636F6E6669673D2F6574632F6B756265726E657465732F626F6F7473747261702D6B7562656C65742E636F6E66002D2D6B756265636F6E6669673D2F6574632F6B756265726E657465732F6B7562656C65742E636F6E66002D2D636F6E6669 [ 46.248275] audit: type=1325 audit(1747442189.642:214): table=mangle:26 family=2 entries=2 op=nft_register_chain pid=2437 subj=system_u:system_r:kernel_t:s0 comm="iptables" [ 46.252541] audit: type=1300 audit(1747442189.642:214): arch=c000003e syscall=46 success=yes exit=136 a0=3 a1=7fff78e7ae20 a2=0 a3=7fff78e7ae0c items=0 ppid=2423 pid=2437 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 53.514389] kauditd_printk_skb: 38 callbacks suppressed [ 53.514391] audit: type=1131 audit(1747442196.949:227): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 55.311130] audit: type=1130 audit(1747442198.745:228): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 55.587949] audit: type=1400 audit(1747442199.023:229): avc: denied { mac_admin } for pid=2785 comm="kubelet" capability=33 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=capability2 permissive=0 [ 55.596160] audit: type=1401 audit(1747442199.023:229): op=setxattr invalid_context="system_u:object_r:container_file_t:s0" [ 55.600822] audit: type=1300 audit(1747442199.023:229): arch=c000003e syscall=188 success=no exit=-22 a0=c000bc49f0 a1=c0009c0ed0 a2=c000bc49c0 a3=25 items=0 ppid=1 pid=2785 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="kubelet" exe="/usr/bin/kubelet" subj=system_u:system_r:kernel_t:s0 key=(null) [ 55.611688] audit: type=1327 audit(1747442199.023:229): proctitle=2F7573722F62696E2F6B7562656C6574002D2D626F6F7473747261702D6B756265636F6E6669673D2F6574632F6B756265726E657465732F626F6F7473747261702D6B7562656C65742E636F6E66002D2D6B756265636F6E6669673D2F6574632F6B756265726E657465732F6B7562656C65742E636F6E66002D2D636F6E6669 [ 55.621630] audit: type=1400 audit(1747442199.023:230): avc: denied { mac_admin } for pid=2785 comm="kubelet" capability=33 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=capability2 permissive=0 [ 55.630167] audit: type=1401 audit(1747442199.023:230): op=setxattr invalid_context="system_u:object_r:container_file_t:s0" [ 55.635621] audit: type=1300 audit(1747442199.023:230): arch=c000003e syscall=188 success=no exit=-22 a0=c0009f8be0 a1=c0009c0f00 a2=c000bc4c90 a3=25 items=0 ppid=1 pid=2785 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="kubelet" exe="/usr/bin/kubelet" subj=system_u:system_r:kernel_t:s0 key=(null) [ 55.645799] audit: type=1327 audit(1747442199.023:230): proctitle=2F7573722F62696E2F6B7562656C6574002D2D626F6F7473747261702D6B756265636F6E6669673D2F6574632F6B756265726E657465732F626F6F7473747261702D6B7562656C65742E636F6E66002D2D6B756265636F6E6669673D2F6574632F6B756265726E657465732F6B7562656C65742E636F6E66002D2D636F6E6669 [ 61.249901] kauditd_printk_skb: 4 callbacks suppressed [ 61.249904] audit: type=1325 audit(1747442204.685:232): table=mangle:38 family=2 entries=1 op=nft_register_chain pid=3003 subj=system_u:system_r:kernel_t:s0 comm="iptables" [ 61.261331] audit: type=1325 audit(1747442204.688:233): table=mangle:39 family=10 entries=1 op=nft_register_chain pid=3004 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" [ 61.279342] audit: type=1300 audit(1747442204.688:233): arch=c000003e syscall=46 success=yes exit=104 a0=3 a1=7ffc305f7c30 a2=0 a3=7ffc305f7c1c items=0 ppid=2892 pid=3004 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 61.295523] audit: type=1327 audit(1747442204.688:233): proctitle=6970367461626C6573002D770035002D5700313030303030002D4E004B5542452D50524F58592D43414E415259002D74006D616E676C65 [ 61.309044] audit: type=1325 audit(1747442204.688:234): table=nat:40 family=10 entries=1 op=nft_register_chain pid=3005 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" [ 61.313443] audit: type=1300 audit(1747442204.688:234): arch=c000003e syscall=46 success=yes exit=100 a0=3 a1=7ffe94b7b420 a2=0 a3=7ffe94b7b40c items=0 ppid=2892 pid=3005 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 61.324487] audit: type=1327 audit(1747442204.688:234): proctitle=6970367461626C6573002D770035002D5700313030303030002D4E004B5542452D50524F58592D43414E415259002D74006E6174 [ 61.329530] audit: type=1300 audit(1747442204.685:232): arch=c000003e syscall=46 success=yes exit=104 a0=3 a1=7ffc7866adf0 a2=0 a3=7ffc7866addc items=0 ppid=2892 pid=3003 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 61.339486] audit: type=1327 audit(1747442204.685:232): proctitle=69707461626C6573002D770035002D5700313030303030002D4E004B5542452D50524F58592D43414E415259002D74006D616E676C65 [ 61.344466] audit: type=1325 audit(1747442204.692:235): table=filter:41 family=10 entries=1 op=nft_register_chain pid=3006 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" [ 69.886374] kauditd_printk_skb: 143 callbacks suppressed [ 69.886378] audit: type=1106 audit(1747442213.321:283): pid=2143 uid=500 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_unix,pam_permit,pam_systemd acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' [ 69.901222] audit: type=1104 audit(1747442213.321:284): pid=2143 uid=500 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' [ 69.924757] audit: type=1106 audit(1747442213.358:285): pid=2139 uid=0 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 69.947764] audit: type=1104 audit(1747442213.358:286): pid=2139 uid=0 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 69.955365] audit: type=1131 audit(1747442213.374:287): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@6-172.31.26.143:22-139.178.68.195:52040 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 70.846613] audit: type=1325 audit(1747442214.282:288): table=filter:89 family=2 entries=15 op=nft_register_rule pid=3343 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 70.851878] audit: type=1300 audit(1747442214.282:288): arch=c000003e syscall=46 success=yes exit=5992 a0=3 a1=7ffecbc86690 a2=0 a3=7ffecbc8667c items=0 ppid=2892 pid=3343 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 70.874495] audit: type=1327 audit(1747442214.282:288): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 70.883208] audit: type=1325 audit(1747442214.301:289): table=nat:90 family=2 entries=12 op=nft_register_rule pid=3343 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 70.888052] audit: type=1300 audit(1747442214.301:289): arch=c000003e syscall=46 success=yes exit=2700 a0=3 a1=7ffecbc86690 a2=0 a3=0 items=0 ppid=2892 pid=3343 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 75.463426] kauditd_printk_skb: 19 callbacks suppressed [ 75.463428] audit: type=1325 audit(1747442218.899:296): table=filter:97 family=2 entries=20 op=nft_register_rule pid=3463 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 75.470194] audit: type=1300 audit(1747442218.899:296): arch=c000003e syscall=46 success=yes exit=8224 a0=3 a1=7fff5cf9fb40 a2=0 a3=7fff5cf9fb2c items=0 ppid=2892 pid=3463 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 75.478976] audit: type=1327 audit(1747442218.899:296): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 75.488614] audit: type=1325 audit(1747442218.922:297): table=nat:98 family=2 entries=12 op=nft_register_rule pid=3463 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 75.494168] audit: type=1300 audit(1747442218.922:297): arch=c000003e syscall=46 success=yes exit=2700 a0=3 a1=7fff5cf9fb40 a2=0 a3=0 items=0 ppid=2892 pid=3463 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 75.510968] audit: type=1327 audit(1747442218.922:297): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 79.201403] audit: type=1325 audit(1747442222.635:298): table=filter:99 family=2 entries=21 op=nft_register_rule pid=3629 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 79.219499] audit: type=1300 audit(1747442222.635:298): arch=c000003e syscall=46 success=yes exit=7480 a0=3 a1=7fff4e23f5c0 a2=0 a3=7fff4e23f5ac items=0 ppid=2892 pid=3629 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 79.284861] audit: type=1327 audit(1747442222.635:298): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 79.333536] audit: type=1325 audit(1747442222.720:299): table=nat:100 family=2 entries=19 op=nft_register_chain pid=3629 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 95.997076] wireguard: WireGuard 1.0.0 loaded. See www.wireguard.com for information. [ 95.998979] wireguard: Copyright (C) 2015-2019 Jason A. Donenfeld . All Rights Reserved. [ 97.544854] kauditd_printk_skb: 2 callbacks suppressed [ 97.544857] audit: type=1400 audit(1747442240.980:300): avc: denied { write } for pid=4308 comm="tee" name="fd" dev="proc" ino=25721 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=dir permissive=0 [ 97.569949] audit: type=1400 audit(1747442241.005:301): avc: denied { write } for pid=4316 comm="tee" name="fd" dev="proc" ino=25732 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=dir permissive=0 [ 97.581066] audit: type=1300 audit(1747442241.005:301): arch=c000003e syscall=257 success=yes exit=3 a0=ffffff9c a1=7ffc7d71a7df a2=241 a3=1b6 items=1 ppid=4273 pid=4316 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="tee" exe="/usr/bin/coreutils" subj=system_u:system_r:kernel_t:s0 key=(null) [ 97.599142] audit: type=1307 audit(1747442241.005:301): cwd="/etc/service/enabled/confd/log" [ 97.601940] audit: type=1302 audit(1747442241.005:301): item=0 name="/dev/fd/63" inode=24497 dev=00:0c mode=010600 ouid=0 ogid=0 rdev=00:00 obj=system_u:system_r:kernel_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 [ 97.609444] audit: type=1327 audit(1747442241.005:301): proctitle=2F7573722F62696E2F636F72657574696C73002D2D636F72657574696C732D70726F672D73686562616E673D746565002F7573722F62696E2F746565002F6465762F66642F3633 [ 97.616942] audit: type=1300 audit(1747442240.980:300): arch=c000003e syscall=257 success=yes exit=3 a0=ffffff9c a1=7fffe6b707d0 a2=241 a3=1b6 items=1 ppid=4271 pid=4308 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="tee" exe="/usr/bin/coreutils" subj=system_u:system_r:kernel_t:s0 key=(null) [ 97.628055] audit: type=1307 audit(1747442240.980:300): cwd="/etc/service/enabled/node-status-reporter/log" [ 97.632344] audit: type=1302 audit(1747442240.980:300): item=0 name="/dev/fd/63" inode=24482 dev=00:0c mode=010600 ouid=0 ogid=0 rdev=00:00 obj=system_u:system_r:kernel_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 [ 97.639510] audit: type=1327 audit(1747442240.980:300): proctitle=2F7573722F62696E2F636F72657574696C73002D2D636F72657574696C732D70726F672D73686562616E673D746565002F7573722F62696E2F746565002F6465762F66642F3633 This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:22 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 100.002027] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready [ 100.003195] IPv6: ADDRCONF(NETDEV_CHANGE): caliae2076718f7: link becomes ready [ 100.165467] IPv6: ADDRCONF(NETDEV_CHANGE): calic1a1509cc20: link becomes ready [ 100.894504] IPv6: ADDRCONF(NETDEV_CHANGE): calibe451daeac4: link becomes ready This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:24 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 101.988351] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready [ 101.989490] IPv6: ADDRCONF(NETDEV_CHANGE): calic1551bc05b6: link becomes ready This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:25 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:26 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 103.231727] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready [ 103.232841] IPv6: ADDRCONF(NETDEV_CHANGE): califf9601efd43: link becomes ready [ 103.309378] kauditd_printk_skb: 541 callbacks suppressed [ 103.309381] audit: type=1325 audit(1747442246.744:412): table=filter:115 family=2 entries=44 op=nft_register_chain pid=4968 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" [ 103.312810] audit: type=1300 audit(1747442246.744:412): arch=c000003e syscall=46 success=yes exit=21936 a0=3 a1=7ffce3a8c9d0 a2=0 a3=7ffce3a8c9bc items=0 ppid=4305 pid=4968 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 103.321359] audit: type=1327 audit(1747442246.744:412): proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 [ 103.359784] IPv6: ADDRCONF(NETDEV_CHANGE): caliad068b2eb93: link becomes ready [ 103.438675] audit: type=1325 audit(1747442246.874:413): table=filter:116 family=2 entries=50 op=nft_register_chain pid=5004 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" [ 103.441252] audit: type=1300 audit(1747442246.874:413): arch=c000003e syscall=46 success=yes exit=24368 a0=3 a1=7ffe94e91030 a2=0 a3=7ffe94e9101c items=0 ppid=4305 pid=5004 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 103.447576] audit: type=1327 audit(1747442246.874:413): proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:27 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 104.090692] audit: type=1325 audit(1747442247.526:414): table=filter:117 family=2 entries=20 op=nft_register_rule pid=5135 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 104.093754] audit: type=1300 audit(1747442247.526:414): arch=c000003e syscall=46 success=yes exit=7480 a0=3 a1=7ffd580ddd40 a2=0 a3=7ffd580ddd2c items=0 ppid=2892 pid=5135 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 104.099186] audit: type=1327 audit(1747442247.526:414): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 104.105037] audit: type=1325 audit(1747442247.535:415): table=nat:118 family=2 entries=14 op=nft_register_rule pid=5135 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 104.304893] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready [ 104.307156] IPv6: ADDRCONF(NETDEV_CHANGE): cali42336864ccc: link becomes ready [ 104.993424] IPv6: ADDRCONF(NETDEV_CHANGE): calidcd0a3704fa: link becomes ready This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:28 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:29 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:30 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:31 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 110.862626] kauditd_printk_skb: 20 callbacks suppressed [ 110.862631] audit: type=1130 audit(1747442254.298:422): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@7-172.31.26.143:22-139.178.68.195:60194 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 111.157705] audit: type=1101 audit(1747442254.593:423): pid=5450 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 111.168509] audit: type=1103 audit(1747442254.604:424): pid=5450 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 111.172836] audit: type=1006 audit(1747442254.608:425): pid=5450 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=8 res=1 [ 111.175728] audit: type=1300 audit(1747442254.608:425): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffc48b5fda0 a2=3 a3=0 items=0 ppid=1 pid=5450 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=8 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 111.181372] audit: type=1327 audit(1747442254.608:425): proctitle=737368643A20636F7265205B707269765D [ 111.230676] audit: type=1105 audit(1747442254.666:426): pid=5450 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 111.235385] audit: type=1103 audit(1747442254.666:427): pid=5453 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 113.128194] audit: type=1106 audit(1747442256.564:428): pid=5450 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 113.146050] audit: type=1104 audit(1747442256.564:429): pid=5450 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 118.160184] kauditd_printk_skb: 19 callbacks suppressed [ 118.160189] audit: type=1130 audit(1747442261.594:437): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@8-172.31.26.143:22-139.178.68.195:60210 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 118.508226] audit: type=1101 audit(1747442261.943:438): pid=5854 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 118.517246] audit: type=1103 audit(1747442261.952:439): pid=5854 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 118.529614] audit: type=1006 audit(1747442261.952:440): pid=5854 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=9 res=1 [ 118.535762] audit: type=1300 audit(1747442261.952:440): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffdf9875840 a2=3 a3=0 items=0 ppid=1 pid=5854 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 118.547935] audit: type=1327 audit(1747442261.952:440): proctitle=737368643A20636F7265205B707269765D [ 118.584816] audit: type=1105 audit(1747442262.019:441): pid=5854 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 118.616035] audit: type=1103 audit(1747442262.045:442): pid=5906 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 119.889550] audit: type=1106 audit(1747442263.323:443): pid=5854 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 119.899265] audit: type=1104 audit(1747442263.324:444): pid=5854 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 124.916892] kauditd_printk_skb: 1 callbacks suppressed [ 124.916895] audit: type=1130 audit(1747442268.352:446): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@9-172.31.26.143:22-139.178.68.195:48844 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 125.189590] audit: type=1101 audit(1747442268.624:447): pid=5966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 125.197531] audit: type=1103 audit(1747442268.632:448): pid=5966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 125.205180] audit: type=1006 audit(1747442268.632:449): pid=5966 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=10 res=1 [ 125.209575] audit: type=1300 audit(1747442268.632:449): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffe279ba150 a2=3 a3=0 items=0 ppid=1 pid=5966 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=10 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 125.217946] audit: type=1327 audit(1747442268.632:449): proctitle=737368643A20636F7265205B707269765D [ 125.236262] audit: type=1105 audit(1747442268.671:450): pid=5966 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 125.247070] audit: type=1103 audit(1747442268.682:451): pid=5969 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 125.779323] audit: type=1106 audit(1747442269.215:452): pid=5966 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 125.787597] audit: type=1104 audit(1747442269.215:453): pid=5966 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 131.785888] kauditd_printk_skb: 23 callbacks suppressed [ 131.785890] audit: type=1130 audit(1747442275.222:473): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@12-172.31.26.143:22-139.178.68.195:43798 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 131.998856] audit: type=1101 audit(1747442275.435:474): pid=6009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 132.008229] audit: type=1103 audit(1747442275.444:475): pid=6009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 132.017058] audit: type=1006 audit(1747442275.444:476): pid=6009 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=13 res=1 [ 132.022774] audit: type=1300 audit(1747442275.444:476): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7fff4131ccd0 a2=3 a3=0 items=0 ppid=1 pid=6009 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=13 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 132.038291] audit: type=1327 audit(1747442275.444:476): proctitle=737368643A20636F7265205B707269765D [ 132.049175] audit: type=1105 audit(1747442275.470:477): pid=6009 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 132.057938] audit: type=1103 audit(1747442275.472:478): pid=6012 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 132.261176] audit: type=1106 audit(1747442275.697:479): pid=6009 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 132.269810] audit: type=1104 audit(1747442275.702:480): pid=6009 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 137.290735] kauditd_printk_skb: 1 callbacks suppressed [ 137.290738] audit: type=1130 audit(1747442280.727:482): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@13-172.31.26.143:22-139.178.68.195:43808 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 137.593141] audit: type=1101 audit(1747442281.029:483): pid=6022 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 137.613341] audit: type=1103 audit(1747442281.049:484): pid=6022 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 137.626061] audit: type=1006 audit(1747442281.049:485): pid=6022 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=14 res=1 [ 137.631114] audit: type=1300 audit(1747442281.049:485): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffde30acd20 a2=3 a3=0 items=0 ppid=1 pid=6022 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=14 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 137.640887] audit: type=1327 audit(1747442281.049:485): proctitle=737368643A20636F7265205B707269765D [ 137.651108] audit: type=1105 audit(1747442281.086:486): pid=6022 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 137.664469] audit: type=1103 audit(1747442281.087:487): pid=6025 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 140.029142] audit: type=1106 audit(1747442283.462:488): pid=6022 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 140.059337] audit: type=1104 audit(1747442283.462:489): pid=6022 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 145.048652] kauditd_printk_skb: 7 callbacks suppressed [ 145.048656] audit: type=1130 audit(1747442288.485:493): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@14-172.31.26.143:22-139.178.68.195:56696 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 145.292322] audit: type=1101 audit(1747442288.728:494): pid=6043 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 145.303121] audit: type=1103 audit(1747442288.738:495): pid=6043 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 145.314363] audit: type=1006 audit(1747442288.738:496): pid=6043 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=15 res=1 [ 145.319931] audit: type=1300 audit(1747442288.738:496): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7fff46df6e60 a2=3 a3=0 items=0 ppid=1 pid=6043 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 145.329430] audit: type=1327 audit(1747442288.738:496): proctitle=737368643A20636F7265205B707269765D [ 145.354644] audit: type=1105 audit(1747442288.791:497): pid=6043 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 145.375787] audit: type=1103 audit(1747442288.802:498): pid=6046 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 146.172841] audit: type=1106 audit(1747442289.609:499): pid=6043 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 146.189521] audit: type=1104 audit(1747442289.609:500): pid=6043 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 151.197459] kauditd_printk_skb: 1 callbacks suppressed [ 151.197462] audit: type=1130 audit(1747442294.633:502): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@15-172.31.26.143:22-139.178.68.195:52880 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 151.470140] audit: type=1101 audit(1747442294.906:503): pid=6098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 151.483203] audit: type=1103 audit(1747442294.915:504): pid=6098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 151.492712] audit: type=1006 audit(1747442294.915:505): pid=6098 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=16 res=1 [ 151.501172] audit: type=1300 audit(1747442294.915:505): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffdd5cf58e0 a2=3 a3=0 items=0 ppid=1 pid=6098 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=16 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 151.514620] audit: type=1327 audit(1747442294.915:505): proctitle=737368643A20636F7265205B707269765D [ 151.532769] audit: type=1105 audit(1747442294.967:506): pid=6098 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 151.542050] audit: type=1103 audit(1747442294.970:507): pid=6103 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 152.380457] audit: type=1106 audit(1747442295.817:508): pid=6098 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 152.397694] audit: type=1104 audit(1747442295.824:509): pid=6098 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 160.923232] kauditd_printk_skb: 20 callbacks suppressed [ 160.923234] audit: type=1325 audit(1747442304.359:526): table=filter:133 family=2 entries=24 op=nft_register_rule pid=6139 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 160.938260] audit: type=1300 audit(1747442304.359:526): arch=c000003e syscall=46 success=yes exit=13432 a0=3 a1=7ffecd96bae0 a2=0 a3=7ffecd96bacc items=0 ppid=2892 pid=6139 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 160.945725] audit: type=1327 audit(1747442304.359:526): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 160.949739] audit: type=1325 audit(1747442304.370:527): table=nat:134 family=2 entries=22 op=nft_register_rule pid=6139 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 160.954199] audit: type=1300 audit(1747442304.370:527): arch=c000003e syscall=46 success=yes exit=6540 a0=3 a1=7ffecd96bae0 a2=0 a3=0 items=0 ppid=2892 pid=6139 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 160.963258] audit: type=1327 audit(1747442304.370:527): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 162.716030] audit: type=1325 audit(1747442306.152:528): table=filter:135 family=2 entries=36 op=nft_register_rule pid=6141 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 162.722442] audit: type=1300 audit(1747442306.152:528): arch=c000003e syscall=46 success=yes exit=13432 a0=3 a1=7fff30d30670 a2=0 a3=7fff30d3065c items=0 ppid=2892 pid=6141 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 162.732647] audit: type=1327 audit(1747442306.152:528): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 162.736837] audit: type=1106 audit(1747442306.168:529): pid=6123 uid=0 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 168.239738] kauditd_printk_skb: 13 callbacks suppressed [ 168.239741] audit: type=1130 audit(1747442311.675:539): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@19-172.31.26.143:22-139.178.68.195:44704 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 168.262648] audit: type=1106 audit(1747442311.690:540): pid=6142 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 168.291397] audit: type=1104 audit(1747442311.693:541): pid=6142 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 168.298726] audit: type=1131 audit(1747442311.697:542): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@18-172.31.26.143:22-139.178.68.195:44700 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 168.540327] audit: type=1101 audit(1747442311.974:543): pid=6156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 168.550724] audit: type=1103 audit(1747442311.986:544): pid=6156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 168.559808] audit: type=1006 audit(1747442311.986:545): pid=6156 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=20 res=1 [ 168.566839] audit: type=1300 audit(1747442311.986:545): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7fff30d018d0 a2=3 a3=0 items=0 ppid=1 pid=6156 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=20 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 168.581756] audit: type=1327 audit(1747442311.986:545): proctitle=737368643A20636F7265205B707269765D [ 168.606056] audit: type=1105 audit(1747442312.042:546): pid=6156 uid=0 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 174.736064] kauditd_printk_skb: 10 callbacks suppressed [ 174.736068] audit: type=1130 audit(1747442318.172:553): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@20-172.31.26.143:22-139.178.68.195:32876 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 175.031666] audit: type=1101 audit(1747442318.468:554): pid=6193 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 175.040571] audit: type=1103 audit(1747442318.471:555): pid=6193 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 175.049641] audit: type=1006 audit(1747442318.471:556): pid=6193 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=21 res=1 [ 175.054845] audit: type=1300 audit(1747442318.471:556): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffc332b7d00 a2=3 a3=0 items=0 ppid=1 pid=6193 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=21 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 175.067383] audit: type=1327 audit(1747442318.471:556): proctitle=737368643A20636F7265205B707269765D [ 175.099818] audit: type=1105 audit(1747442318.536:557): pid=6193 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 175.116346] audit: type=1103 audit(1747442318.536:558): pid=6196 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 177.239743] audit: type=1106 audit(1747442320.676:559): pid=6193 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 177.250436] audit: type=1104 audit(1747442320.677:560): pid=6193 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 182.275331] kauditd_printk_skb: 1 callbacks suppressed [ 182.275334] audit: type=1130 audit(1747442325.711:562): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@21-172.31.26.143:22-139.178.68.195:51856 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 182.579487] audit: type=1101 audit(1747442326.016:563): pid=6254 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 182.589279] audit: type=1103 audit(1747442326.025:564): pid=6254 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 182.598951] audit: type=1006 audit(1747442326.025:565): pid=6254 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=22 res=1 [ 182.607302] audit: type=1300 audit(1747442326.025:565): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7fff4a225fc0 a2=3 a3=0 items=0 ppid=1 pid=6254 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=22 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 182.625279] audit: type=1327 audit(1747442326.025:565): proctitle=737368643A20636F7265205B707269765D [ 182.669553] audit: type=1105 audit(1747442326.105:566): pid=6254 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 182.684047] audit: type=1103 audit(1747442326.118:567): pid=6257 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 183.925885] audit: type=1106 audit(1747442327.362:568): pid=6254 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 183.942264] audit: type=1104 audit(1747442327.363:569): pid=6254 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 188.951875] kauditd_printk_skb: 1 callbacks suppressed [ 188.951878] audit: type=1130 audit(1747442332.388:571): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@22-172.31.26.143:22-139.178.68.195:51866 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 189.200729] audit: type=1101 audit(1747442332.637:572): pid=6276 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 189.209576] audit: type=1103 audit(1747442332.646:573): pid=6276 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 189.223223] audit: type=1006 audit(1747442332.646:574): pid=6276 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=23 res=1 [ 189.228528] audit: type=1300 audit(1747442332.646:574): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffdcc660df0 a2=3 a3=0 items=0 ppid=1 pid=6276 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=23 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 189.238077] audit: type=1327 audit(1747442332.646:574): proctitle=737368643A20636F7265205B707269765D [ 189.258565] audit: type=1105 audit(1747442332.692:575): pid=6276 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 189.269527] audit: type=1103 audit(1747442332.694:576): pid=6279 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 190.146000] audit: type=1106 audit(1747442333.582:577): pid=6276 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 26.534205] audit: type=1104 audit(1747442169.962:163): pid=2106 uid=0 auid=500 ses=6 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 26.538118] audit: type=1131 audit(1747442169.962:164): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@5-172.31.26.143:22-139.178.68.195:52024 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 27.157729] Initializing XFRM netlink socket This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:36:11 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 41.102268] kauditd_printk_skb: 88 callbacks suppressed [ 41.102272] audit: type=1130 audit(1747442184.535:203): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 41.109516] audit: type=1131 audit(1747442184.535:204): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 41.987092] audit: type=1130 audit(1747442185.422:205): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 42.064585] audit: type=1131 audit(1747442185.499:206): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed' [ 44.941149] audit: type=1130 audit(1747442188.376:207): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 44.944526] audit: type=1131 audit(1747442188.376:208): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 45.408396] audit: type=1130 audit(1747442188.843:209): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=failed' [ 45.648513] audit: type=1130 audit(1747442189.082:210): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 46.079372] audit: type=1131 audit(1747442189.514:211): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=systemd-hostnamed comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 46.199167] audit: type=1400 audit(1747442189.634:212): avc: denied { mac_admin } for pid=2423 comm="kubelet" capability=33 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=capability2 permissive=0 [ 46.204396] audit: type=1401 audit(1747442189.634:212): op=setxattr invalid_context="system_u:object_r:container_file_t:s0" [ 46.209097] audit: type=1300 audit(1747442189.634:212): arch=c000003e syscall=188 success=no exit=-22 a0=c0009c1fb0 a1=c0009cde48 a2=c0009c1f80 a3=25 items=0 ppid=1 pid=2423 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="kubelet" exe="/usr/bin/kubelet" subj=system_u:system_r:kernel_t:s0 key=(null) [ 46.217313] audit: type=1327 audit(1747442189.634:212): proctitle=2F7573722F62696E2F6B7562656C6574002D2D626F6F7473747261702D6B756265636F6E6669673D2F6574632F6B756265726E657465732F626F6F7473747261702D6B7562656C65742E636F6E66002D2D6B756265636F6E6669673D2F6574632F6B756265726E657465732F6B7562656C65742E636F6E66002D2D636F6E6669 [ 46.224721] audit: type=1400 audit(1747442189.634:213): avc: denied { mac_admin } for pid=2423 comm="kubelet" capability=33 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=capability2 permissive=0 [ 46.230325] audit: type=1401 audit(1747442189.634:213): op=setxattr invalid_context="system_u:object_r:container_file_t:s0" [ 46.233655] audit: type=1300 audit(1747442189.634:213): arch=c000003e syscall=188 success=no exit=-22 a0=c0009dd760 a1=c0009cde60 a2=c000b02060 a3=25 items=0 ppid=1 pid=2423 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="kubelet" exe="/usr/bin/kubelet" subj=system_u:system_r:kernel_t:s0 key=(null) [ 46.241163] audit: type=1327 audit(1747442189.634:213): proctitle=2F7573722F62696E2F6B7562656C6574002D2D626F6F7473747261702D6B756265636F6E6669673D2F6574632F6B756265726E657465732F626F6F7473747261702D6B7562656C65742E636F6E66002D2D6B756265636F6E6669673D2F6574632F6B756265726E657465732F6B7562656C65742E636F6E66002D2D636F6E6669 [ 46.248275] audit: type=1325 audit(1747442189.642:214): table=mangle:26 family=2 entries=2 op=nft_register_chain pid=2437 subj=system_u:system_r:kernel_t:s0 comm="iptables" [ 46.252541] audit: type=1300 audit(1747442189.642:214): arch=c000003e syscall=46 success=yes exit=136 a0=3 a1=7fff78e7ae20 a2=0 a3=7fff78e7ae0c items=0 ppid=2423 pid=2437 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 53.514389] kauditd_printk_skb: 38 callbacks suppressed [ 53.514391] audit: type=1131 audit(1747442196.949:227): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 55.311130] audit: type=1130 audit(1747442198.745:228): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=kubelet comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 55.587949] audit: type=1400 audit(1747442199.023:229): avc: denied { mac_admin } for pid=2785 comm="kubelet" capability=33 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=capability2 permissive=0 [ 55.596160] audit: type=1401 audit(1747442199.023:229): op=setxattr invalid_context="system_u:object_r:container_file_t:s0" [ 55.600822] audit: type=1300 audit(1747442199.023:229): arch=c000003e syscall=188 success=no exit=-22 a0=c000bc49f0 a1=c0009c0ed0 a2=c000bc49c0 a3=25 items=0 ppid=1 pid=2785 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="kubelet" exe="/usr/bin/kubelet" subj=system_u:system_r:kernel_t:s0 key=(null) [ 55.611688] audit: type=1327 audit(1747442199.023:229): proctitle=2F7573722F62696E2F6B7562656C6574002D2D626F6F7473747261702D6B756265636F6E6669673D2F6574632F6B756265726E657465732F626F6F7473747261702D6B7562656C65742E636F6E66002D2D6B756265636F6E6669673D2F6574632F6B756265726E657465732F6B7562656C65742E636F6E66002D2D636F6E6669 [ 55.621630] audit: type=1400 audit(1747442199.023:230): avc: denied { mac_admin } for pid=2785 comm="kubelet" capability=33 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=capability2 permissive=0 [ 55.630167] audit: type=1401 audit(1747442199.023:230): op=setxattr invalid_context="system_u:object_r:container_file_t:s0" [ 55.635621] audit: type=1300 audit(1747442199.023:230): arch=c000003e syscall=188 success=no exit=-22 a0=c0009f8be0 a1=c0009c0f00 a2=c000bc4c90 a3=25 items=0 ppid=1 pid=2785 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="kubelet" exe="/usr/bin/kubelet" subj=system_u:system_r:kernel_t:s0 key=(null) [ 55.645799] audit: type=1327 audit(1747442199.023:230): proctitle=2F7573722F62696E2F6B7562656C6574002D2D626F6F7473747261702D6B756265636F6E6669673D2F6574632F6B756265726E657465732F626F6F7473747261702D6B7562656C65742E636F6E66002D2D6B756265636F6E6669673D2F6574632F6B756265726E657465732F6B7562656C65742E636F6E66002D2D636F6E6669 [ 61.249901] kauditd_printk_skb: 4 callbacks suppressed [ 61.249904] audit: type=1325 audit(1747442204.685:232): table=mangle:38 family=2 entries=1 op=nft_register_chain pid=3003 subj=system_u:system_r:kernel_t:s0 comm="iptables" [ 61.261331] audit: type=1325 audit(1747442204.688:233): table=mangle:39 family=10 entries=1 op=nft_register_chain pid=3004 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" [ 61.279342] audit: type=1300 audit(1747442204.688:233): arch=c000003e syscall=46 success=yes exit=104 a0=3 a1=7ffc305f7c30 a2=0 a3=7ffc305f7c1c items=0 ppid=2892 pid=3004 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 61.295523] audit: type=1327 audit(1747442204.688:233): proctitle=6970367461626C6573002D770035002D5700313030303030002D4E004B5542452D50524F58592D43414E415259002D74006D616E676C65 [ 61.309044] audit: type=1325 audit(1747442204.688:234): table=nat:40 family=10 entries=1 op=nft_register_chain pid=3005 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" [ 61.313443] audit: type=1300 audit(1747442204.688:234): arch=c000003e syscall=46 success=yes exit=100 a0=3 a1=7ffe94b7b420 a2=0 a3=7ffe94b7b40c items=0 ppid=2892 pid=3005 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip6tables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 61.324487] audit: type=1327 audit(1747442204.688:234): proctitle=6970367461626C6573002D770035002D5700313030303030002D4E004B5542452D50524F58592D43414E415259002D74006E6174 [ 61.329530] audit: type=1300 audit(1747442204.685:232): arch=c000003e syscall=46 success=yes exit=104 a0=3 a1=7ffc7866adf0 a2=0 a3=7ffc7866addc items=0 ppid=2892 pid=3003 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 61.339486] audit: type=1327 audit(1747442204.685:232): proctitle=69707461626C6573002D770035002D5700313030303030002D4E004B5542452D50524F58592D43414E415259002D74006D616E676C65 [ 61.344466] audit: type=1325 audit(1747442204.692:235): table=filter:41 family=10 entries=1 op=nft_register_chain pid=3006 subj=system_u:system_r:kernel_t:s0 comm="ip6tables" [ 69.886374] kauditd_printk_skb: 143 callbacks suppressed [ 69.886378] audit: type=1106 audit(1747442213.321:283): pid=2143 uid=500 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_limits,pam_env,pam_unix,pam_permit,pam_systemd acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' [ 69.901222] audit: type=1104 audit(1747442213.321:284): pid=2143 uid=500 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' [ 69.924757] audit: type=1106 audit(1747442213.358:285): pid=2139 uid=0 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 69.947764] audit: type=1104 audit(1747442213.358:286): pid=2139 uid=0 auid=500 ses=7 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 69.955365] audit: type=1131 audit(1747442213.374:287): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@6-172.31.26.143:22-139.178.68.195:52040 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 70.846613] audit: type=1325 audit(1747442214.282:288): table=filter:89 family=2 entries=15 op=nft_register_rule pid=3343 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 70.851878] audit: type=1300 audit(1747442214.282:288): arch=c000003e syscall=46 success=yes exit=5992 a0=3 a1=7ffecbc86690 a2=0 a3=7ffecbc8667c items=0 ppid=2892 pid=3343 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 70.874495] audit: type=1327 audit(1747442214.282:288): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 70.883208] audit: type=1325 audit(1747442214.301:289): table=nat:90 family=2 entries=12 op=nft_register_rule pid=3343 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 70.888052] audit: type=1300 audit(1747442214.301:289): arch=c000003e syscall=46 success=yes exit=2700 a0=3 a1=7ffecbc86690 a2=0 a3=0 items=0 ppid=2892 pid=3343 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 75.463426] kauditd_printk_skb: 19 callbacks suppressed [ 75.463428] audit: type=1325 audit(1747442218.899:296): table=filter:97 family=2 entries=20 op=nft_register_rule pid=3463 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 75.470194] audit: type=1300 audit(1747442218.899:296): arch=c000003e syscall=46 success=yes exit=8224 a0=3 a1=7fff5cf9fb40 a2=0 a3=7fff5cf9fb2c items=0 ppid=2892 pid=3463 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 75.478976] audit: type=1327 audit(1747442218.899:296): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 75.488614] audit: type=1325 audit(1747442218.922:297): table=nat:98 family=2 entries=12 op=nft_register_rule pid=3463 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 75.494168] audit: type=1300 audit(1747442218.922:297): arch=c000003e syscall=46 success=yes exit=2700 a0=3 a1=7fff5cf9fb40 a2=0 a3=0 items=0 ppid=2892 pid=3463 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 75.510968] audit: type=1327 audit(1747442218.922:297): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 79.201403] audit: type=1325 audit(1747442222.635:298): table=filter:99 family=2 entries=21 op=nft_register_rule pid=3629 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 79.219499] audit: type=1300 audit(1747442222.635:298): arch=c000003e syscall=46 success=yes exit=7480 a0=3 a1=7fff4e23f5c0 a2=0 a3=7fff4e23f5ac items=0 ppid=2892 pid=3629 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 79.284861] audit: type=1327 audit(1747442222.635:298): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 79.333536] audit: type=1325 audit(1747442222.720:299): table=nat:100 family=2 entries=19 op=nft_register_chain pid=3629 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 95.997076] wireguard: WireGuard 1.0.0 loaded. See www.wireguard.com for information. [ 95.998979] wireguard: Copyright (C) 2015-2019 Jason A. Donenfeld . All Rights Reserved. [ 97.544854] kauditd_printk_skb: 2 callbacks suppressed [ 97.544857] audit: type=1400 audit(1747442240.980:300): avc: denied { write } for pid=4308 comm="tee" name="fd" dev="proc" ino=25721 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=dir permissive=0 [ 97.569949] audit: type=1400 audit(1747442241.005:301): avc: denied { write } for pid=4316 comm="tee" name="fd" dev="proc" ino=25732 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=dir permissive=0 [ 97.581066] audit: type=1300 audit(1747442241.005:301): arch=c000003e syscall=257 success=yes exit=3 a0=ffffff9c a1=7ffc7d71a7df a2=241 a3=1b6 items=1 ppid=4273 pid=4316 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="tee" exe="/usr/bin/coreutils" subj=system_u:system_r:kernel_t:s0 key=(null) [ 97.599142] audit: type=1307 audit(1747442241.005:301): cwd="/etc/service/enabled/confd/log" [ 97.601940] audit: type=1302 audit(1747442241.005:301): item=0 name="/dev/fd/63" inode=24497 dev=00:0c mode=010600 ouid=0 ogid=0 rdev=00:00 obj=system_u:system_r:kernel_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 [ 97.609444] audit: type=1327 audit(1747442241.005:301): proctitle=2F7573722F62696E2F636F72657574696C73002D2D636F72657574696C732D70726F672D73686562616E673D746565002F7573722F62696E2F746565002F6465762F66642F3633 [ 97.616942] audit: type=1300 audit(1747442240.980:300): arch=c000003e syscall=257 success=yes exit=3 a0=ffffff9c a1=7fffe6b707d0 a2=241 a3=1b6 items=1 ppid=4271 pid=4308 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="tee" exe="/usr/bin/coreutils" subj=system_u:system_r:kernel_t:s0 key=(null) [ 97.628055] audit: type=1307 audit(1747442240.980:300): cwd="/etc/service/enabled/node-status-reporter/log" [ 97.632344] audit: type=1302 audit(1747442240.980:300): item=0 name="/dev/fd/63" inode=24482 dev=00:0c mode=010600 ouid=0 ogid=0 rdev=00:00 obj=system_u:system_r:kernel_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 [ 97.639510] audit: type=1327 audit(1747442240.980:300): proctitle=2F7573722F62696E2F636F72657574696C73002D2D636F72657574696C732D70726F672D73686562616E673D746565002F7573722F62696E2F746565002F6465762F66642F3633 This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:22 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 100.002027] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready [ 100.003195] IPv6: ADDRCONF(NETDEV_CHANGE): caliae2076718f7: link becomes ready [ 100.165467] IPv6: ADDRCONF(NETDEV_CHANGE): calic1a1509cc20: link becomes ready [ 100.894504] IPv6: ADDRCONF(NETDEV_CHANGE): calibe451daeac4: link becomes ready This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:24 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 101.988351] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready [ 101.989490] IPv6: ADDRCONF(NETDEV_CHANGE): calic1551bc05b6: link becomes ready This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:25 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:26 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 103.231727] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready [ 103.232841] IPv6: ADDRCONF(NETDEV_CHANGE): califf9601efd43: link becomes ready [ 103.309378] kauditd_printk_skb: 541 callbacks suppressed [ 103.309381] audit: type=1325 audit(1747442246.744:412): table=filter:115 family=2 entries=44 op=nft_register_chain pid=4968 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" [ 103.312810] audit: type=1300 audit(1747442246.744:412): arch=c000003e syscall=46 success=yes exit=21936 a0=3 a1=7ffce3a8c9d0 a2=0 a3=7ffce3a8c9bc items=0 ppid=4305 pid=4968 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 103.321359] audit: type=1327 audit(1747442246.744:412): proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 [ 103.359784] IPv6: ADDRCONF(NETDEV_CHANGE): caliad068b2eb93: link becomes ready [ 103.438675] audit: type=1325 audit(1747442246.874:413): table=filter:116 family=2 entries=50 op=nft_register_chain pid=5004 subj=system_u:system_r:kernel_t:s0 comm="iptables-nft-re" [ 103.441252] audit: type=1300 audit(1747442246.874:413): arch=c000003e syscall=46 success=yes exit=24368 a0=3 a1=7ffe94e91030 a2=0 a3=7ffe94e9101c items=0 ppid=4305 pid=5004 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-nft-re" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 103.447576] audit: type=1327 audit(1747442246.874:413): proctitle=69707461626C65732D6E66742D726573746F7265002D2D6E6F666C757368002D2D766572626F7365002D2D77616974003130002D2D776169742D696E74657276616C003530303030 This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:27 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 104.090692] audit: type=1325 audit(1747442247.526:414): table=filter:117 family=2 entries=20 op=nft_register_rule pid=5135 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 104.093754] audit: type=1300 audit(1747442247.526:414): arch=c000003e syscall=46 success=yes exit=7480 a0=3 a1=7ffd580ddd40 a2=0 a3=7ffd580ddd2c items=0 ppid=2892 pid=5135 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 104.099186] audit: type=1327 audit(1747442247.526:414): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 104.105037] audit: type=1325 audit(1747442247.535:415): table=nat:118 family=2 entries=14 op=nft_register_rule pid=5135 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 104.304893] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready [ 104.307156] IPv6: ADDRCONF(NETDEV_CHANGE): cali42336864ccc: link becomes ready [ 104.993424] IPv6: ADDRCONF(NETDEV_CHANGE): calidcd0a3704fa: link becomes ready This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:28 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:29 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:30 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: This is ip-172-31-26-143 (Linux x86_64 5.15.182-flatcar) 00:37:31 SSH host key: SHA256:SnYG5WhaliPkVX+IjINxF8b8wTiw/O/vlGCtK2ZO3Nw (ECDSA) SSH host key: SHA256:Fi1At8qIKRA5NCGUdQHbtIlyCX7Hzi55mVwYTDJVrBw (ED25519) SSH host key: SHA256:0zLK78aDtSFH0BiOuWOeLQ/KkLgImRNtsBVpY8/Y+TQ (RSA) eth0: 172.31.26.143 fe80::443:7aff:feed:436f ip-172-31-26-143 login: [ 110.862626] kauditd_printk_skb: 20 callbacks suppressed [ 110.862631] audit: type=1130 audit(1747442254.298:422): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@7-172.31.26.143:22-139.178.68.195:60194 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 111.157705] audit: type=1101 audit(1747442254.593:423): pid=5450 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 111.168509] audit: type=1103 audit(1747442254.604:424): pid=5450 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 111.172836] audit: type=1006 audit(1747442254.608:425): pid=5450 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=8 res=1 [ 111.175728] audit: type=1300 audit(1747442254.608:425): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffc48b5fda0 a2=3 a3=0 items=0 ppid=1 pid=5450 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=8 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 111.181372] audit: type=1327 audit(1747442254.608:425): proctitle=737368643A20636F7265205B707269765D [ 111.230676] audit: type=1105 audit(1747442254.666:426): pid=5450 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 111.235385] audit: type=1103 audit(1747442254.666:427): pid=5453 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 113.128194] audit: type=1106 audit(1747442256.564:428): pid=5450 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 113.146050] audit: type=1104 audit(1747442256.564:429): pid=5450 uid=0 auid=500 ses=8 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 118.160184] kauditd_printk_skb: 19 callbacks suppressed [ 118.160189] audit: type=1130 audit(1747442261.594:437): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@8-172.31.26.143:22-139.178.68.195:60210 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 118.508226] audit: type=1101 audit(1747442261.943:438): pid=5854 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 118.517246] audit: type=1103 audit(1747442261.952:439): pid=5854 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 118.529614] audit: type=1006 audit(1747442261.952:440): pid=5854 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=9 res=1 [ 118.535762] audit: type=1300 audit(1747442261.952:440): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffdf9875840 a2=3 a3=0 items=0 ppid=1 pid=5854 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 118.547935] audit: type=1327 audit(1747442261.952:440): proctitle=737368643A20636F7265205B707269765D [ 118.584816] audit: type=1105 audit(1747442262.019:441): pid=5854 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 118.616035] audit: type=1103 audit(1747442262.045:442): pid=5906 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 119.889550] audit: type=1106 audit(1747442263.323:443): pid=5854 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 119.899265] audit: type=1104 audit(1747442263.324:444): pid=5854 uid=0 auid=500 ses=9 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 124.916892] kauditd_printk_skb: 1 callbacks suppressed [ 124.916895] audit: type=1130 audit(1747442268.352:446): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@9-172.31.26.143:22-139.178.68.195:48844 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 125.189590] audit: type=1101 audit(1747442268.624:447): pid=5966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 125.197531] audit: type=1103 audit(1747442268.632:448): pid=5966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 125.205180] audit: type=1006 audit(1747442268.632:449): pid=5966 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=10 res=1 [ 125.209575] audit: type=1300 audit(1747442268.632:449): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffe279ba150 a2=3 a3=0 items=0 ppid=1 pid=5966 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=10 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 125.217946] audit: type=1327 audit(1747442268.632:449): proctitle=737368643A20636F7265205B707269765D [ 125.236262] audit: type=1105 audit(1747442268.671:450): pid=5966 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 125.247070] audit: type=1103 audit(1747442268.682:451): pid=5969 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 125.779323] audit: type=1106 audit(1747442269.215:452): pid=5966 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 125.787597] audit: type=1104 audit(1747442269.215:453): pid=5966 uid=0 auid=500 ses=10 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 131.785888] kauditd_printk_skb: 23 callbacks suppressed [ 131.785890] audit: type=1130 audit(1747442275.222:473): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@12-172.31.26.143:22-139.178.68.195:43798 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 131.998856] audit: type=1101 audit(1747442275.435:474): pid=6009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 132.008229] audit: type=1103 audit(1747442275.444:475): pid=6009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 132.017058] audit: type=1006 audit(1747442275.444:476): pid=6009 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=13 res=1 [ 132.022774] audit: type=1300 audit(1747442275.444:476): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7fff4131ccd0 a2=3 a3=0 items=0 ppid=1 pid=6009 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=13 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 132.038291] audit: type=1327 audit(1747442275.444:476): proctitle=737368643A20636F7265205B707269765D [ 132.049175] audit: type=1105 audit(1747442275.470:477): pid=6009 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 132.057938] audit: type=1103 audit(1747442275.472:478): pid=6012 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 132.261176] audit: type=1106 audit(1747442275.697:479): pid=6009 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 132.269810] audit: type=1104 audit(1747442275.702:480): pid=6009 uid=0 auid=500 ses=13 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 137.290735] kauditd_printk_skb: 1 callbacks suppressed [ 137.290738] audit: type=1130 audit(1747442280.727:482): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@13-172.31.26.143:22-139.178.68.195:43808 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 137.593141] audit: type=1101 audit(1747442281.029:483): pid=6022 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 137.613341] audit: type=1103 audit(1747442281.049:484): pid=6022 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 137.626061] audit: type=1006 audit(1747442281.049:485): pid=6022 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=14 res=1 [ 137.631114] audit: type=1300 audit(1747442281.049:485): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffde30acd20 a2=3 a3=0 items=0 ppid=1 pid=6022 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=14 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 137.640887] audit: type=1327 audit(1747442281.049:485): proctitle=737368643A20636F7265205B707269765D [ 137.651108] audit: type=1105 audit(1747442281.086:486): pid=6022 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 137.664469] audit: type=1103 audit(1747442281.087:487): pid=6025 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 140.029142] audit: type=1106 audit(1747442283.462:488): pid=6022 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 140.059337] audit: type=1104 audit(1747442283.462:489): pid=6022 uid=0 auid=500 ses=14 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 145.048652] kauditd_printk_skb: 7 callbacks suppressed [ 145.048656] audit: type=1130 audit(1747442288.485:493): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@14-172.31.26.143:22-139.178.68.195:56696 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 145.292322] audit: type=1101 audit(1747442288.728:494): pid=6043 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 145.303121] audit: type=1103 audit(1747442288.738:495): pid=6043 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 145.314363] audit: type=1006 audit(1747442288.738:496): pid=6043 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=15 res=1 [ 145.319931] audit: type=1300 audit(1747442288.738:496): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7fff46df6e60 a2=3 a3=0 items=0 ppid=1 pid=6043 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=15 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 145.329430] audit: type=1327 audit(1747442288.738:496): proctitle=737368643A20636F7265205B707269765D [ 145.354644] audit: type=1105 audit(1747442288.791:497): pid=6043 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 145.375787] audit: type=1103 audit(1747442288.802:498): pid=6046 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 146.172841] audit: type=1106 audit(1747442289.609:499): pid=6043 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 146.189521] audit: type=1104 audit(1747442289.609:500): pid=6043 uid=0 auid=500 ses=15 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 151.197459] kauditd_printk_skb: 1 callbacks suppressed [ 151.197462] audit: type=1130 audit(1747442294.633:502): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@15-172.31.26.143:22-139.178.68.195:52880 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 151.470140] audit: type=1101 audit(1747442294.906:503): pid=6098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 151.483203] audit: type=1103 audit(1747442294.915:504): pid=6098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 151.492712] audit: type=1006 audit(1747442294.915:505): pid=6098 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=16 res=1 [ 151.501172] audit: type=1300 audit(1747442294.915:505): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffdd5cf58e0 a2=3 a3=0 items=0 ppid=1 pid=6098 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=16 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 151.514620] audit: type=1327 audit(1747442294.915:505): proctitle=737368643A20636F7265205B707269765D [ 151.532769] audit: type=1105 audit(1747442294.967:506): pid=6098 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 151.542050] audit: type=1103 audit(1747442294.970:507): pid=6103 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 152.380457] audit: type=1106 audit(1747442295.817:508): pid=6098 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 152.397694] audit: type=1104 audit(1747442295.824:509): pid=6098 uid=0 auid=500 ses=16 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 160.923232] kauditd_printk_skb: 20 callbacks suppressed [ 160.923234] audit: type=1325 audit(1747442304.359:526): table=filter:133 family=2 entries=24 op=nft_register_rule pid=6139 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 160.938260] audit: type=1300 audit(1747442304.359:526): arch=c000003e syscall=46 success=yes exit=13432 a0=3 a1=7ffecd96bae0 a2=0 a3=7ffecd96bacc items=0 ppid=2892 pid=6139 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 160.945725] audit: type=1327 audit(1747442304.359:526): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 160.949739] audit: type=1325 audit(1747442304.370:527): table=nat:134 family=2 entries=22 op=nft_register_rule pid=6139 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 160.954199] audit: type=1300 audit(1747442304.370:527): arch=c000003e syscall=46 success=yes exit=6540 a0=3 a1=7ffecd96bae0 a2=0 a3=0 items=0 ppid=2892 pid=6139 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 160.963258] audit: type=1327 audit(1747442304.370:527): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 162.716030] audit: type=1325 audit(1747442306.152:528): table=filter:135 family=2 entries=36 op=nft_register_rule pid=6141 subj=system_u:system_r:kernel_t:s0 comm="iptables-restor" [ 162.722442] audit: type=1300 audit(1747442306.152:528): arch=c000003e syscall=46 success=yes exit=13432 a0=3 a1=7fff30d30670 a2=0 a3=7fff30d3065c items=0 ppid=2892 pid=6141 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iptables-restor" exe="/usr/sbin/xtables-nft-multi" subj=system_u:system_r:kernel_t:s0 key=(null) [ 162.732647] audit: type=1327 audit(1747442306.152:528): proctitle=69707461626C65732D726573746F7265002D770035002D5700313030303030002D2D6E6F666C757368002D2D636F756E74657273 [ 162.736837] audit: type=1106 audit(1747442306.168:529): pid=6123 uid=0 auid=500 ses=18 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 168.239738] kauditd_printk_skb: 13 callbacks suppressed [ 168.239741] audit: type=1130 audit(1747442311.675:539): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@19-172.31.26.143:22-139.178.68.195:44704 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 168.262648] audit: type=1106 audit(1747442311.690:540): pid=6142 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 168.291397] audit: type=1104 audit(1747442311.693:541): pid=6142 uid=0 auid=500 ses=19 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 168.298726] audit: type=1131 audit(1747442311.697:542): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@18-172.31.26.143:22-139.178.68.195:44700 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 168.540327] audit: type=1101 audit(1747442311.974:543): pid=6156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 168.550724] audit: type=1103 audit(1747442311.986:544): pid=6156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 168.559808] audit: type=1006 audit(1747442311.986:545): pid=6156 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=20 res=1 [ 168.566839] audit: type=1300 audit(1747442311.986:545): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7fff30d018d0 a2=3 a3=0 items=0 ppid=1 pid=6156 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=20 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 168.581756] audit: type=1327 audit(1747442311.986:545): proctitle=737368643A20636F7265205B707269765D [ 168.606056] audit: type=1105 audit(1747442312.042:546): pid=6156 uid=0 auid=500 ses=20 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 174.736064] kauditd_printk_skb: 10 callbacks suppressed [ 174.736068] audit: type=1130 audit(1747442318.172:553): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@20-172.31.26.143:22-139.178.68.195:32876 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 175.031666] audit: type=1101 audit(1747442318.468:554): pid=6193 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 175.040571] audit: type=1103 audit(1747442318.471:555): pid=6193 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 175.049641] audit: type=1006 audit(1747442318.471:556): pid=6193 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=21 res=1 [ 175.054845] audit: type=1300 audit(1747442318.471:556): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffc332b7d00 a2=3 a3=0 items=0 ppid=1 pid=6193 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=21 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 175.067383] audit: type=1327 audit(1747442318.471:556): proctitle=737368643A20636F7265205B707269765D [ 175.099818] audit: type=1105 audit(1747442318.536:557): pid=6193 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 175.116346] audit: type=1103 audit(1747442318.536:558): pid=6196 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 177.239743] audit: type=1106 audit(1747442320.676:559): pid=6193 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 177.250436] audit: type=1104 audit(1747442320.677:560): pid=6193 uid=0 auid=500 ses=21 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 182.275331] kauditd_printk_skb: 1 callbacks suppressed [ 182.275334] audit: type=1130 audit(1747442325.711:562): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@21-172.31.26.143:22-139.178.68.195:51856 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 182.579487] audit: type=1101 audit(1747442326.016:563): pid=6254 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 182.589279] audit: type=1103 audit(1747442326.025:564): pid=6254 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 182.598951] audit: type=1006 audit(1747442326.025:565): pid=6254 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=22 res=1 [ 182.607302] audit: type=1300 audit(1747442326.025:565): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7fff4a225fc0 a2=3 a3=0 items=0 ppid=1 pid=6254 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=22 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 182.625279] audit: type=1327 audit(1747442326.025:565): proctitle=737368643A20636F7265205B707269765D [ 182.669553] audit: type=1105 audit(1747442326.105:566): pid=6254 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 182.684047] audit: type=1103 audit(1747442326.118:567): pid=6257 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 183.925885] audit: type=1106 audit(1747442327.362:568): pid=6254 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 183.942264] audit: type=1104 audit(1747442327.363:569): pid=6254 uid=0 auid=500 ses=22 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 188.951875] kauditd_printk_skb: 1 callbacks suppressed [ 188.951878] audit: type=1130 audit(1747442332.388:571): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@22-172.31.26.143:22-139.178.68.195:51866 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 189.200729] audit: type=1101 audit(1747442332.637:572): pid=6276 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 189.209576] audit: type=1103 audit(1747442332.646:573): pid=6276 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 189.223223] audit: type=1006 audit(1747442332.646:574): pid=6276 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=23 res=1 [ 189.228528] audit: type=1300 audit(1747442332.646:574): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffdcc660df0 a2=3 a3=0 items=0 ppid=1 pid=6276 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=23 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 189.238077] audit: type=1327 audit(1747442332.646:574): proctitle=737368643A20636F7265205B707269765D [ 189.258565] audit: type=1105 audit(1747442332.692:575): pid=6276 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 189.269527] audit: type=1103 audit(1747442332.694:576): pid=6279 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 190.146000] audit: type=1106 audit(1747442333.582:577): pid=6276 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 190.157462] audit: type=1104 audit(1747442333.592:578): pid=6276 uid=0 auid=500 ses=23 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 195.151810] kauditd_printk_skb: 1 callbacks suppressed [ 195.151814] audit: type=1130 audit(1747442338.588:580): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@23-172.31.26.143:22-139.178.68.195:46322 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 195.405336] audit: type=1101 audit(1747442338.842:581): pid=6289 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 195.414234] audit: type=1103 audit(1747442338.851:582): pid=6289 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 195.421025] audit: type=1006 audit(1747442338.851:583): pid=6289 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=24 res=1 [ 195.424846] audit: type=1300 audit(1747442338.851:583): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffebb36e100 a2=3 a3=0 items=0 ppid=1 pid=6289 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=24 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 195.431952] audit: type=1327 audit(1747442338.851:583): proctitle=737368643A20636F7265205B707269765D [ 195.442850] audit: type=1105 audit(1747442338.879:584): pid=6289 uid=0 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 195.450966] audit: type=1103 audit(1747442338.879:585): pid=6292 uid=0 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 196.293091] audit: type=1106 audit(1747442339.729:586): pid=6289 uid=0 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 196.301193] audit: type=1104 audit(1747442339.730:587): pid=6289 uid=0 auid=500 ses=24 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 201.336454] kauditd_printk_skb: 1 callbacks suppressed [ 201.336457] audit: type=1130 audit(1747442344.773:589): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='unit=sshd@24-172.31.26.143:22-139.178.68.195:44378 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' [ 201.622909] audit: type=1101 audit(1747442345.059:590): pid=6316 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:accounting grantors=pam_access,pam_unix,pam_faillock,pam_permit acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 201.631713] audit: type=1103 audit(1747442345.068:591): pid=6316 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 201.644070] audit: type=1006 audit(1747442345.068:592): pid=6316 uid=0 subj=system_u:system_r:kernel_t:s0 old-auid=4294967295 auid=500 tty=(none) old-ses=4294967295 ses=25 res=1 [ 201.649210] audit: type=1300 audit(1747442345.068:592): arch=c000003e syscall=1 success=yes exit=3 a0=5 a1=7ffc15afa190 a2=3 a3=0 items=0 ppid=1 pid=6316 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=25 comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:kernel_t:s0 key=(null) [ 201.657264] audit: type=1327 audit(1747442345.068:592): proctitle=737368643A20636F7265205B707269765D [ 201.677596] audit: type=1105 audit(1747442345.114:593): pid=6316 uid=0 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_open grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 201.687423] audit: type=1103 audit(1747442345.124:594): pid=6319 uid=0 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 202.621720] audit: type=1106 audit(1747442346.058:595): pid=6316 uid=0 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:session_close grantors=pam_loginuid,pam_env,pam_lastlog,pam_limits,pam_env,pam_unix,pam_permit,pam_systemd,pam_mail acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success' [ 202.629929] audit: type=1104 audit(1747442346.058:596): pid=6316 uid=0 auid=500 ses=25 subj=system_u:system_r:kernel_t:s0 msg='op=PAM:setcred grantors=pam_env,pam_faillock,pam_unix acct="core" exe="/usr/sbin/sshd" hostname=139.178.68.195 addr=139.178.68.195 terminal=ssh res=success'